Coda File System

Re: AFS tokens and kerberos 5

From: Jan Harkes <jaharkes_at_cs.cmu.edu>
Date: Tue, 27 Aug 2002 12:22:05 -0400
On Tue, Aug 27, 2002 at 09:21:40AM -0400, Greg Troxel wrote:
> I am not fully clear on the details below of the AFS changes for
> kerberos 5, but I thought it would be helpful for coda folks to be
> aware of what's going on (it was news to me).

Won't affect Coda. It looks like the AFS folks are simply sticking their
tokens in something that looks a lot like a kerberos IV ticket. This way
if you log into another machine and your kerberos tickets are
transparently forwarded your AFS authentication 'piggybacks' along and
klist shows not only the kerberos tickets, but also the AFS tokens.

The proposed changes seems to be related to krb524, obtaining kerberos
IV tickets based on your kerberos 5 tickets, so that the krb5 AFS
ticket? is automatically converted into the krbIV equivalent AFS token.

Jan
Received on 2002-08-27 12:23:21