9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
From: erik quanstrom <quanstro@quanstro.net>
To: 9fans@9fans.net
Subject: Re: [9fans] Multi-domain authentication?
Date: Mon, 20 Oct 2008 19:43:39 -0400	[thread overview]
Message-ID: <7b75306d4d0e8f34424afe7afe994236@quanstro.net> (raw)

> http://osdir.com/ml/os.plan9.nine-grid/2005-06/msg00001.html is a proposal
> from some years ago from TIP9UG to do multi-domain authentication in a way
> somewhat reminiscent of Kerberos.[1]
>
> The only change to factotum, AFAICT, was the following addition:
>>    if(_strfindattr(s->key->attr, "grid")){
>>      snprint(s->t.suid, sizeof s->t.suid, "%s@%s", s->t.cuid, _strfindattr(s->key->attr, "dom"));
>>      safecpy(s->t.cuid, s->t.suid, sizeof s->t.cuid);
>>      flog("grid user: %s", s->t.suid);
>>    }
> in the SHaveAuth case of p9skread.
>
> This seems like a good way to go about MDA, so I am curious why this change
> didn't get put back into the mainline code?  Is there something
> fundamentally wrong?  Was a different approach selected?  Was the issue
> simply tabled?

could you explain what you mean by multi-domain authentication?

i authenticate from one plan 9 authentication domain to another
every day.  the only thing that needs to be set up is that the hostowner
of the other auth domain's auth server needs to be in your /lib/ndb/auth.
(this is already done if you use bootes.)  and you need a line with
auth and authdom keys added to /lib/ndb/local on the auth client's
machine.

is there something else you are looking for?

> [1] I say similar to Kerberos in that it requires a domain A wishing to
> accept identities from domain B to have a key from B's authsrv.

i don't understand this.  which key are you talking about?

- erik




             reply	other threads:[~2008-10-20 23:43 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-10-20 23:43 erik quanstrom [this message]
2008-10-21  0:09 ` andrey mirtchovski
2008-10-21  0:10   ` erik quanstrom
2008-10-21  0:40     ` andrey mirtchovski
2008-10-21  2:21 ` Nathaniel W Filardo
  -- strict thread matches above, loose matches on Subject: below --
2008-10-21 17:45 erik quanstrom
2008-10-21 13:14 erik quanstrom
2008-10-21  0:49 erik quanstrom
2008-10-21  1:05 ` andrey mirtchovski
2008-10-21  2:25   ` ron minnich
2008-10-21  3:29 ` Eric Van Hensbergen
2008-10-21  7:25   ` roger peppe
2008-10-21  7:52   ` Steve Simon
2008-10-21 17:43   ` Nathaniel W Filardo
2008-10-20  4:38 Nathaniel W Filardo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7b75306d4d0e8f34424afe7afe994236@quanstro.net \
    --to=quanstro@quanstro.net \
    --cc=9fans@9fans.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).