[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Turning off hostname canonicalisation



>>>>> "Jeffrey" == Jeffrey Hutzelman <jhutz@cmu.edu> writes:

    Jeffrey> I would consider case-insensitive lookups of service
    Jeffrey> principals in the KDB to be an example of such aliases,
    Jeffrey> provided the ticket issued by the KDC uses the same case
    Jeffrey> as the request.  Normally I would see little value in
    Jeffrey> such functionality, as existing specifications do
    Jeffrey> recommend case-folding of hostnames before they are used
    Jeffrey> to construct service principal names. Nonetheless, if
    Jeffrey> there are clients widely deployed which do not do this,
    Jeffrey> it would seem useful for KDC's to have such a feature,
    Jeffrey> and I do not believe it would be in conflict with the
    Jeffrey> Kerberos spec.


Yes.  However I don't think supporting case insensitive names in a
keytab works this way in an interoperable manner.

--Sam