Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM

Love Hörnquist Åstrand <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <[email protected]>
12 okt 2011 kl. 02:56 skrev Harry Coin:

> So, kindly look at https://github.com/heimdal/heimdal/blob/master/lib/krb5/aname_to_localname.c. 

aname_to_localname is compatibility and glue that help network server that don't transport username as part of the protocol.

Its exists because server writers can't create authorization system, services like NFS needs to mange their own authorization decisions and map  gss name to their own internal identifier, just like its done in AD, AFS and apparently coda too.

Having implicitly rights just because of the existence of a kerberos principal, make life too complicated and doesn't allow sane group management. For example in the NFS case, webservers can see web tree but no other machines.

Mapping user/root -> root is a convention used at KTH and round in stockholm, it have zero impact on security unless you also put that principal into roots .k5login file. It also matches behaivor of (k)su.

Love
smime.p7s (application/pkcs7-signature, 4.3 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.