<[email protected]> writes:

> A question on the kerberos implementation ( Kerb v5-1.6) that we tested
> and are using now in experimental studies: Does this kerberos version
> allow to distinguish between different users in terms of allowing to
> grant the TGS ticket for a certain service for certain users and
> refusing the TGS ticket grant for other users.

I don't believe there's a mechanism in either MIT Kerberos or Heimdal to
support this particular use case.  Kerberos generally assumes that
authorization decisions are handled in the application, not at the level
of issuing tickets.

-- 
Russ Allbery ([email protected])             <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to