Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM

Russ Allbery <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization The Eyrie
Message-ID <[email protected]>
[email protected] writes:

> I have seen already a couple of generations of system administrators who
> become very skilled in implementing hacks and workarounds. Of course
> they do solve problems of the day - problems which often would not be
> there were it not the confusing design from the beginning.

Okay, I have to admit that this statement warms my heart, as that's
exactly the sort of thing that I tend to say to other people.  :)

I'm not sure I really have anything more to add, since I think we
understand each other fairly well and are coming at the problem from
different angles.  I've not been convinced by the sharp definition that
you have of authorization, but I can also see the merits in what you're
saying.  I'll at least go think about it and see if I can come up with a
way to improve the pam-krb5 documentation so that people at least
understand the distinctions and have pointers towards appropriate
resources for adding more systematic authorization if they want it.

Thank you for the discussion!

-- 
Russ Allbery ([email protected])             <http://www.eyrie.org/~eagle/>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.