[OpenAFS-devel] [LKML] Re: In-kernel Authentication Tokens (PAGs)

John S. Bucy bucy-openafs-devel@gloop.org
Tue, 13 Jul 2004 11:08:54 -0400


On Tue, Jul 13, 2004 at 08:34:57AM -0500, David Thompson wrote:
> 
> We also currently use the "Join a previously defined PAG" functionality.  We 
> make use of it only because of the "1 PAG per second" rule (we need 
> authentications more frequently than once per second for web applications, for 
> example).  I would delight to switch to an interface that would simply let me 
> create a new authentication context without a time constraint (and then 
> authenticate it from a file-based credential).

I too have gotten bitten by this -- mail in my case, though our crummy
solution was just to set up a second mail server which spread out the
load enough for it to stop breaking (for now).  I'd also like to see a
new pag system that lacks this "throttling/resource exhaustion"
characteristic.

john