From Newsgroup: comp.protocols.kerberos
2. A client may not have access to the session keys in its ccache, e.g. if itrCOs using gssproxy.
Oops, sorry -- thatrCOs a little off the mark. In that case of course session-key logging wonrCOt help the client directly, since it doesnrCOt perform those operations or call libkrb5 itself at all; the gssproxy daemon does. In that case werCOd apply KRB5KEYLOGFILE to the daemon. But there is a second reason nonetheless: itrCOs easier for debugging. A long-lived client process under observation could have its ccache flushed by ticket renewal or similar management, losing the needed session keys (and a mechanism like gssproxy could in fact have several ccaches it manages) -- whereas setting KRB5KEYLOGFILE would reliably capture them all without extra work.
--
Richard
--- Synchronet 3.21d-Linux NewsLink 1.2