On Sat, 8 Apr 2006, Nicolas Williams wrote:
I doesn't have to. This can be a local matter. And in at least one implementation it is.
For the record, patches existed for OpenSSH which provided this feature (for Kerberos and GSI, at least). It was included in the original code drop that was provided to the OpenSSH folks, but was one of the features removed in the interests of simplifying the code when GSS userauth was integrated.
It was implemented in the same way as storage of delegated credentials is implemented - by providing mechanism specific routines.
S.