[23453] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Question about krb5_kuserok() and .k5login

daemon@ATHENA.MIT.EDU (Sam Hartman)
Sat Feb 26 18:56:22 2005

To: Michael Calmer <mc@suse.de>
From: Sam Hartman <hartmans@mit.edu>
Date: Sat, 26 Feb 2005 18:54:43 -0500
In-Reply-To: <200502241225.54974.mc@suse.de> (Michael Calmer's message of
 "Thu, 24 Feb 2005 12:25:54 +0100")
Message-ID: <tsl1xb2ubb0.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

I believe the MIT behavior is correct.  You need a way of saying that
for a particular local account that the default Kerberos realm's
principal by that name is not allowed to log in.

Otherwise it is problematic to have machines where the local
authorization policy does not map well to the Kerberos realm's account
policy.

--Sam

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post