Hi Simo,

 > Yes this is true, it would be best to just accept * and let the gssapi
 > library find a match within the keys in the keytab.

To cope with possibly shared keytabs I was planning on using the
wildcard match code in bind and default it to DNS/*

 > Or you can collaborate with distros to get the patches in sooner.
 > That's what we did with bind in Fedora/RHEL. As soon as we knew the
 > patches would be accepted upstream we added them to the current
 > distribution.

There is more to Samba than just Linux distro builds. The range of
OSes people use is huge, and not all are as approachable about getting
their basic utilities updated.

Even with the big distros, how would we get updates for RHEL or SLES
out quickly? That takes a long time.

I suspect the total work of making bind do the right thing on all the
distros we care about may be of a similar magnitude to writing a new
DNS server, assuming Kai continues to progess as he has.

Cheers, Tridge

