kinit and enterprise names

Sam Hartman hartmans at painless-security.com
Tue Dec 23 14:40:35 EST 2008


>>>>> "Love" == Love Hörnquist Åstrand <lha at kth.se> writes:

    Love> 23 dec 2008 kl. 20:01 skrev Sam Hartman:

    >> Luke, do we want some mechanism to request an enterprise name
    >> for kinit?

    Love> Heimdal uses kinit --canonicalize to turn on parsing as
    Love> KRB5_PRINCIPAL_PARSE_ENTERPRISE (and at the same time
    Love> request client canonicalion of the KDC).

Luke added a canonicalize flag, but it does not also parse as
enterprise.  It seems desirable if we make --canonicalize imply
enterprise to have a option that turns on canonicalize but does not
imply enterprise name.




More information about the krbdev mailing list