Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM

Nico Williams <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <CAK3OfOiCTXF8NSn3Kq0BYqHNE=Ya5Cv9pc4quuWDEVMSpbMaCw@mail.gmail.com>
On Wed, Oct 26, 2011 at 2:37 PM, Jeffrey Hutzelman <[email protected]> wrote:
> No; there's a third option, which is that apache is _not_ a proxy, but
> also doesn't run with more access than it needs to do its job.  In fact,
> to run the non-proxy case as you suggest would a gross violation of the
> principle of least privilege.

I'd meant to say something about Apache needing the union of access
rights that its users need to access those resources through it, but
forgot to.  In many edge service deployments, however, there's not
much difference between that and having all privileges that future
legitimate users might need too.

Nico
--
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.