pkinit kinit/krb5.conf naming inconsistencies

Nicolas Williams Nicolas.Williams at
Tue Sep 16 16:54:01 EDT 2008

On Tue, Sep 16, 2008 at 01:45:46PM -0700, Henry B. Hotz wrote:
> On Sep 16, 2008, at 9:12 AM, krbdev-request at wrote:
> >I'm assuming that Heimdal's kinit doesn't have this -x thing, that in
> >Heimdal if you want to override the system's krb5.conf you should use
> >the KRB5_CONFIG environment variable.
> I care a lot more about rationalizing the krb5.conf file than the  
> command line options.  For reference:

Meaning what?  That you don't care about the difference in naming in
kinit -x?

> kinit --pk-user=<x509 identity> --x509-anchors=<directory> --pk-use- 
> enckey ...

Is the above how Heimdal does it?  I don't mind that, but I do mind
kinit -x <param-name-that-doesn't-relate-to-krb5.conf>.

In any case, I suppose that MIT filibusters by silence, thus nothing
will change and I'm just wasting my time.


More information about the krbdev mailing list