Re: [Freeipa-devel] Thesis - Gnome Keyring Key Storage in Vault/KRA

2014-10-14 Thread Martin Kosek
On 10/13/2014 07:37 PM, Simo Sorce wrote: On Mon, 13 Oct 2014 13:24:10 +0200 Martin Kosek mko...@redhat.com wrote: Hello all, Last week me, Jakub and Stef discussed a design for a candidate for a FreeIPAGnome keyring related thesis:

Re: [Freeipa-devel] Thesis - Gnome Keyring Key Storage in Vault/KRA

2014-10-14 Thread Simo Sorce
On Tue, 14 Oct 2014 13:21:53 +0200 Martin Kosek mko...@redhat.com wrote: On 10/13/2014 07:37 PM, Simo Sorce wrote: On Mon, 13 Oct 2014 13:24:10 +0200 Martin Kosek mko...@redhat.com wrote: Hello all, Last week me, Jakub and Stef discussed a design for a candidate for a FreeIPAGnome

[Freeipa-devel] Thesis - Gnome Keyring Key Storage in Vault/KRA

2014-10-13 Thread Martin Kosek
Hello all, Last week me, Jakub and Stef discussed a design for a candidate for a FreeIPAGnome keyring related thesis: https://thesis-managementsystem.rhcloud.com/topic/show/219/gnome-keyring-storage-in-freeipa Apparently, there was a misunderstanding when crafting the topic proposal, it is not

Re: [Freeipa-devel] Thesis - Gnome Keyring Key Storage in Vault/KRA

2014-10-13 Thread Sumit Bose
On Mon, Oct 13, 2014 at 01:24:10PM +0200, Martin Kosek wrote: Hello all, Last week me, Jakub and Stef discussed a design for a candidate for a FreeIPAGnome keyring related thesis: https://thesis-managementsystem.rhcloud.com/topic/show/219/gnome-keyring-storage-in-freeipa Apparently,

Re: [Freeipa-devel] Thesis - Gnome Keyring Key Storage in Vault/KRA

2014-10-13 Thread Simo Sorce
On Mon, 13 Oct 2014 13:24:10 +0200 Martin Kosek mko...@redhat.com wrote: Hello all, Last week me, Jakub and Stef discussed a design for a candidate for a FreeIPAGnome keyring related thesis: https://thesis-managementsystem.rhcloud.com/topic/show/219/gnome-keyring-storage-in-freeipa

Re: [Freeipa-devel] Thesis - Gnome Keyring Key Storage in Vault/KRA

2014-10-13 Thread Simo Sorce
On Mon, 13 Oct 2014 14:15:10 +0200 Sumit Bose sb...@redhat.com wrote: What about using a new authorization data type for the key. Then only the KDCs on the IPA servers need access to the key. The authorization data can be added to the service ticket of the host the user logs into. Since SSSD