Re: Bug in kinit and afslog

What's the status of libkopenafs?  IIRC Russ Allbery (just down hill  
from you) was working on getting Heimdal's libkafs generalized for  
inclusion in the AFS tree (or maybe he was trying to add the kafs API  
to the aklog code).  If you *know* you have the pt* calls available  
then it's not hard to put the right calls in libkafs place to fix the  

I think my current position is that the token shouldn't list a UID  
unless it got it from AFS.  For libkafs that means it should leave it  
blank unless it was told by the caller (e.g. ftpd) tells it what UID  
to include.  I have flip-flopped on this point a several times over  
the last couple of years however.

On Aug 1, 2007, at 10:41 AM, Alf Wachsmann wrote:

> On Wed, 1 Aug 2007, Ken Hornstein wrote:
>>> Maybe it would be better to put the principal name in the token
>>> instead of the potentially completely wrong UID?
>> I hate to ask ... why do you care what UID is in there?  It was  
>> only used
>> by one piece of software that I know of (the Andrew Mail System).
> I hope none of our scripts/software cares - but users do, incl.  
> myself.
> It is really irritating to look at your AFS token and see a UID that
> you don't expect. In most cases a user would not even try to use such
> a token because it is "just wrong".
> -- Alf.
