Skip Menu |
 

Subject: 2.6.5 too aggressive about dialog popup with network change
When 2.6.5 currently detects the network has changed, it popups up the Authenticate to
Kerberos dialog. This behavior is too aggressive as it requires user interaction to
authenticate or dismiss at a time when the user may actually need to.

KfM is less aggressive. Even if it detects that the tickets may be invalid, it does not popup the
dialog until and application actually attempts to use Kerberos. KfM does have slightly
inconsistent behavior in that if the application is using GSS/Krb5 and has addressless tickets,
KfM still won't popup the dialog even though Kerberos.app (Panther) displays the tickets as
invalid, because of the v4 IP address being different. However this behavior is still beneficial
to the user.

Change is to make the popup happen when a Kerberos application makes a call rather than
solely network change, and then, only when needed.
[mjv - Wed Oct 20 11:01:14 2004]:
Show quoted text
>authenticate or dismiss at a time when the user may actually need to.

Edit: when the user may not actually need to (i.e. not Kerberized connections are happening
at that point)
Date: Wed, 20 Oct 2004 12:17:56 -0400
From: Jeffrey Altman <jaltman@mit.edu>
To: rt-kfw-comment@krbdev.mit.edu
Subject: Re: [krbdev.mit.edu #2749] 2.6.5 too aggressive about dialog popup with network change
RT-Send-Cc:
This feature was added to KFW prior to the application triggered popups.
It should probably be given its own configuration option now.
Download smime.p7s
application/x-pkcs7-signature 3.1KiB

Message body not shown because it is not plain text.

Leash has been replaced by Network Identity Manager in KFW 3.0