jaltman at secure-endpoints.com
Tue Aug 17 09:39:55 EDT 2010
On 8/13/2010 10:01 AM, Douglas E. Engert wrote:
> What is missing is an OpenAFS aklog that can use SSPI.
> My old gssklog from 2004 could use SSPI :-)
While it is certainly true that the rxkad aklog could be implemented
using the LSA credential cache functions to request a krb5 service
ticket for afs, the SSPI cannot be used to obtain rxgk security tokens
because it lacks an implementation of the GSS PRF.
There will be a need for a non-Microsoft Kerberos/GSS implementation for
use with AFS implementation for quite some time to come.
More information about the krbdev