#765655 openssh: please clarify documentations for GSSAPI's cascading credential feature

Package:
src:openssh
Source:
openssh
Submitter:
Christoph Anton Mitterer
Date:
2026-08-23 11:43:05 UTC
Severity:
wishlist
Tags:
#765655#5
Date:
2014-10-17 02:05:22 UTC
From:
To:
Hi Colin.

I would find the attached patch to be a useful addition
to the description of the two options regarding cascading
credentials in the manpages.

Could you please have a look at it and if you like it
merge it with your gssapi.patch?

Thanks,
Chris.

#765655#10
Date:
2014-10-17 02:24:50 UTC
From:
To:
Oh, and I've just seen that there is also an issue with the quotation
marks:
     GSSAPITrustDns
             Set to “yes to indicate that the DNS is trusted to securely canonicalize” the
             name of the host being connected to. If “no, the hostname entered on the”
             command line will be passed untouched to the GSSAPI library.  The default is
             “no”.  This option only applies to protocol version 2 connections using GSS‐
             API.
which is corrected by a 2nd patch attached to this mail.


Colin, you possibly further please clarify, which of the options added
by gssapi.patch, actually require GSSAPI key exchange?


Thanks,
Chris.

#765655#15
Date:
2014-10-17 02:30:17 UTC
From:
To:
Christoph Anton Mitterer <calestyo@scientia.net> writes:

Hi Christoph,

The GSSAPI patch is actually maintained by Simon Wilkinson at:

http://www.sxw.org.uk/computing/patches/openssh.html

Many different distributions incorporate it.  For issues that are generic
to any packaging of ssh with that patch, you may want to report them
directly to Simon, or at least copy him on these reports, and he's
probably the best person to ask questions about how the patch works.

#765655#20
Date:
2014-10-17 02:45:09 UTC
From:
To:
tags 765655 + upstream
stop

Hi Simon.

Russ Allerby just reminded me that these things should go upstream
respectively that you can likely answer them.

Could you please have a look at:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765655

Thanks,
Chris.