[OpenAFS] Manually Creating Cross Realm Users

Derek Atkins warlord@MIT.EDU
26 Jul 2003 00:57:32 -0400


Chris McClimans <Chris.McClimans@ttu.edu> writes:

> Does this mean that the pts entry would be username for the principal
> username@REMOTE.REALM and I could pts createuser username -id 12345?
> -chris

Asuming you make "REMOTE.REALM" the kerberos realm for your cell, and
obtain a key, afs/your.cell@REMOTE.REALM...  For a user with a
kerberos principal of username@REMOTE.REALM you would give them a pts
name of "username" and you can assign them an id of whatever you want.

e.g.:

klist
...
Default principal: warlord@ATHENA.MIT.EDU
...
07/26/03 00:39:12  07/26/03 10:39:12  afs.athena.mit.edu@ATHENA.MIT.EDU
07/26/03 00:39:12  07/26/03 10:39:12  afs.sipb.mit.edu@ATHENA.MIT.EDU
...

tokens
User's (AFS ID 9661) tokens for afs@sipb.mit.edu [Expires Jul 26 10:39]
User's (AFS ID 9661) tokens for afs@athena.mit.edu [Expires Jul 26 10:39]
...
--> pts exa 9661 -c sipb
Name: warlord, id: 9661, owner: system:administrators, creator: ...

-derek

-- 
       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       warlord@MIT.EDU                        PGP key available