[Date Prev][Date Next]
Re: syncrepl + GSSAPI
--On Thursday, August 05, 2004 1:13 PM -0400 "Matthew J. Smith"
Thank you for the response. Google did bring me across k5start, and I
am contemplating it's use. I was hoping that slapd could do this
without needing any extra utilities, simply obtaining and refreshing the
ticket as part of the syncrepl process. I may use k5start (or even just
a cron'd kinit). But first, can anyone definitively tell me whether
slapd does or will ever directly support this functionality?
It doesn't currently, I'm not sure that it ever would, but a developer
would have to answer that. I don't suggest using cron, because I've seen
that not work well (we used to do that). k5start with svcscan has worked
very well for us.
Part of the problem with slapd getting and maintaining its own ticket is
that it would have to know a variety of different things about your
Kerberos setup, as well as having to refresh the ticket periodically.
Principal Software Developer
GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html