[OpenAFS-devel] [LKML] Re: In-kernel Authentication Tokens (PAGs)

Derek Atkins warlord@MIT.EDU
Tue, 13 Jul 2004 10:38:53 -0400


Tomas Olsson <tol@stacken.kth.se> writes:

> I'd say that my id(s) for the distributed system(s) don't necessarily have
> anything to do with my local uid, so changing uid shouldn't affect my creds
> for the distributed system(s). Just like doing kinit shouldn't affect my
> local uid. I can say that being forced to reauthenticate (or similar) to be
> able to run my scripts in AFS every time I run sudo would be annoying.
>
> Comments? Better examples?

lpr, sendmail, or other apps that are setuid for local storage but
need access to your credentials to talk to a network server?

-derek
-- 
       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       warlord@MIT.EDU                        PGP key available