Re: choosing principal names
Harry Coin <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
On 10/5/2011 12:56 PM, Nico Williams wrote: > On Wed, Oct 5, 2011 at 11:55 AM, Love Hörnquist Åstrand<[email protected]> wrote: >> I think there should be very little kerberos programmers, there should be more gss programmers. > +1 > Hear the sound of the can getting kicked down the road. It is this group that defines the concept 'principal', it is this group that has written into its libraries uid sensitive default filenames, it is this group that has a toe in the water of every OS pond. Appreciating the desire not to create undue limitation enshrined in the code, is it too much to ask you publish consensus clear specific principal naming guidance across OS adopters at least for the non-person and system-admin actors? Guideance that shows appreciation for present concepts like 'root-as-a-box-specific-person-not-a-daemon-or-service', 'realm wide multihost service-xxx', 'box specific instance of service/daemon/server', 'non-person clients of the aforementioned'. This needs must originate from the place that imposes fixed default filenames and defines the concept 'principal'. In the alternative, tomorrow will look alot like yesterday.