Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM
Russ Allbery <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Harry Coin <[email protected]> writes: > All the atmospherics vented here with such finality. Yet nobody on this > list seems the least concerned that right here and now kerberos/heimdal > style is incapable of allowing all existing applications to do as they > did for all users prior, via the most standard and widespread inter-*nix > os networking scheme out there: NFS. I don't believe NFS is even remotely the most standard and widespread inter-UNIX networking scheme. For example, Stanford doesn't use it in any serious way at all (other than some internal unauthenticated NFSv3 via separate storage networks as essentially an iSCSI substitute) because we have a better (for our purposes) network file system. I think part of your confusion is that your introduction to Kerberos was apparently Kerberized NFS, which is, from the perspective of Kerberized services in general, very weird. And therefore you've internalized several of the bizarre oddities of Kerberized NFS as being typical of Kerberos and GSS-API, when in fact they're just weird implications of NFS, and those of us who neither use nor have any interest in NFS are just going "huh?" So yes, you to an extent correct that I am not in the least bit concerned with NFS. I don't use the protocol and don't find it particularly interesting. -- Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/>