<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://k5wiki.kerberos.org/wiki?action=history&amp;feed=atom&amp;title=Release_Meeting_Minutes%2F2014-06-17</id>
		<title>Release Meeting Minutes/2014-06-17 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://k5wiki.kerberos.org/wiki?action=history&amp;feed=atom&amp;title=Release_Meeting_Minutes%2F2014-06-17"/>
		<link rel="alternate" type="text/html" href="https://k5wiki.kerberos.org/wiki?title=Release_Meeting_Minutes/2014-06-17&amp;action=history"/>
		<updated>2026-04-30T08:18:39Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.4</generator>

	<entry>
		<id>https://k5wiki.kerberos.org/wiki?title=Release_Meeting_Minutes/2014-06-17&amp;diff=5329&amp;oldid=prev</id>
		<title>TomYu: New page: {{minutes|2014}} Tony Acero, Viktor Dukhovni, Will Fiveash, Greg Hudson, Zhanna Tsitkov, Nico Williams, Tom Yu  ;Tom: Will, have you seen any DB2 corruption since we fixed the last big bug...</title>
		<link rel="alternate" type="text/html" href="https://k5wiki.kerberos.org/wiki?title=Release_Meeting_Minutes/2014-06-17&amp;diff=5329&amp;oldid=prev"/>
				<updated>2014-06-17T21:18:07Z</updated>
		
		<summary type="html">&lt;p&gt;New page: {{minutes|2014}} Tony Acero, Viktor Dukhovni, Will Fiveash, Greg Hudson, Zhanna Tsitkov, Nico Williams, Tom Yu  ;Tom: Will, have you seen any DB2 corruption since we fixed the last big bug...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{minutes|2014}}&lt;br /&gt;
Tony Acero, Viktor Dukhovni, Will Fiveash, Greg Hudson, Zhanna Tsitkov, Nico Williams, Tom Yu&lt;br /&gt;
&lt;br /&gt;
;Tom: Will, have you seen any DB2 corruption since we fixed the last big bug?&lt;br /&gt;
&lt;br /&gt;
;Will: Haven't asked people yet; will make a note.&lt;br /&gt;
&lt;br /&gt;
;Greg: Nico, Russ wants to know your preferred JSON lib.&lt;br /&gt;
&lt;br /&gt;
;Nico: libjq https://github.com/stedolan/jq&lt;br /&gt;
&lt;br /&gt;
;Nico: Have some changes to Heimdal (not pushed) to do capaths computation.  Wanted to call jq from Heimdal, ran into problems with heimbase.&lt;br /&gt;
&lt;br /&gt;
== Firewalled realms ==&lt;br /&gt;
&lt;br /&gt;
;Viktor: Various scenarios where users ssh into DMZ machines -- DMZ has no connectivity to origin realm.  Get and delegate krbtgt/target@target.  Keeps origin creds from leaking into possibly less secure target realm.&lt;br /&gt;
&lt;br /&gt;
;Viktor: Selected realms get destination TGTs instead of origin TGTs forwarded; alternatively, white list realms that get origin TGTs.&lt;br /&gt;
&lt;br /&gt;
;Tom: Two pieces&lt;br /&gt;
:# list of target realms to which to forward local target TGTs&lt;br /&gt;
:# client lib on destination app server -- deal with the weird ccache&lt;br /&gt;
&lt;br /&gt;
We think identifying the &amp;quot;starting TGT&amp;quot; in a ccache for this situation (client origin realm different from krbtgt/A@A) is helpful, probably using a ccache config entry.&lt;br /&gt;
&lt;br /&gt;
;Viktor: Java bug -- sometimes picks wrong krbtgt/A@A if there are multiple in cache.&lt;br /&gt;
&lt;br /&gt;
;Tom: Does hopping realms work? e.g. client@A ssh to DMZ realm B, then ssh to different DMZ realm C that can't talk to B?&lt;br /&gt;
&lt;br /&gt;
;Viktor: Should work.&lt;br /&gt;
&lt;br /&gt;
;Greg: Receive side might be better to implement first.&lt;br /&gt;
&lt;br /&gt;
;Tom: Need to coordinate how to structure the configuration settings.&lt;br /&gt;
&lt;br /&gt;
== DB2 ==&lt;br /&gt;
&lt;br /&gt;
;Will: Sent mail re DB2 -- probably haven't seen that kind of corruption since that bug {{bug|5880}} was fixed.&lt;/div&gt;</summary>
		<author><name>TomYu</name></author>	</entry>

	</feed>