[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kerberos
Subject:    Re: kvno and gss_init_sec_context
From:       Greg Hudson <ghudson () MIT ! EDU>
Date:       2013-10-27 18:38:06
Message-ID: 526D5D8E.2020303 () mit ! edu
[Download RAW message or body]

On 10/27/2013 01:19 PM, Arpit Srivastava wrote:
> What difference does it makes, at protocol and message exchange level,
> by not doing kvno and directly calling gss_init_sec_context() api for
> getting the service ticket and the tokens ?

Just what you observed.  If an appropriate service ticket is already
present in the ccache, gss_init_sec_context will use it; otherwise, it
will make a TGS request for the service ticket first.

kvno is not intended to be a normal part of using Kerberos; it is more
of an operational testing tool like ping or traceroute.

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic