Re: multimple domain authentication

Eric Grosse <ehg-b/[email protected]> Wed, 01 Sep 2004 18:52:25 -0400
Newsgroups gmane.os.plan9.nine-grid
Message-ID <[email protected]>
I don't recall the context of that remark, but it seems doubtful
to me.  The Plan 9 authentication mechanism depends on shared keys
that would be missing from that attempt to proxy if the mediator
doesn't do any rewriting.

The role of /lib/ndb/auth is indeed to hold "speaks for" relations,
so it is a natural place to put the authentication by indirection.
But this isn't something you can do today with existing mechanisms,
as far as I know.

andrey mirtchovski wrote:

>>How do we do this?
>>
> 
> 
> by having the local auth server act as a mediator between the client
> and its authentication server.  i think ehg said it's possible to be
> able to transport keys securely between the two and only snoop the
> final result -- success of failure (again, i may be wrong with this :)
> 
> /lib/ndb/auth expands to hold information about authentication domains
> we can allow in, something like:
> 
> 	friendlyauth=plan9.ucalgary.ca
> 		uid=!bootes uid=!someoneidontlike uid=*
> 
> doable?
> 
> _______________________________________________
> 9grid mailing list
> 9grid-bRIBFEq44iy2p8tyqo/[email protected]
> http://nwn.definitive.org/mailman/listinfo/9grid
smime.p7s (application/x-pkcs7-signature, 13.9 KB) - not displayed