On Mon, Oct 24, 2011 at 08:56:53PM -0500, Nico Williams wrote:
> I'm having a hard time parsing what you write. But if I understand
Harry, no offence but I second Nico's impression, it is not
always clear what you mean by certain terms.
> correctly you want *per-share* mappings of principals to authorization
> IDs. That would require changes to the application -- changes to the
> Kerberos library alone could not provide that feature. (Note that
> Solaris, for example, allows only per-share mapping options for
> *root*, not any other local accounts. What you're asking for, if I
> understood correctly, is a fairly large, though perhaps desirable
> change to NFS servers.)
This summary looks reasonable to me, without knowing how much
it corresponds to Harry's intentions.
> If you want a DB, well, I'll be adding a plugin for an aname2lname DB.
> And I'll probably include a default plugin that uses a binary search
> on a sorted file where every line consists of <principal> <username>,
> or something like that.
Nico, will an application have a way to point out an application-specific
database instance (== mapping)? Populate its database instance? Populate
in advance?
Rune
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.