Re: multimple domain authentication

[email protected] Wed, 1 Sep 2004 15:55:38 -0700
Newsgroups gmane.os.plan9.nine-grid
Message-ID <[email protected]>
Actually my proposal doesn't allow laundering.  The point of looking
at the caller's IP address is to determine which auth server to
contact to *attempt* to authenticate the callers's claimed identity.
This isn't blind stupid authentication like BSD .rhosts.  If you
launder your connection, we contact the wrong auth server and you
can't authenticate.  You (or your factotum) still have to prove who
you are, cryptographically.