Default libkrb5 ccache location
Lennart Poettering
mzerqung at 0pointer.de
Tue Jul 30 21:55:37 UTC 2013
On Tue, 30.07.13 08:34, Stephen Gallagher (sgallagh at redhat.com) wrote:
> >> The problem with /tmp is that if you want predictable filenames
> >> for the storage, you open yourself to a denial-of-service attack
> >> where another user can create a file with the same name.
> >
> > Well, but that's not unsurmountable, just pick a randomly named
> > directory in /tmp and make sure to have a symlink:
> >
> > ln -s /tmp/krb.XXXXXX "$HOME/.krb-`cat /etc/machine-id`"
> >
>
> Picking a random name brings us back to one of the original problems
> we needed to solve: random names make life *miserable* for daemons
> like GSSD that need to find the appropriate credentials for a user.
Hence give the random name stability via a stable symlink. Please read
what I actually wrote.
Lennart
--
Lennart Poettering - Red Hat, Inc.
More information about the devel
mailing list