9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
From: YAMANASHI Takeshi <9.nashi@gmail.com>
To: 9fans@cse.psu.edu
Subject: Re: [9fans] 9grid
Date: Thu,  9 Jun 2005 10:27:39 +0900	[thread overview]
Message-ID: <77d9f817fc67cc7300f8444559d04ef7@orthanc.cc.titech.ac.jp> (raw)

> The single central auth server approach uses the
> outside.plan9.bell-labs.com auth server allowing anyone who has
> a sources account (I.E. anyone who wants to), to attach to grid nodes

Yes.  But that's not the problem both multi authdom proposals are
trying to solve, I guess.  If you don't like the way sources accounts are
distributed (I.E. anyone who wants to), you can choose not to trust
the sources auth server and use others instead, like 9grid.de and/or tip9ug.
Both proposals are allowing you which authdom you trust or not.
Also, both proposals solved the username crash between multiple
authdoms.

Oh wait, what's the difference between the two proposals, btw?

> and run arbitary software, and read any world readable files
> on any node.

These are next hurdles I would like to jump over.
How about constructing the namespace of a grid user
only from /mnt/term/* ?

> how can an adminstrator on one side of the world trust an unknwon
> user on the other side?

Maybe he can't confidently trust unknown users in an authdom
on the other side of the world, but he may trust the admin of
the authdom reasonably.  I think this is the heart of grid's
authentication in general.


> Unfortunately in the current implementation, exchanges between the auth
> servers rely on DNS for mutual authentication.

I'm sorry.  I'm left behind here.  Which parts of the current
implementation rely on DNS for mutual authentication?


> Next we need some way to stop grid users hogging too much of a nodes
> cpu capacity, network bandwidth, disk space, and to stop them posting spam
> or organising DDoS attacks...

I wonder how globus is managing these issues...
-- 




             reply	other threads:[~2005-06-09  1:27 UTC|newest]

Thread overview: 48+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-06-09  1:27 YAMANASHI Takeshi [this message]
2005-06-09  3:01 ` Ronald G. Minnich
  -- strict thread matches above, loose matches on Subject: below --
2008-11-17 14:14 erik quanstrom
2008-11-17 16:22 ` lupin636
2008-11-14 12:23 erik quanstrom
2008-11-14 15:10 ` lupin636
2008-11-17 10:12 ` lupin636
2008-11-17 11:54   ` erik quanstrom
2008-11-17 14:13   ` lupin636
2008-11-13 15:43 erik quanstrom
2008-11-13 17:06 ` lupin636
2008-11-13 17:24   ` andrey mirtchovski
2008-11-13 17:26     ` erik quanstrom
2008-11-14  9:44     ` lupin636
2008-11-14  9:44 ` torsbohn
2008-11-14 13:53   ` erik quanstrom
2008-11-11 12:09 erik quanstrom
2008-11-11 13:18 ` lupin636
2008-11-11 14:42   ` john
2008-11-11 15:12   ` lupin636
2008-11-11 15:40     ` Uriel
2008-11-11 16:32     ` lupin636
2008-11-11 17:14       ` Uriel
2008-11-12  0:13     ` ron minnich
2008-11-12  0:11       ` erik quanstrom
2008-11-12  0:41         ` ron minnich
2008-11-12  0:36           ` erik quanstrom
2008-11-12  0:59             ` ron minnich
2008-11-12 10:27     ` lupin636
2008-11-12 14:38       ` john
2008-11-12 16:16       ` lupin636
2008-11-13 12:08       ` lupin636
2008-11-13 12:28         ` erik quanstrom
2008-11-13 15:32         ` lupin636
2008-11-10 18:38 erik quanstrom
2008-11-11  9:50 ` lupin636
2008-11-10 11:35 erik quanstrom
2008-11-10 14:13 ` lupin636
2008-11-10 17:35 ` lupin636
2008-11-10 17:46   ` ron minnich
2008-11-11  9:50   ` lupin636
2008-11-10  9:56 lupin636
2005-06-09  2:17 YAMANASHI Takeshi
2005-06-09  2:28 ` andrey mirtchovski
2005-06-09  1:41 andrey mirtchovski
2005-06-08 14:14 Steve Simon
2005-06-08 15:16 ` Russ Cox
2005-06-08 20:55 ` arisawa

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=77d9f817fc67cc7300f8444559d04ef7@orthanc.cc.titech.ac.jp \
    --to=9.nashi@gmail.com \
    --cc=9fans@cse.psu.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).