With the ever-growing array of holes being pushed though the gssapi layer to get at the krb5_context, when will it be better to just provide the krb5_context? I'm noticing that we need yet another hook, to set the realm lookup function. It seems things are getting a bit unwieldy. If that's too much, the other approach might be to remove the send_to_kdc gssapi and specific krb5 hook, and replace it with the generic plugin mechanism. Thoughts? Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Red Hat Inc. http://redhat.com
This is a digitally signed message part