![]() |
cosign-discuss at umich.edu |
general discussion of cosign development and deployment | |
Thanks for the reply on the hardware and all, very helpful.
CoSign and Kerberos question. When an application requests a Kerberos ticket
(the RETRIEVE command to cosignd) it appears to be allowed to specify the
ticket name (eg imap/imap.auckland.ac.nz@xxxxxxxxxxxxxx). This looks to be a
service account (in the examples I have seen), does this mean that a service
ticket is passed back to the application, and not a/the TGT the cosign CGI
obtained to authenticate the user?