Received: from PACIFIC-CARRIER-ANNEX.MIT.EDU by po7.MIT.EDU (5.61/4.7) id AA15482; Thu, 14 Dec 95 21:26:24 EST
Received: by MIT.EDU 
	id AB11605; Thu, 14 Dec 95 21:26:23 EST
Date: Thu, 14 Dec 95 21:26:23 EST
From: MAILER-DAEMON@MIT.EDU (Mail Delivery Subsystem)
Subject: Returned mail: Cannot send message for 3 days
Message-Id: <9512150226.AB11605@MIT.EDU>
To: <gaskell@dstc.qut.edu.au>
To: proven@PO7.LOCAL
To: tytso@PO9.LOCAL
To: basch@lehman.com
To: jis@E40-PO.LOCAL
To: tlyu@PO9.LOCAL

   ----- Transcript of session follows -----
421 gardenia.saclay.cea.fr.tcp... Deferred: Connection timed out during user open with oeillet.saclay.cea.fr
451 zucco@gardenia.saclay.cea.fr... Cannot send message for 3 days
zucco@gardenia.saclay.cea.fr... Cannot send message for 3 days

   ----- Unsent message follows -----
Received: from typhoon.dstc.qut.edu.au by MIT.EDU with SMTP
	id AA10089; Mon, 11 Dec 95 21:00:46 EST
Received: (from gaskell@localhost) by typhoon.dstc.qut.edu.au (8.7.3/8.7.3) id MAA24701; Tue, 12 Dec 1995 12:00:28 +1000 (EST)
Date: Tue, 12 Dec 1995 12:00:23 +1000 (EST)
From: Gary Gaskell <gaskell@dstc.edu.au>
X-Sender: gaskell@typhoon.dstc.qut.edu.au
To: Douglas Engert <b17783@achilles.ctd.anl.gov>
Cc: kerberos@MIT.EDU, David Conran <conran@dstc.edu.au>,
        Jason Andrade <jason@dstc.edu.au>,
        Andrew Sammut <sammut@dstc.qut.edu.au>
Subject: Using krb in a multiple realm environment
In-Reply-To: <199507191236.HAA13196@achilles.ctd.anl.gov>
Message-Id: <Pine.OSF.3.91.951212114748.741N-100000@typhoon.dstc.qut.edu.au>
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII


Hi Doug, 

I thought you might be the best person to respond to this question.

The situation here is that six universities are involved in the DSTC.  
Currently our admins use kerberised rlogin to login securely to the 
various universities to perform admin tasks.  We have elected to do this 
via two different kerberos realms.

The usability question is:

The default is that only one TGT exists in the user's cache at once.  Now 
say that I am doing work locally (at realm = DSTC.QUT.EDU.AU) and what to 
concurrently do work at another university (At realm = DSTC.EDU.AU), when 
I kinit to the other realm, it wipes out the TGT to the current realm.  
Isn't that inconvenient?  

Would it be silly to hack the code to allow more than one TGT?  Anyone 
else hassled by this?

BTW, we found the bug with the ^c on OSF/1 3.2 on an alpha.  I haven't 
yet posted the fixes, as I wish to be very sure on the detail before I post 
to such an astute audience (as it appears we triggered a kernel 
"feature", and I must still write some exploratory code to replace the 
error independently of the Kerberos rlogind code).


regards


Gary Gaskell                         Cooperative Research Centre for
Research Scientist                   Distributed Systems Technology
DSTC                                 Ph:      61 7 3864 1051
Level 12, ITE Building               Fax:     61 7 3864 1282
Queensland University of Technology  Email:   gaskell@dstc.edu.au  
Brisbane, Australia.                 Ph (A/H) (07) 3857 7912
                                     Mobile:  0411 221 946
_________________________________________________________________

