Re: [RFC PATCH] CIFS posix acl permission checking

Volker Lendecke <[email protected]>
Newsgroups gmane.linux.file-systems.cifs
Organization SerNet GmbH, Goettingen, Germany
Message-ID <[email protected]>
On Fri, Mar 12, 2010 at 07:35:42AM -0500, simo wrote:
> > Ok, then we rule out batch machines where there are no user
> > credentials. NFS does this fine. I know this is REALLY ugly,
> > but I have customers who need this. If you have a good
> > solution for that problem, I would really be happy to hear
> > this. Something like constrained delegation in Kerberos to
> > me sounds pretty much like the exact same hack in a
> > different place.
> 
> The solution in those case is probably S4U2PROXY, or NFS.

The reason why my customer wants to get away from NFS is the
16 groups limit. Different question: Why is s4u2proxy more
secure than allowing "su - <user>" over cifs?

Volker

_______________________________________________
linux-cifs-client mailing list
[email protected]
https://lists.samba.org/mailman/listinfo/linux-cifs-client
signature.asc (application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkuaOJcACgkQbZMKAi3WUkm6DwCfb6RJWbFxQMEiYLUG8RRnJ83u
rAUAoIACCRaRkNi4UvRVbspl+pL59iSo
=FhyJ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.