[22079] in Kerberos
ACLs question
daemon@ATHENA.MIT.EDU (Bob Dowling)
Wed Jul 28 06:54:38 2004
Date: Wed, 28 Jul 2004 11:51:07 +0100 (BST)
From: Bob Dowling <rjd4@cam.ac.uk>
To: kerberos@mit.edu
Message-ID: <Pine.LNX.4.58.0407281142360.32265@noether.csi.cam.ac.uk>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Reply-To: Bob Dowling <rjd4@cam.ac.uk>
Errors-To: kerberos-bounces@mit.edu
I'm running a KCD/kadmind on a Fedora box using Fedora's packages (1.3.1
release 6) and am having problems with my wildcarded ACLs.
My situation is that I have a DNS domain with a very large number of
subdomains (and subsubdomains etc. ad nauseam) whose computers may require
host principals. I would like to be able to delegate control of these to
the people responsible for the computers in each subdomain (departmental
computing staff, conscripted PhD students, etc.).
I have been able to get wildcard ACLs working of the form
rjd4/manager@TEST.CAM.AC.UK * host/*@TEST.CAM.AC.UK
but not of the form
rjd4/manager@TEST.CAM.AC.UK * host/*.foo.cam.ac.uk@TEST.CAM.AC.UK
though there are no parse errors reported to the kadmind logs.
Am I doing something wrong or is this a genuine limitation in the parsing
of the ACLs file? If the latter could I propose that kadmind logs
something about not being able to parse a line in kadm5.acl?
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos