Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM
Russ Allbery <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Harry Coin <[email protected]> writes: > On 10/14/2011 11:28 AM, Russ Allbery wrote: >> In other words, adding an alt_auth_map=%s/root to the PAM configuration >> is equivalent to giving every user a .k5login file that lists both >> user@REALM and user/root@REALM and then using search_k5login. It >> allows the /root instance to be used to authenticate to their personal >> UNIX account. > Is it really equivalent to that .k5login entirely? It is not, since > krb5_kuserok will not associate users and principals what pam_krb tries > to fix with this. So, stacks that don't call upon pam: gssapi, sasl, > nfs... will not associate the principals pam_krb5 does. Yes, I was only talking in the pam-krb5 context, not in general. -- Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/>