[1778] in Kerberos

home help back first fref pref prev next nref lref last post

OSF/DCE Kerberos Questions

daemon@ATHENA.MIT.EDU (Steve Clark)
Wed Feb 26 18:59:29 1992

Date: Wed, 26 Feb 92 21:53:18 GMT
From: seclark@iscnvx.lmsc.lockheed.com (Steve Clark)
To: kerberos@shelby.Stanford.EDU

I appreciate help from anyone regarding these questions:

Q1:  Will OSF/DCE Kerberos authentication and authorization using ACLs
     permit a user with client-name (principal-name)  "USER_A"   to access
     a service using a local account-name  of  "USER_B"   (access to accounts
     with names that are different from the Kerberos client-name) ?

Q2:  Will  DCE  allow me to  prevent  a  Kerberos client (principal)  "USER_A"
     from accessing a  service  with local account-name   "USER_A"  (there
     may be accounts on different hosts that have the same name,  but they may
     belong to different individuals and a way to prevent authorization is
     needed).

Q3:  Will  "krb_kntoln"   (/etc/aname  feature)  be supported by DCE
     out-of-the-box,  as  a user-hook,  or not at all?

Q4:  Are  .klogin  files  supported by DCE Kerberos?

home help back first fref pref prev next nref lref last post