Re: nfs client 'nobody no matter what' clarification was Re: k5userok .c / doc mismatch

Love Hörnquist Åstrand <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <[email protected]>
14 okt 2011 kl. 22:05 skrev Harry Coin:

> 1: Is it the case that the example principal 'alnumstring/[email protected]' will never be associated by heimdal (kuserok and friends) to any local account whatsoever, no matter the principal type, unless the local user is of the sort that has a default directory (e.g. not /nonexistent), and that directory has a .k5login file or k5login.d/, and that principal is among those in that(those) file(s)?

correct.

> and second,
> 
> 2: Asked to deduce a local user from a principal name as in example 1, heimdal will fail such requests always even if user alnumstring exists on the local system whose hostname is nfsclient and whose domain is domain.com and the default realm is DOMAIN.COM?

Correct, but this is krb5_aname_to_localname() and not krb5_kuserok().

Love
smime.p7s (application/pkcs7-signature, 4.3 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.