Re: multimple domain authentication

Micah Stetson <[email protected]> Wed, 1 Sep 2004 22:28:53 -0700
Newsgroups gmane.os.plan9.nine-grid
Message-ID <20040902052853.GA29986@epaphras>
> unless someone want to code up some 'orribly complex
> group rights nonsense.

I should just shut up, and I will.  But I don't intend
something complex.  I'm just saying (probably poorly)
that if you're giving some access to users whose names
aren't previously known to a file server, the file server
needs to have some notion of those users' rights.  So
you probably need to mess with fossil (and maybe others)
and think/work out the issues.  I was just thinking of
having default rights (maybe nothing) for unknown users
in trusted domains and the ability to override that
default for specific users/domains, probably by adding
them to a local group.  I thought about having the AS
manage group membership and pass those things around,
but I didn't mean to suggest that -- that probably would
get "'orribly complex".  It just sounded to me like Andrey
was saying fossil wouldn't be affected, and Ron was saying
that the file servers could be ignored because we weren't
concerned with serving files.  I probably misunderstood.

Sorry for the noise,

Micah