Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM

Russ Allbery <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization The Eyrie
Message-ID <[email protected]>
Harry Coin <[email protected]> writes:

> All the atmospherics vented here with such finality.  Yet nobody on this
> list seems the least concerned that right here and now kerberos/heimdal
> style is incapable of allowing all existing applications to do as they
> did for all users prior, via the most standard and widespread inter-*nix
> os networking scheme out there: NFS.

I don't believe NFS is even remotely the most standard and widespread
inter-UNIX networking scheme.  For example, Stanford doesn't use it in any
serious way at all (other than some internal unauthenticated NFSv3 via
separate storage networks as essentially an iSCSI substitute) because we
have a better (for our purposes) network file system.

I think part of your confusion is that your introduction to Kerberos was
apparently Kerberized NFS, which is, from the perspective of Kerberized
services in general, very weird.  And therefore you've internalized
several of the bizarre oddities of Kerberized NFS as being typical of
Kerberos and GSS-API, when in fact they're just weird implications of NFS,
and those of us who neither use nor have any interest in NFS are just
going "huh?"

So yes, you to an extent correct that I am not in the least bit concerned
with NFS.  I don't use the protocol and don't find it particularly
interesting.

-- 
Russ Allbery ([email protected])             <http://www.eyrie.org/~eagle/>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.