We're currently running AFS, and are using the AFS kaserver for 
our kerberos service.  We are interested in migrating to using
kerberos 5 or DCE kerberos.

The reason I'm posting here is that I've heard a lot of scattered
traffic about using AFS with V5 kerberos, but I haven't really heard
anything about what you need to do to migrate from a kaserver
environment to using an MIT v5 server to hand out AFS tickets.  For
example, I've heard about daemons which listen on the kaserver port
and translate AFS reqs into v5 requests and stuff like that.  I
haven't really heard specifics about whether you can easily hook the 
AFS string_to_key into the v5 server.  I know there are ways to use
different realm names for a while in the v5 server (so that you can
migrate from not using a realm name to using one, or so that you can
merge realms).  Something I was interested in was possibly using a
different string_to_key for awhile (until the user changed their
password for example).

Basically, I'm just putting out feelers to find out what people have
done.  Any ideas or thoughts on this would be greatly appreciated.

Thanks in advance,
-Scott

Reply via email to