[1715] in athena10

home help back first fref pref prev next nref lref last post

Re: nss: hesiod -> ldap for groups?

daemon@ATHENA.MIT.EDU (Jonathan Reed)
Mon Mar 16 13:01:17 2009

Cc: Athena 10 <athena10@mit.edu>
Message-Id: <8C8D636C-5A47-4E39-A2A4-BE663FB70A17@mit.edu>
From: Jonathan Reed <jdreed@MIT.EDU>
To: Geoffrey Thomas <geofft@mit.edu>
In-Reply-To: <alpine.DEB.2.00.0903150458410.6214@geminorum.mit.edu>
Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Apple Message framework v919.2)
Date: Mon, 16 Mar 2009 13:00:20 -0400


On Mar 15, 2009, at 5:01 AM, Geoffrey Thomas wrote:

> Hm, did we ever get anywhere on this discussion, e.g. getting either  
> ldap.mit.edu or win.mit.edu's LDAP servers to give us GIDs? One more  
> comment is below...

I talked with Richard Edelson about this at the end of IAP.  He said  
that as far as he knew, the LDAP servers definitely knew about moira  
GIDs, so it was probably a matter of just figuring out how to do it.   
So the next step is that some debathena-dev folks should find a time  
to sit down with Richard  (and possibly a few other people) and hash  
out what Debathena needs and how we can get it.   Bill and/or I can  
probably help with facilitating this meeting.

On Mar 15, 2009, at 5:35 PM, Mitchell E Berger wrote:

> I thought after some conversation
> at least you and I became convinced that it'd be not too hard to have
> a PAM module query the AFS protection database for membership in the
> enumerated access.conf groups, and that sidestepped the issue of  
> figuring
> out whether the various LDAP domains would be willing to change their
> promised support levels.

While this sounds interesting, I'm concerned that it's being pursued  
for the wrong reasons.  "figuring out whether the various LDAP domains  
would be willing to change their promised support levels" may require  
a bit more effort, but it's not a technically hard problem.  If we do  
something hackish, it should ideally be only to work around  
incompatibilities at Layer 7 or below.

-Jon

home help back first fref pref prev next nref lref last post