Re: GSSAPI Key Exchange Patch for OpenSSH 4.7p1

This is a discussion on Re: GSSAPI Key Exchange Patch for OpenSSH 4.7p1 within the OpenSSH Development forums, part of the Networking and Network Related category; On 1 Mar 2008, at 03:12, Russ Allbery wrote: > Matthew Andrews <matt@slackers.net> writes: > &...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-01-2008
Simon Wilkinson
 
Posts: n/a
Default Re: GSSAPI Key Exchange Patch for OpenSSH 4.7p1


On 1 Mar 2008, at 03:12, Russ Allbery wrote:

> Matthew Andrews <matt@slackers.net> writes:
>
>> Hmmm.... The cascading credentials code sounds interesting, but
>> raises
>> the practical question of how does one deal with derived credentials.
>>

> Just re-run the session PAM stack with PAM_REFRESH_CREDS set, the
> same as
> what a screensaver would do. This does all the right things with
> derived
> credentials if your PAM modules are properly written.


This is exactly what my cascading credentials code for OpenSSH does.
It uses an additional PAM stack (so you can set different options
than the 'main' ssh PAM stack) which it calls the session layer of
whenever credentials are renewed. We use this to renew both AFS
tokens, and KX509 certificates.

Informatics are now running this code in production. I expect to be
making a public release next week.

Cheers,

Simon.

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
https://lists.mindrot.org/mailman/li...enssh-unix-dev
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:20 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0