Re: aname_to_locaname vs gssapi svc/host.domain.org@REALM
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
Russ, What you say looks like the best feasible outcome. Thanks! Rune On Sun, Oct 30, 2011 at 11:22:20AM -0700, Russ Allbery wrote: > I'm not sure I really have anything more to add, since I think we > understand each other fairly well and are coming at the problem from > different angles. I've not been convinced by the sharp definition that > you have of authorization, but I can also see the merits in what you're > saying. I'll at least go think about it and see if I can come up with a > way to improve the pam-krb5 documentation so that people at least > understand the distinctions and have pointers towards appropriate > resources for adding more systematic authorization if they want it. > > Thank you for the discussion! > > -- > Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/> >