1
0
mirror of https://github.com/openbsd/src.git synced 2025-01-10 06:47:55 -08:00
openbsd-src/kerberosV
miod b8cf7916d5 Put back local change that allowed things to build on static-libs-only
arches, that was lost in last heimdal import.
Found the hard way by deraadt@.
2002-02-11 19:04:44 +00:00
..
doc Build and install Heimdal infofile. 2001-06-21 23:45:27 +00:00
include Put back local change that allowed things to build on static-libs-only 2002-02-11 19:04:44 +00:00
lib Misc. updates for heimdal-0.4e 2002-02-06 09:13:34 +00:00
libexec Misc. updates for heimdal-0.4e 2002-02-06 09:13:34 +00:00
src Fix misspelling 2002-02-06 13:37:14 +00:00
usr.bin Misc. updates for heimdal-0.4e 2002-02-06 09:13:34 +00:00
usr.sbin Misc. updates for heimdal-0.4e 2002-02-06 09:13:34 +00:00
Makefile SUDO correctly. 2001-06-27 17:54:43 +00:00
Makefile.inc Make kerberosV compile entirely on platforms lacking shared libraries, 2001-08-07 22:09:58 +00:00
README Added todo about kstash and library cleanup 2001-07-11 09:14:36 +00:00

Maintainer
==========

Please contact <hin@openbsd.org> if you have questions or problems.


Status of the code
==================

This code is currently beta quality code, but seems to work quite well.
Heimdal is used by several large University and Commercial sites.


Building
========

The kerberosV directory is now fully a part of the buildsystem, and a
regular "make build" process is the correct way to compile it.

The krb5.conf and krb5.keytab files have recently been moved to
/etc/kerberosV directory. If you've previously used this code you should
move those files.


Documentation
=============

Some documentation is available in the `heimdal' info-page, but it is currently
quite incomplete. A number of manpages for library functions are also
available.


BSD Auth
========

There's also a BSD Authentication login script in src/libexec/login_krb5,
but they are not enabled by default. Refer to login.conf(5), login(1),
login_krb5(8) and login_krb5-or-pwd(8) for more information on how to
enable them.


TODO
====

Things todo, in no particular order:

 - Make sure to not try krb5 auth when no ticket exists. (same goes for krb4)
   (i think this is actually ok, but it needs to be verified.)
 - Password quality checks in kpasswdd
 - krb5-config script
 - kx, kxd
 - rxtelnet, rxterm
 - pop-server and push
 - rsh, rshd
 - ssh and sshd
 - Test what happens for a user not using kerberos
 - Test all combinations of compat stuff between client, kdc and server
 - Slave propagation k5->k5 and k4->k5
 - Test and document how to upgrade a realm from k4 to k5
 - Test compatibility with other k5 implementations, for example MIT and
   Windows 2000, and document any caveats or tricks
 - Logging
 - Manpages are missing for many library functions, as well as a few
   programs. So we should document them and give back to the Heimdal project.
 - Fix /etc/rc and companions
 - Example configuration installed when system is installed
 - GSS-API support in our ftp client and server
 - Figure out how to deal with kstash
 - Reduce the number of libraries in kerberosV as well as kerberosIV,
   kerberosV:
	libasn1, libkadm5clnt, libkadm5srv, libhdb -> libkrb5
   kerberosIV:
	libacl, libkadm, libkdb -> libkrb
- Unify libroken, and put libsl and libcom_err in libroken