[OpenAFS-port-darwin] krb5 aklog.loginlogout ?

Sebastian Hagedorn Hagedorn@uni-koeln.de
Fri, 18 Jun 2004 12:29:46 +0200


--==========232032DBCD0BAAD2B592==========
Content-Type: text/plain; charset=iso-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

--On Freitag, 18. Juni 2004 11:30 Uhr +0200 Eric Knauel=20
<knauel@informatik.uni-tuebingen.de> wrote:

>> Bah, just build openssh with krb5 support directly. Don't go out of
>> your way to find problems.
>
> That would be too easy: In that setting there is now way to restrict
> who can log on to my machine since it is configured to use NIS as a
> user database.  So, any NIS-user who obtains a Kerberos ticket can log
> in via ssh.

Really? Is the setting of AllowUsers in /etc/sshd_config ignored? That's=20
what I use ...

Cheers, Sebastian Hagedorn
--
Sebastian Hagedorn M.A. - RZKR-R1 (Geb=E4ude 52), Zimmer 18
Zentrum f=FCr angewandte Informatik - Universit=E4tsweiter Service RRZK
Universit=E4t zu K=F6ln / Cologne University - Tel. +49-221-478-5587
--==========232032DBCD0BAAD2B592==========
Content-Type: application/pgp-signature
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (Darwin)

iEYEARECAAYFAkDSxBoACgkQGXsGmU0QW0Vk1ACfZlsK4zXH1gu9dB0ci0w6rlTH
4GEAoOJPnnROrWiT6BVmFWWp0/EK2Tyt
=q79j
-----END PGP SIGNATURE-----

--==========232032DBCD0BAAD2B592==========--