[OpenAFS] one afs/cell.domain princs per realm

Chris McClimans openafs-info@mcclimans.net
Wed, 27 Aug 2003 11:02:59 -0500


On Wednesday, August 27, 2003, at 10:46  AM, Derrick J Brashear wrote:

> On Wed, 27 Aug 2003, Ken Hornstein wrote:
>
>>   - Change aklog to simply mangle the V5 ticket appropriately.  See 
>> the
>>     mailing list archives for the discussion on this.  If you do
>>     this, Derrick Brashear will curse you until the day he dies, but
>>     he does that for _so_ many people, I think the effect is getting
>>     kinda diluted :-)
>
> Untrue. I think it's a bad idea, but only bad enough that I wasn't 
> going
> to write one. If he wants to do it, hey, more power to him.
>
> It's not like he's forking aklog or something.
>

I'm looking at Doug's kerberos 5 modifications below and also the 
gssklog. Any suggestions as two which might fit better? Maybe a 
combination of the two?
I may be able to just do one REALM, and that being ttu.edu. But I must 
create a cell called cs.ttu.edu, and have the users be local.
I'll have to run any krb524ness within my boxes. TTU.EDU is a windows 
AD domain and they are not likely to run krb524. Thanks for all the 
direction and support thus far.

https://lists.openafs.org/pipermail/openafs-info/2003-June/009459.html