[OpenAFS] Output of tokens command intermittently shows AFS ID

Derrick Brashear shadow@gmail.com
Mon, 29 Mar 2010 11:23:18 -0400


On Mon, Mar 29, 2010 at 11:09 AM, Booker Bense <bbense@slac.stanford.edu> w=
rote:
> On Sun, 28 Mar 2010, Derrick Brashear wrote:
>
>>>
>>> User's (AFS ID 3903) tokens for afs@cs.unc.edu [Expires Apr =A01 11:28]
>>
>> This token was gotten by a tool that did the PTS lookup. Not all do.
>> This ID is irrelevant to the usability of the token.
>
> It's also potentially irrelevent to the actual AFS ID in the token as wel=
l.
> Since this is encrypted in the AFS key, there is
> no real way for the OS to know what it is. It's just makes it's
> best guess based on the mapping of username to pts id.
>
> Given a sufficiently convoluted setup, this mapping can be wrong.

It's usually wrong because of lazy tools rather than any actual failure.

However, lazy tools are legal.



--=20
Derrick