Skip to content

Some questions about gssproxy.conf options #77

Answered by simo5
foonon asked this question in Q&A
Discussion options

You must be logged in to vote
  1. "Impersonate" allows the use of Constrained Delegation (which needs to be also authorized by the KDC), while "trusted" allows users of the service to tell who to impersonate, which could be any other user.
    Trusted needs to be used carefully, generally should be set only on services that restrict access to either root or a controlled service account.

  2. After first ccache initialization (when TGT and first ticket is received) the cache is sent back encrypted to the client. Later on the client may request additional tickets, and does so by sending the received cache to the gss-proxy process that uses it to retrieve the new ticket and create a GSSAPI session. Given the original cache contao…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by foonon
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants