[OpenAFS] Mapping btw. AFS tokens and Kerberos tickets (Heimdal)

Russ Allbery rra@stanford.edu
Wed, 09 Nov 2005 14:20:49 -0800

Volker Lendecke <Volker.Lendecke@SerNet.DE> writes:

> Do the various AFS server accept Kerberos V tickets natively or don't
> they do it?

AFS servers do accept Kerberos V tickets natively, sort of.  They don't do
proper krb5 authentication yet, but they can use the core of a krb5 ticket
as a token provided that you're using DES as the encryption type.  You
still get a single krb5 ticket for the AFS service and use it everywhere,

Full support for Kerberos v5, including other enctypes and individual
service tickets for each server, is still coming.

