Re: [RFC PATCH] CIFS posix acl permission checking
Volker Lendecke <[email protected]>
| Newsgroups | gmane.linux.file-systems.cifs |
|---|---|
| Organization | SerNet GmbH, Goettingen, Germany |
| Message-ID | <[email protected]> |
On Fri, Mar 12, 2010 at 07:35:42AM -0500, simo wrote: > > Ok, then we rule out batch machines where there are no user > > credentials. NFS does this fine. I know this is REALLY ugly, > > but I have customers who need this. If you have a good > > solution for that problem, I would really be happy to hear > > this. Something like constrained delegation in Kerberos to > > me sounds pretty much like the exact same hack in a > > different place. > > The solution in those case is probably S4U2PROXY, or NFS. The reason why my customer wants to get away from NFS is the 16 groups limit. Different question: Why is s4u2proxy more secure than allowing "su - <user>" over cifs? Volker _______________________________________________ linux-cifs-client mailing list [email protected] https://lists.samba.org/mailman/listinfo/linux-cifs-client
signature.asc
(application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkuaOJcACgkQbZMKAi3WUkm6DwCfb6RJWbFxQMEiYLUG8RRnJ83u rAUAoIACCRaRkNi4UvRVbspl+pL59iSo =FhyJ -----END PGP SIGNATURE-----