root/ host/ <uid 0 service like nfs>/ ?!?
Harry Coin <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
Is there a settled intention or reference for the nuances among 'uid 0 principals'? Though I don't see it set forth as such, my sense is that for principals: root/<fqdn>@REALM is intended to mean a person logged in and issuing commands as local uid 0 / root on <fqdn>. <other-than-host>/<fqdn>@REALM is intended to be the name of a daemon/service/non-person-with-at-least-one-process-id, possibly with uid:0, running on <fqdn>. Viz: nfs4 server/0. ldap uid varies *bsd/*nix, etc. host/<fqdn>@REALM is intended to be a 'catch all' principal for all uid:0 services running on <fqdn> that, well, what? Missed the memo above? Got it correct? What? Is there consensus about what 'best practice' is in this regard?