Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM
Love Hörnquist Åstrand <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
12 okt 2011 kl. 02:56 skrev Harry Coin: > So, kindly look at https://github.com/heimdal/heimdal/blob/master/lib/krb5/aname_to_localname.c. aname_to_localname is compatibility and glue that help network server that don't transport username as part of the protocol. Its exists because server writers can't create authorization system, services like NFS needs to mange their own authorization decisions and map gss name to their own internal identifier, just like its done in AD, AFS and apparently coda too. Having implicitly rights just because of the existence of a kerberos principal, make life too complicated and doesn't allow sane group management. For example in the NFS case, webservers can see web tree but no other machines. Mapping user/root -> root is a convention used at KTH and round in stockholm, it have zero impact on security unless you also put that principal into roots .k5login file. It also matches behaivor of (k)su. Love
smime.p7s
(application/pkcs7-signature, 4.3 KB) - not displayed