Re: multimple domain authentication

andrey mirtchovski <mirtchov-o/MP3MtDmzouExZ/[email protected]> Wed, 1 Sep 2004 16:27:58 -0600
Newsgroups gmane.os.plan9.nine-grid
Message-ID <[email protected]>
>> wouldn't that leave us with clashing usernames though?
> 
> nah, the username is user@authdom.  voilĂ , no clashes.
> 

would you care to implement that part?

by the way, what happens when i'm accessing bell-labs.com resources
from sdgm.net but i can only authenticate from ucalgary?

things aren't as simple as they seem and ip-based authentication isn't
enough.  in fact i have already used geoff's method for our unix ports
collection at ucalgary (which isn't functional right now), but
discovered that i wanted to be able to authenticate from two different
servers simultaneously, because there are people who haven't signed to
sources.cs yet still need to connect to our system. 

a real solution would allow the user to carry their authentication
origins everywhere they go (through the @domain username, perhaps?).
like an ID card -- no matter where this current connection is coming
from i'm still andrey from ucalgary and auth.ucalgary is the only
place that can confirm my identity.

andrey