Subject: Re: SURVEY: Removal of Kerberos 4 from base
To: Greg Troxel <gdt@ir.bbn.com>
From: Love <lha@NetBSD.org>
List: tech-security
Date: 04/15/2005 18:23:57
--=-=-=


Greg Troxel <gdt@ir.bbn.com> writes:

>   I've asked core for permission to remove Kerberos 4 support from current,
>   and thus the next upcoming netbsd major release after 3.0.  I was asked to
>   query our users if there was still users of the kerberos 4 code that felt
>   that running Kerberos 4 from pkgsrc wasn't good enough.  I promised to glue
>   in code in the KDC so it would still service requests to Kerberos 4
>   clients.
>
> I'm not sure I understand exactly what you are proposing to do.  In my
> case, I use krb4 with amanda (also firewalled, since I know that's
> dicey).  It sounds like the *'d libraries below will be removed:

Yes, they would be removed. BTW, I looks to me that Amanda have kerberos 5
support.

> Then, it sounds like the libraries will not be installed or used by
> normal base system programs, but the in-tree V5 KDC (/usr/sbin/kdc)
> would still be able to run and answer v4 AS-REQ and TGS-REQ queries.
> I don't follow whether krb524 will still work, but I personally don't
> care since that isn't needed for amanda.
>
>
> So if that's what you mean, that sounds ok.

Yes, exactly that.

Love


--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (NetBSD)

iQEVAwUAQl/qoNo1gLFKFEjAAQI7gQf8D36njNXa0y+DXFFU/HhLBgICRo8z74Vn
vnRNl+MGivBFcGmmK9dgs68pWj6w1BGvBmxab110KhDLxyuZYmPcY7PWgUw2euxf
ZGxmtuRrQfcTb00NYumSycxBqzPTHavOR0plPMsgPwjIefDpXkHWWyDVMzEwPiH0
RZl0kIFIzzvhB53Z/NEFSjLw/aL3xvdBXzrjK0oa66Xqgyt8QcaTIN+TQIHGb5hy
me66X9+s3Q/11H2pEDgjm1qnn4AzXno9WGTFUmfKeL+H/C3buqvLYmw9dyDFPayO
EmlCrWJ9Jbn5E+w5md/YLXJtnV01tnqKOsguDKVOf2G5vcRILhABWQ==
=rj+t
-----END PGP SIGNATURE-----
--=-=-=--