Re: [RFC PATCH] CIFS posix acl permission checking
Volker Lendecke <[email protected]>
| Newsgroups | gmane.linux.file-systems.cifs |
|---|---|
| Organization | SerNet GmbH, Goettingen, Germany |
| Message-ID | <[email protected]> |
On Fri, Mar 12, 2010 at 07:58:03AM -0500, simo wrote: > > The reason why my customer wants to get away from NFS is the > > 16 groups limit. Different question: Why is s4u2proxy more > > secure than allowing "su - <user>" over cifs? > > Because you can control at the KDC level which tickets the server is > allowed to get. And without giving out user credentials or even root > credentials. And because this way you don't change the security model. Ok. Which KDCs support this? Volker _______________________________________________ linux-cifs-client mailing list [email protected] https://lists.samba.org/mailman/listinfo/linux-cifs-client
signature.asc
(application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkuaO4kACgkQbZMKAi3WUklkSwCdE57n5uXOBfwlj1wOI+5IirWW GLQAnA/jwjBnOdg5ZpdFTuwMgxSU6D2L =BJX8 -----END PGP SIGNATURE-----