Keytab initiation design review

Nico Williams nico at
Wed Jun 27 17:18:51 EDT 2012

default_client_keytab needs some sort of token expansion, otherwise
all clients must share the same keytab (and, therefore, have common
privilege), or else they must use an environment variable.  The latter
will be the case in actuality without token expansion.

I don't see my requirement that environment variables not be the only
practical method of configuring client keytabs.  This is a very strong
requirement for me.  Is it not on the list due to an oversight, or do
you not accept it as a requirement?


More information about the krbdev mailing list