Re: Open issues on draft-ietf-krb-wg-general-pac
Nico Williams <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <CAK3OfOiMxTG2dEUjy7p7pYjirMQUOa20XD8rEtcqOL9PEgbGuQ@mail.gmail.com> |
On Wed, Feb 15, 2012 at 1:24 PM, Simo Sorce <[email protected]> wrote: >> * renaming of domains >> >> Are there any semantics KDCS and services must follow? > > I would say the actual renaming of realms is not in scope. > What the UDID allows is to handle file permissions for those systems > that us a 'Domain ID' to store Access Control Lists. Admittedly only > Windows and Solaris with ZFS do that now. On other Posix sytsems Samba > emulates that by storing ACLs in extended attributes. > So this is also an interop attribute used by those system that have a > concept of domain namespaces for user/group identifiers. I'd like to clarify that it's ZFS much more than Solaris that stores SIDs on disk. ZFS has been ported to numerous other operating systems (MacOS X, FreeBSD, Linux, and probably others), and while it probably doesn't store SIDs on any of those at this time, it may only be a matter of time until it does. Also, there are OpenSolaris-derivatives that do store SIDs on disk in ZFS, but they are not Solaris proper. Back to the domain/realm rename issue, my position is as follows: I'd like domain/realm rename to be feasible, but in a pinch I'll settle for declaring that to be infeasible, but the I-D (and ultimately the RFC) must be explicit on this point. But first we should make an effort to make this feasible. It would help now to discuss what's necessary in order to support domain/realm renames. I believe there's two ways to do this: Domain/realm rename method 1: assign unique IDs to domains/realms and preferably also provide a name resolution mechanism. Domain/realm rename method 2: pass around {current-name, [original-name], date-created} in the PAD. This is sufficient to allow filesystems to store {original-name, date-created} and does not require a name resolution mechanism. I prefer method 2 because it seems simpler, though it does require that KDC keep a history of domain/realm renames (something that I think is fair to assume, at least within a "forest"). We may need to have a notion of domains/realms being members of zero, one, or more forests, and we may want such forest names to appear in the PAD. Nico -- _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg