[22079] in Kerberos

home help back first fref pref prev next nref lref last post

ACLs question

daemon@ATHENA.MIT.EDU (Bob Dowling)
Wed Jul 28 06:54:38 2004

Date: Wed, 28 Jul 2004 11:51:07 +0100 (BST)
From: Bob Dowling <rjd4@cam.ac.uk>
To: kerberos@mit.edu
Message-ID: <Pine.LNX.4.58.0407281142360.32265@noether.csi.cam.ac.uk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Reply-To: Bob Dowling <rjd4@cam.ac.uk>
Errors-To: kerberos-bounces@mit.edu

I'm running a KCD/kadmind on a Fedora box using Fedora's packages (1.3.1 
release 6) and am having problems with my wildcarded ACLs.

My situation is that I have a DNS domain with a very large number of 
subdomains (and subsubdomains etc. ad nauseam) whose computers may require 
host principals.  I would like to be able to delegate control of these to 
the people responsible for the computers in each subdomain (departmental 
computing staff, conscripted PhD students, etc.).  

I have been able to get wildcard ACLs working of the form

rjd4/manager@TEST.CAM.AC.UK	*	host/*@TEST.CAM.AC.UK

but not of the form

rjd4/manager@TEST.CAM.AC.UK	*	host/*.foo.cam.ac.uk@TEST.CAM.AC.UK

though there are no parse errors reported to the kadmind logs.

Am I doing something wrong or is this a genuine limitation in the parsing 
of the ACLs file?  If the latter could I propose that kadmind logs 
something about not being able to parse a line in kadm5.acl?
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post