anonymous realm and host realm referrals

Sam Hartman hartmans at MIT.EDU
Thu Dec 17 19:39:45 EST 2009

>>>>> "Greg" == Greg Hudson <ghudson at MIT.EDU> writes:

    Greg> On Thu, 2009-12-17 at 12:36 -0500, Sam Hartman wrote:
    >> 3) Introduce functionality to find the first TGT in the ccache
    >> when trying to contact the client's KDC and using the anonymous
    >> realm.

    Greg> This makes me a little nervous because I think it may be the
    Greg> first time we're considering ccaches as ordered sequences
    Greg> rather than sets, but it should work in practice.

Order of tgts in a ccache actually already matters.  You will use the
first tgt you find where the second component is the target realm.

