Default libkrb5 ccache location

Lennart Poettering mzerqung at 0pointer.de
Tue Jul 30 21:55:37 UTC 2013


On Tue, 30.07.13 08:34, Stephen Gallagher (sgallagh at redhat.com) wrote:

> >> The problem with /tmp is that if you want predictable filenames
> >> for the storage, you open yourself to a denial-of-service attack
> >> where another user can create a file with the same name.
> > 
> > Well, but that's not unsurmountable, just pick a randomly named 
> > directory in /tmp and make sure to have a symlink:
> > 
> > ln -s /tmp/krb.XXXXXX "$HOME/.krb-`cat /etc/machine-id`"
> > 
> 
> Picking a random name brings us back to one of the original problems
> we needed to solve: random names make life *miserable* for daemons
> like GSSD that need to find the appropriate credentials for a user.

Hence give the random name stability via a stable symlink. Please read
what I actually wrote.

Lennart

-- 
Lennart Poettering - Red Hat, Inc.


More information about the devel mailing list