2. A client may not have access to the session keys in its ccache, e.g. if it’s using gssproxy.
I have a patch to libkrb5 which implements a feature similar to the SSLKEYLOGFILE environment variable that’s now in pretty wide use for
TLS: it logs session keys to a keytab named by KRB5KEYLOGFILE. The main
use for this, just as with the TLS version, is to decrypt packet
captures with Wireshark; the latter’s KRB5 dissector takes a keytab as input.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (0 / 16) |
Uptime: | 162:12:13 |
Calls: | 10,385 |
Calls today: | 2 |
Files: | 14,057 |
Messages: | 6,416,501 |