Re: Re: [OpenAFS] OpenAFS for Windows - outstanding projects report and call for testers
Jeffrey Altman <[email protected]>
| Newsgroups | gmane.comp.file-systems.openafs.devel.win32 |
|---|---|
| Organization | No Longer Affiliated with Columbia University in the City of New York |
| Message-ID | <[email protected]> |
The concept of a "default cell" for the client service is very specific in meaning. The default cell is the cell from which the afs client service obtains the root.afs volume. There is nothing user specific about this "default". In fact, when dynamic roots (freelance mode on windows) are in use there is no "default cell" at all. This is because the root.afs volume which is used is created locally within the afs client service. At the present time, the afs client's default cell name is also used for another purpose. It is used as the default cell for user authentication in afscreds.exe, aklog.exe, klog.exe, leash32.exe, etc. However, there is no reason why there should be such a binding. Especially on a multi-user system with roaming profiles. I may want to have my default authentication cell be athena.mit.edu even though the local afs client is bound to secure-endpoints.com. The windows client already supports obtaining tokens for multiple cells from a single Kerberos 5 principal. When viewed in this perspective is the concept of a single default cell for authentication even desireable? What I really want is for AFS to be smart enough to know that with my [email protected] TGT I can obtain afs tokens for athena.mit.edu, grand.central.org, dementia.org, secure-endpoints.com, etc. In this case I don't really have a default cell, but a collection of cells. When I authenticate I want to obtain tokens for all of them. This is the direction I am headed. Jeffrey Altman Tim C. wrote: > I like most of the changes, and I'd like to say thanks! :) I had a >question about the long term projects. > > > >> 1. No longer use AFS Client Service "cell" as the default cell for >>individual users >> >> >> > What does this mean? Is this saying that the default cell for the >machine as a whole won't be the default cell for users? On unix, the >ThisCell file defines the default cell, and its the default cell for >everyone. Will the windows client not follow this behavior? So people >will be able to set their default cell? I'm not too sure I like this. > >Thanks, > Tim > >----------------------------------------------------------------------- >Tim Craig These are my opinions and not my employers. :) >OIT-Systems >[email protected] It's hard to be serious when you're > naked. - Garfield >----------------------------------------------------------------------- >_______________________________________________ >OpenAFS-Win32-devel mailing list >[email protected] >http://lists.openafs.org/mailman/listinfo/openafs-win32-devel > >
smime.p7s
(application/x-pkcs7-signature, 3.2 KB) - not displayed