On Sat, Nov 19, 2016 at 07:11:25PM -0600, Dennis Gilmore wrote:
> koji authentication will be switching to Kerberos. Koji supports multiple 
> authentication mechanisms. Fedora infrastructure has set up a freeipa 
> instance 
> internally that has credential syncing to fas. We are working on ensuring 
> that 
> gssapi caching is supported so that you can have multiple TGT's and the 
> ability to work in multiple reams at once. you can get started today by doing 
> kinit <fas username>@FEDORAPROJECT.ORG if you move your ~/.fedora.cert file 
> out of the way authentication will still work.


  Can you expand (with links to webpages/wiki?) on multiple TGTs support?
At the moment, when I use kinit on F25, I get ticket for @FEDORAPROJECT.ORG 
realm,
but I lose my primary principal ticket. This means I lose access to my services,
including access to web proxy being my internet gateway.
  What's the trick to have _both_ tickets active – for my organisation and for
Fedora – at the same time?  This is using default Ticket cache: 
KEYRING:persistent:…

-- 
Tomasz Torcz              ,,If you try to upissue this patchset I shall be 
seeking
xmpp: zdzich...@chrome.pl   an IP-routable hand grenade.'' -- Andrew Morton 
(LKML)
_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Reply via email to