Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM
Russ Allbery <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
[email protected] writes: > I have seen already a couple of generations of system administrators who > become very skilled in implementing hacks and workarounds. Of course > they do solve problems of the day - problems which often would not be > there were it not the confusing design from the beginning. Okay, I have to admit that this statement warms my heart, as that's exactly the sort of thing that I tend to say to other people. :) I'm not sure I really have anything more to add, since I think we understand each other fairly well and are coming at the problem from different angles. I've not been convinced by the sharp definition that you have of authorization, but I can also see the merits in what you're saying. I'll at least go think about it and see if I can come up with a way to improve the pam-krb5 documentation so that people at least understand the distinctions and have pointers towards appropriate resources for adding more systematic authorization if they want it. Thank you for the discussion! -- Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/>