[23453] in Kerberos
Re: Question about krb5_kuserok() and .k5login
daemon@ATHENA.MIT.EDU (Sam Hartman)
Sat Feb 26 18:56:22 2005
To: Michael Calmer <mc@suse.de>
From: Sam Hartman <hartmans@mit.edu>
Date: Sat, 26 Feb 2005 18:54:43 -0500
In-Reply-To: <200502241225.54974.mc@suse.de> (Michael Calmer's message of
"Thu, 24 Feb 2005 12:25:54 +0100")
Message-ID: <tsl1xb2ubb0.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
I believe the MIT behavior is correct. You need a way of saying that
for a particular local account that the default Kerberos realm's
principal by that name is not allowed to log in.
Otherwise it is problematic to have machines where the local
authorization policy does not map well to the Kerberos realm's account
policy.
--Sam
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos