Does KRB5_TRACE logging ever print sensitive info? (like passwords)

2017-06-21 Thread pratyush parimal
Hi all, I was wondering that in order to debug kerberos issues on a production machine, would it be a good idea to enable trace logging via KRB5_TRACE, for a small amount of time ? I have experimented with kerberos trace logging in a test environment with commands like kinit, kadmin, and other pr

Re: Does KRB5_TRACE logging ever print sensitive info? (like passwords)

2017-06-21 Thread Greg Hudson
On 06/21/2017 11:03 PM, pratyush parimal wrote: > I have experimented with kerberos trace logging in a test environment with > commands like kinit, kadmin, and other programmatic calls to GSSAPI and > never came across passwords or anything sensitive printed in the trace log. > It mainly showed me