X-Recipient: archive-cygwin@delorie.com
DomainKey-Signature: a=rsa-sha1; c=nofws; d=sourceware.org; h=list-id
	:list-unsubscribe:list-subscribe:list-archive:list-post
	:list-help:sender:message-id:date:from:mime-version:to:subject
	:references:in-reply-to:content-type:content-transfer-encoding;
	 q=dns; s=default; b=URpHjFhrkx/T4Mtr6RgQPocNyc/ki9ir6WG63UMBhH4
	9R+auKBrxxVSQ2I2huMkCh9/HEzaN/X58sBZFJLhlH2l3p7gFXdHvzdxznMxHm9+
	dm5HZoQA27cUtUlsaMfseAarXMpuD/EcKa4/OsdpCu9Q6Hb4M3lVh24YL/vI/YFI
	=
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sourceware.org; h=list-id
	:list-unsubscribe:list-subscribe:list-archive:list-post
	:list-help:sender:message-id:date:from:mime-version:to:subject
	:references:in-reply-to:content-type:content-transfer-encoding;
	 s=default; bh=fFqlFNkp8HTFg4K2NAH0WIHQaDo=; b=xJ4VJnNU0PWyST9+q
	RB/5Qe7tOXxWPUHKkcpfUEjgV9GKN4BLut/U7FBouoZamT/iefLo0c/WN5ZgO3Ly
	BYfXWqESKRajTFZFZ+Wr72zTQrcJH6EP1cuQi5t5i9qdcAfFFx/Fc9LBeEnyKL3j
	YrgPPSFTpFkI8xUl4w1IA9GkYk=
Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Mail-Followup-To: cygwin@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com
X-Spam-SWARE-Status: No, score=-2.7 required=5.0 tests=AWL,BAYES_00,KHOP_THREADED autolearn=ham version=3.3.1
X-MDAV-Result: clean
X-MDAV-Processed: mail.secure-endpoints.com, Mon, 24 Jun 2013 07:56:52 -0400
X-Spam-Processed: mail.secure-endpoints.com, Mon, 24 Jun 2013 07:56:52 -0400	(not processed: message from trusted or authenticated source)
X-Return-Path: jaltman@openafs.org
X-Envelope-From: jaltman@openafs.org
X-MDaemon-Deliver-To: cygwin@cygwin.com
Message-ID: <51C83402.5030404@openafs.org>
Date: Mon, 24 Jun 2013 07:56:50 -0400
From: Jeffrey Altman <jaltman@openafs.org>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/20130509 Thunderbird/17.0.6
MIME-Version: 1.0
To: cygwin@cygwin.com
Subject: Re: Packaging Heimdal for Cygwin was Re: Heimdal 1.5.2: "unknown mech-code 2529639054 for mech 1 3 6 1 4 1 311 2 2 10"
References: <409A0E510096B044A0EE3778BB3F1F5C01379C903ECD@EXMAIL.hrl.com> <51C33835.6000207@openafs.org> <409A0E510096B044A0EE3778BB3F1F5C01379C904127@EXMAIL.hrl.com> <51C38880.3090401@openafs.org> <20130621074355.GE1620@calimero.vinschen.de> <51C45788.7080908@openafs.org> <20130621140733.GF7362@calimero.vinschen.de> <51C48EE2.1000406@openafs.org> <20130624091012.GA14319@calimero.vinschen.de>
In-Reply-To: <20130624091012.GA14319@calimero.vinschen.de>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit

On 6/24/2013 5:10 AM, Corinna Vinschen wrote:
> On Jun 21 13:35, Jeffrey Altman wrote:
>> Since Cygwin Heimdal is built as Linux without any platform specific
>> credential cache support it will be restricted to using FILE: caches as
>> a ticket store.  Microsoft Kerberos never uses FILE: based caches and
>> native MIT and Heimdal distributions use them only when explicitly
>> configured to.
>>
>> The preferred location of a krb5.conf file on Windows is
>>
>>   %ALLUSERSPROFILE%\Kerberos\krb5.conf
>>
>> By reading the DOS formatted file stored at that location any configuration
>> applied to native Kerberos library distributions will also be used by
>> Cygwin applications.
> 
> Sorry if I'm dense but what does that mean exactly for Cygwin?  Assuming
> the Cygwin heimdal package would use that file location, would it be only
> able to interact correctly with other third part kerberos or heimdal
> packages, or would it also work with the native stuff and AD?

If Cygwin shared that location it would share the configuration for
native MIT and Heimdal Kerberos distributions.

Microsoft's Kerberos SSP is in-kernel and does not use configuration
files.  All Microsoft configuration is via Group Policy and Registry
manipulation.

Jeffrey Altman



--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

