Re: multimple domain authentication
Eric Grosse <ehg-b/[email protected]> Wed, 01 Sep 2004 18:52:25 -0400
| Newsgroups | gmane.os.plan9.nine-grid |
|---|---|
| Message-ID | <[email protected]> |
I don't recall the context of that remark, but it seems doubtful to me. The Plan 9 authentication mechanism depends on shared keys that would be missing from that attempt to proxy if the mediator doesn't do any rewriting. The role of /lib/ndb/auth is indeed to hold "speaks for" relations, so it is a natural place to put the authentication by indirection. But this isn't something you can do today with existing mechanisms, as far as I know. andrey mirtchovski wrote: >>How do we do this? >> > > > by having the local auth server act as a mediator between the client > and its authentication server. i think ehg said it's possible to be > able to transport keys securely between the two and only snoop the > final result -- success of failure (again, i may be wrong with this :) > > /lib/ndb/auth expands to hold information about authentication domains > we can allow in, something like: > > friendlyauth=plan9.ucalgary.ca > uid=!bootes uid=!someoneidontlike uid=* > > doable? > > _______________________________________________ > 9grid mailing list > 9grid-bRIBFEq44iy2p8tyqo/[email protected] > http://nwn.definitive.org/mailman/listinfo/9grid
smime.p7s
(application/x-pkcs7-signature, 13.9 KB) - not displayed