Re: nfs client 'nobody no matter what' clarification was Re: k5userok .c / doc mismatch
Love Hörnquist Åstrand <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
> Nico, thanks. Freebsd has integrated heimdal. MIT's kerberos has advanced capabilities in the areas I need to make my current project functional right now today, but I don't see a documented way to specify it instead of heimdal. I'd be grateful to anyone who could point me to a single option somewhere that lets me 'recompile the freebsd kernel and userland world' with MIT's version. > > I urge the heimdal folk to recognize that there exists a category of realm usage which is 'more tightly controlled than usual' shall we say, where users with realm-wide single-sign on needs are very few and generally administrative in nature. On the other hand, I have plently of userX/fqdn principals in the way gssapi likes to see them, but there is no meaning for a principal userX@REALM. > > So, until you folks clarify the foggy future into code, I'm either going to have to write it myself only if that seems less bothersome than switching freebsd to MIT's kerberos. Harry, can you describe what your use cases and what your expectation are. Love
smime.p7s
(application/pkcs7-signature, 4.3 KB) - not displayed