diff options
| author | Simo Sorce <simo@redhat.com> | 2016-11-30 09:06:33 -0500 |
|---|---|---|
| committer | Simo Sorce <simo@redhat.com> | 2017-01-13 15:50:06 -0500 |
| commit | 2d49ba029e5b0fdaa4bafc3d5bca0cb1169c9877 (patch) | |
| tree | 0eda5a7654de058300d3cbf642b60c3819c4e141 /proxy/Makefile.am | |
| parent | 56d2a3119c4713fbfabf98b0afc0882d64324166 (diff) | |
Use a local keytab for creds encryption
If available use a keytab for creds encryption.
Since now we can store encrypted credentials, on the cient side, for later
reuse, it is better to be able to decrypt them even after a gssproxy daemon
restart (maintenance, crashes, etc..)
If a keytab is rotated this can cause a restarted gssproxy to fail to decrypt
stored credentials, but in that case those credentials are also probably
useless and need to be refreshed, so this is not a huge deal, and definitely
better than the status quo.
Signed-off-by: Simo Sorce <simo@redhat.com>
Diffstat (limited to 'proxy/Makefile.am')
0 files changed, 0 insertions, 0 deletions
