[OpenAFS-devel] 1.5.1 - multiple Kerberos realm support

Derrick J Brashear shadow@dementia.org
Tue, 2 May 2006 16:15:52 -0400 (EDT)


On Tue, 2 May 2006, Christopher D. Clausen wrote:

> Jeffrey Altman <jaltman@secure-endpoints.com> wrote:
>> The OpenAFS Gatekeepers announce the availability of OpenAFS
>> Development version 1.5.1 .
>> [snip]
>>
>> (3) partial support for multiple Kerberos realms mapping to a single
>> cell has been added to servers.
>
> Are there more details on this multiple Kerberos realm support
> somewhere?

List them in /usr/afs/etc/krb.conf, one per line

Usernames must map directly e.g. be the same in all realms, though.

> In what situations would be it be useful?  (I'd like to eventually get
> rid of gssklogd if OpenAFS can handle that same functionality natively.)
>
> And what exactly does "partial support" mean?

It means later you'll be able to also say
userA@realm1 maps to userB@realm2


> _______________________________________________
> OpenAFS-devel mailing list
> OpenAFS-devel@openafs.org
> https://lists.openafs.org/mailman/listinfo/openafs-devel
>
>