[Touch-packages] [Bug 1889548] Re: ssh using gssapi will enforce FILE: credentials cache

2022-07-11 Thread Andreas Hasenack
Toby, you are mostly interested in this because you have some sort of policy, perhaps one that doesn't allow secrets to be stored on disk in clear text and protected just by filesystem permissions? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages,

[Touch-packages] [Bug 1889548] Re: ssh using gssapi will enforce FILE: credentials cache

2022-07-08 Thread Andreas Hasenack
** Also affects: openssh via https://bugzilla.mindrot.org/show_bug.cgi?id=3203 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssh in Ubuntu.

[Touch-packages] [Bug 1889548] Re: ssh using gssapi will enforce FILE: credentials cache

2020-08-26 Thread Toby Blake
Hi there, I'm afraid I haven't had much time to look properly into this recently, but it remains on my list. In the meantime, I've submitted an enhancement request upstream: https://bugzilla.mindrot.org/show_bug.cgi?id=3203 Cheers Toby ** Bug watch added: OpenSSH Portable Bugzilla #3203

[Touch-packages] [Bug 1889548] Re: ssh using gssapi will enforce FILE: credentials cache

2020-08-10 Thread Toby Blake
Hi Christian, Again, thanks for the above. https://bugzilla.mindrot.org/show_bug.cgi?id=2775, in particular, looks interesting, as it seems to be an attempt to bring the relevant ccache patches up to date for version 8. e.g. we have been patching our SL systems additionally for

[Touch-packages] [Bug 1889548] Re: ssh using gssapi will enforce FILE: credentials cache

2020-08-07 Thread Christian Ehrhardt 
Due to that hint with SciLinux I have fetched http://ftp.scientificlinux.org/linux/scientific/7.8/SRPMS/vendor/openssh-7.4p1-21.el7.src.rpm I can't see it but that is https://bugzilla.redhat.com/show_bug.cgi?id=991186 I can see follow on issues referring to it

[Touch-packages] [Bug 1889548] Re: ssh using gssapi will enforce FILE: credentials cache

2020-08-06 Thread Toby Blake
Hi Christian, Thanks for your reply (and for the links). I agree that a configurable option coming from upstream would be the preferred option. I'll submit a bug upstream accordingly and note the ID here. I note there's a patch referenced in the openssh mailing list link, unfortunately the

[Touch-packages] [Bug 1889548] Re: ssh using gssapi will enforce FILE: credentials cache

2020-08-04 Thread Christian Ehrhardt 
Hi Toby, It seems that is an ongoing topic for years, I've found this discussed from the KRB POV [1] and on openssh [2]. Especially following [1] it seems things aren't too easy but there are a few workarounds/hints that might or might not help your use case. In general having this configurable