Re: Open issues on draft-ietf-krb-wg-general-pac

Nico Williams <[email protected]>
Newsgroups gmane.ietf.krb-wg
Message-ID <CAK3OfOiMxTG2dEUjy7p7pYjirMQUOa20XD8rEtcqOL9PEgbGuQ@mail.gmail.com>
On Wed, Feb 15, 2012 at 1:24 PM, Simo Sorce <[email protected]> wrote:
>> * renaming of domains
>>
>> Are there any semantics KDCS and services must follow?
>
> I would say the actual renaming of realms is not in scope.
> What the UDID allows is to handle file permissions for those systems
> that us a 'Domain ID' to store Access Control Lists. Admittedly only
> Windows and Solaris with ZFS do that now. On other Posix sytsems Samba
> emulates that by storing ACLs in extended attributes.
> So this is also an interop attribute used by those system that have a
> concept of domain namespaces for user/group identifiers.

I'd like to clarify that it's ZFS much more than Solaris that stores
SIDs on disk.
ZFS has been ported to numerous other operating systems (MacOS X, FreeBSD,
Linux, and probably others), and while it probably doesn't store SIDs
on any of those
at this time, it may only be a matter of time until it does.  Also, there are
OpenSolaris-derivatives that do store SIDs on disk in ZFS, but they
are not Solaris
proper.

Back to the domain/realm rename issue, my position is as follows:

   I'd like domain/realm rename to be feasible, but in a pinch I'll settle for
   declaring that to be infeasible, but the I-D (and ultimately the RFC) must
   be explicit on this point.  But first we should make an effort to make
   this feasible.

It would help now to discuss what's necessary in order to support
domain/realm renames.  I believe there's two ways to do this:

Domain/realm rename method 1: assign unique IDs to domains/realms
and preferably also provide a name resolution mechanism.

Domain/realm rename method 2: pass around {current-name,
[original-name], date-created} in the PAD.  This is sufficient to
allow filesystems to store {original-name, date-created} and does
not require a name resolution mechanism.

I prefer method 2 because it seems simpler, though it does require
that KDC keep a history of domain/realm renames (something that I
think is fair to assume, at least within a "forest").  We may need to
have a notion of domains/realms being members of zero, one, or more
forests, and we may want such forest names to appear in the PAD.

Nico
--
_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.