Re: Open issues on draft-ietf-krb-wg-general-pac

Simo Sorce <[email protected]>
Newsgroups gmane.ietf.krb-wg
Organization Red Hat, Inc.
Message-ID <[email protected]>
On Wed, 2012-02-15 at 15:18 -0600, Nico Williams wrote:
> On Wed, Feb 15, 2012 at 11:45 AM, Sam Hartman <[email protected]> wrote:
> > 4) Why is it domain not realm?
> >
> > Some of this has been fixed in the recent draft, but we should have a better understanding of where we
> 
> Because it's getting to be time to accept that realms are named after
> domains?  :)  But, sure, the right thing is to say "realm".
> 
> > 6)  Home directories and URIs
> >
> > Will require discussion on the list.
> 
> We had one today on the concall.
> 
> Simo seemed to think that the URIs would be for all the possible
> locations of a user's home directory on potentially thousands of
> servers.  But that's not the case, at least I can't think of any case
> where one would want that, and IIUC neither could Jeff H.

No, I think this could be used badly, and have environments that have
10s or 100s of URIs.
But, after some consideration I think that the admins should be free to
shoot themselves in the foot in this case, they can as easily remove
URIs as they add them.

> My point is that a POSIX path can be a URI (/net/server/path) or not,
> but if not and there's no local homedir then we'll need... a federated
> automount map?  No, that's too much complexity.  What Jeff and I are
> asking for would be optional: a sequence of zero, one, or more URIs,
> but probably never more than one per relevant URI scheme.  Even if
> Simo himself has no use for this Jeff and I believe we do.

I think I can accept this request, and leave to the implementation the
freedom to implement storing multiple URIs or paths in the PAD or not.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York

_______________________________________________
ietf-krb-wg mailing list
[email protected]
https://lists.anl.gov/mailman/listinfo/ietf-krb-wg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.