Re: syncrepl + GSSAPI

--On Thursday, August 05, 2004 1:13 PM -0400 "Matthew J. Smith" <matt.smith@uconn.edu> wrote:

Thank you for the response.  Google did bring me across k5start, and I
am contemplating it's use.  I was hoping that slapd could do this
without needing any extra utilities, simply obtaining and refreshing the
ticket as part of the syncrepl process.  I may use k5start (or even just
a cron'd kinit).  But first, can anyone definitively tell me whether
slapd does or will ever directly support this functionality?

It doesn't currently, I'm not sure that it ever would, but a developer would have to answer that. I don't suggest using cron, because I've seen that not work well (we used to do that). k5start with svcscan has worked very well for us.

Part of the problem with slapd getting and maintaining its own ticket is that it would have to know a variety of different things about your Kerberos setup, as well as having to refresh the ticket periodically.


