Hi Jochen,

On Do 26 Jan 2012 15:13:58 CET Jochen Schulz wrote:

3) we use kerberos here and to correctly pass the the KRB5CCNAME to the
running session i wrote a line with "export KRB5CCNAME" in
x2goruncommand. This also is now obsolete because you implemented
Xsession-support.

I use Kerberos a lot, too, and have not needed this so far. Even without
x2goserver-xsession installed. Could you specifiy on this?

for the principle functionality of authentification/authorization via
kerberos there is no problem. To succesfully use single-sign-on with
kerberos or be able to held a kerberos-authorized nfsv4 mount you need a
valid ticket-cache all the time and the software must know where to look
(KRB5CCNAME). the way x2goruncommand was doing it, the started session
(in our case it is gnome-session) didn't know anything about KRB5CCNAME
and also all subsequent processes didn't know either.

committed:
http://code.x2go.org/gitweb?p=x2goserver.git;a=commitdiff;h=6e50ee147551291fc4dc8cd8a8d9a9817da7f90b

Greets,
Mike


--

DAS-NETZWERKTEAM
mike gabriel, dorfstr. 27, 24245 barmissen
fon: +49 (4302) 281418, fax: +49 (4302) 281419

GnuPG Key ID 0xB588399B
mail: [email protected], http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb

Attachment: pgpv3Rt5yhaCR.pgp
Description: Digitale PGP-Unterschrift

_______________________________________________
X2go-Dev mailing list
[email protected]
https://lists.berlios.de/mailman/listinfo/x2go-dev

Reply via email to