Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM
Russ Allbery <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Nico Williams <[email protected]> writes: > But again, *daemons* have NO business using NFS resources unless the > host is a diskless NFS client. Sure they do. Web servers serving out authenticated NFS content, daemons rotating their logs into a network file system, backups pushing data into a network file system from local database servers, access to protected configuration files stored in a network file system for convenience, daemons whose entire purpose is to access files on behalf of a user... I could go on. This sort of thing is extremely common in the AFS world and has been for quite some time. In fact, NFS's traditionally poor handling of this compared to the AFS token mechanism is in my mind one of the flaws in NFS (which seems to slowly be improving). -- Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/>