We have users internally that want to run sometimes as a "build" user we
have. In our pre-Kerberos we'd just add sudo's to their machines. We can
still do this, however they obviously don't get a tgt for this build
user, so they can't access any kerberized apps as this build user,
without typing in the password.

Is there any method for a principle to be allowed to obtain another
principle's tgt (given a valid tgt for the first principle)? A kind of
sudo for tgt's (Without just leaving around keytabs).


Colin Simpson
Network Manager
Concept Systems Ltd

