Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM
Nico Williams <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <CAK3OfOiCTXF8NSn3Kq0BYqHNE=Ya5Cv9pc4quuWDEVMSpbMaCw@mail.gmail.com> |
On Wed, Oct 26, 2011 at 2:37 PM, Jeffrey Hutzelman <[email protected]> wrote: > No; there's a third option, which is that apache is _not_ a proxy, but > also doesn't run with more access than it needs to do its job. In fact, > to run the non-proxy case as you suggest would a gross violation of the > principle of least privilege. I'd meant to say something about Apache needing the union of access rights that its users need to access those resources through it, but forgot to. In many edge service deployments, however, there's not much difference between that and having all privileges that future legitimate users might need too. Nico --