Re: multimple domain authentication
[email protected] Wed, 1 Sep 2004 15:55:38 -0700
| Newsgroups | gmane.os.plan9.nine-grid |
|---|---|
| Message-ID | <[email protected]> |
Actually my proposal doesn't allow laundering. The point of looking at the caller's IP address is to determine which auth server to contact to *attempt* to authenticate the callers's claimed identity. This isn't blind stupid authentication like BSD .rhosts. If you launder your connection, we contact the wrong auth server and you can't authenticate. You (or your factotum) still have to prove who you are, cryptographically.