[OpenAFS-devel] aklog on MacOS X was Re: Service Ticket Questions

Douglas E. Engert deengert@anl.gov
Thu, 23 Mar 2006 10:45:49 -0600


Henry B. Hotz wrote:


> 
> Just to bring another issue into the discussion.  What about if we  use 
> something besides Kerberos to get AFS tokens?  Apple seems to be  headed 
> in the direction of using the Keychain Manager to show PKI- based 
> permissions.  That's a pretty disjoint GUI from Kerberos.app.   My 
> belief is that that's far enough off that it's worth doing  something 
> about the UI confusion with tokens and Kerberos anyway.   Something to 
> ponder in odd moments.

gssklog has been doing this for 5 years. The Globus GSI uses x.509
certificates, and has implementd a gssapi mechanisum. The gssklog
can use this to get AFS tokens.



> ------------------------------------------------------------------------ 
> ----
> The opinions expressed in this message are mine,
> not those of Caltech, JPL, NASA, or the US Government.
> Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu
> 
> 
> _______________________________________________
> OpenAFS-devel mailing list
> OpenAFS-devel@openafs.org
> https://lists.openafs.org/mailman/listinfo/openafs-devel
> 
> 

-- 

  Douglas E. Engert  <DEEngert@anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444