Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM

Russ Allbery <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization The Eyrie
Message-ID <[email protected]>
Harry Coin <[email protected]> writes:
> On 10/14/2011 11:28 AM, Russ Allbery wrote:

>> In other words, adding an alt_auth_map=%s/root to the PAM configuration
>> is equivalent to giving every user a .k5login file that lists both
>> user@REALM and user/root@REALM and then using search_k5login.  It
>> allows the /root instance to be used to authenticate to their personal
>> UNIX account.

> Is it really equivalent to that .k5login entirely?  It is not, since
> krb5_kuserok will not associate users and principals what pam_krb tries
> to fix with this.  So, stacks that don't call upon pam: gssapi, sasl,
> nfs...  will not associate the principals pam_krb5 does.

Yes, I was only talking in the pam-krb5 context, not in general.

-- 
Russ Allbery ([email protected])             <http://www.eyrie.org/~eagle/>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.