<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://k5wiki.kerberos.org/wiki?action=history&amp;feed=atom&amp;title=Release_Meeting_Minutes%2F2013-06-11</id>
		<title>Release Meeting Minutes/2013-06-11 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://k5wiki.kerberos.org/wiki?action=history&amp;feed=atom&amp;title=Release_Meeting_Minutes%2F2013-06-11"/>
		<link rel="alternate" type="text/html" href="https://k5wiki.kerberos.org/wiki?title=Release_Meeting_Minutes/2013-06-11&amp;action=history"/>
		<updated>2026-05-13T05:15:17Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.4</generator>

	<entry>
		<id>https://k5wiki.kerberos.org/wiki?title=Release_Meeting_Minutes/2013-06-11&amp;diff=5139&amp;oldid=prev</id>
		<title>TomYu: New page: {{minutes|2013}}  Shawn Emery, Greg Hudson, Ben Kaduk, Nathaniel McCallum, Zhanna Tsitkov, Nico Williams, Tom Yu  ==Companion daemon==  ;Nathaniel: Worst case it drops off face of earth. R...</title>
		<link rel="alternate" type="text/html" href="https://k5wiki.kerberos.org/wiki?title=Release_Meeting_Minutes/2013-06-11&amp;diff=5139&amp;oldid=prev"/>
				<updated>2013-06-13T20:44:53Z</updated>
		
		<summary type="html">&lt;p&gt;New page: {{minutes|2013}}  Shawn Emery, Greg Hudson, Ben Kaduk, Nathaniel McCallum, Zhanna Tsitkov, Nico Williams, Tom Yu  ==Companion daemon==  ;Nathaniel: Worst case it drops off face of earth. R...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{minutes|2013}}&lt;br /&gt;
&lt;br /&gt;
Shawn Emery, Greg Hudson, Ben Kaduk, Nathaniel McCallum, Zhanna Tsitkov, Nico Williams, Tom Yu&lt;br /&gt;
&lt;br /&gt;
==Companion daemon==&lt;br /&gt;
&lt;br /&gt;
;Nathaniel: Worst case it drops off face of earth. Reject to client. Should somehow signal client to retry.&lt;br /&gt;
&lt;br /&gt;
;Greg: RADIUS server might not be a companion daemon.&lt;br /&gt;
&lt;br /&gt;
;Nathaniel: Local will always give an immediate error. libkrad will attempt to retry.&lt;br /&gt;
&lt;br /&gt;
;Tom: KDC_ERR_SVC_UNAVAILABLE&lt;br /&gt;
&lt;br /&gt;
;Nathaniel: Requirement to put sockets in /run (from SELinux)&lt;br /&gt;
&lt;br /&gt;
;Greg: Open to configure option for /run, maybe try to add autodetect&lt;br /&gt;
&lt;br /&gt;
;Shawn: More authorization checks for S4U2Self... limit proxy princ deleg for specific clients. [ Probably really need this in S4U2Proxy ]&lt;br /&gt;
&lt;br /&gt;
;Greg: Write a project page.  LDAP back end can check but ignores client principal.  [ this would be a new capability ]&lt;br /&gt;
&lt;br /&gt;
;Nico: Have wanted this too.&lt;br /&gt;
&lt;br /&gt;
==Zero-component principals==&lt;br /&gt;
&lt;br /&gt;
;Nico: Question on KITTEN list re zero-length (zero component) principals... want to steal syntax to specify realm alone GSS name type for naming realms.  Form would be &amp;quot;@REALMNAME&amp;quot;.  Heimdal apparently gives you a single-component principal whose content is &amp;quot;@&amp;quot; in that case.&lt;br /&gt;
&lt;br /&gt;
==OTP==&lt;br /&gt;
&lt;br /&gt;
;Nathaniel: Greg, have working tests. Forward slash determines file vs (literal) password for secret.&lt;br /&gt;
&lt;br /&gt;
;Greg: Maybe we can have a default directory.&lt;/div&gt;</summary>
		<author><name>TomYu</name></author>	</entry>

	</feed>