a suggestion for improving pkinit preauth plugin token choosing

Greg Hudson ghudson at MIT.EDU
Wed May 12 11:56:35 EDT 2010


On Wed, 2010-05-12 at 08:56 -0400, Sam Hartman wrote:
> For example, what should that prompt read? "Press enter," may be right
> for a CLI instance, but will be wrongish for gdm.

In a previous discussion, I suggested adding a prompt type for
"continue".  The text would then be something to the effect of "Please
insert your token.", and it would be up to the prompter implementation
to convey how to continue.  For instance, the POSIX prompter might
display

  Please insert your token.
  Press enter to continue:

and the GDM prompter might display a dialog saying "Please insert your
token." with continue and cancel buttons.

Ref to the prior conversation:

http://mailman.mit.edu/pipermail/krbdev/2010-March/008800.html

Existing prompter implementations might do something suboptimal, but not
entirely broken.





More information about the krbdev mailing list