Creating a new pre-authentication plugin

Luke Howard lukeh at
Thu Aug 2 04:00:01 EDT 2012

On 02/08/2012, at 5:55 PM, Alejandro Perez Mendez <alex at> wrote:

> Indeed, this approach is also written down into the draft. We just shown 
> our preference for the other alternative since we think GSS-preauth does 
> not (theoretically) make the KDC statefull. The problem is that, seeing 
> now that usually MIT Kerberos and other implemenations are linked with 
> the GSS-API in an static way, the KDC would be becoming into a statefull 
> element.

By static do you mean, within the same process, as opposed to statically linked?

-- Luke

More information about the krbdev mailing list