[OpenAFS-port-darwin] krb5 aklog.loginlogout ?
Sebastian Hagedorn
Hagedorn@uni-koeln.de
Fri, 18 Jun 2004 12:29:46 +0200
--==========232032DBCD0BAAD2B592==========
Content-Type: text/plain; charset=iso-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline
--On Freitag, 18. Juni 2004 11:30 Uhr +0200 Eric Knauel=20
<knauel@informatik.uni-tuebingen.de> wrote:
>> Bah, just build openssh with krb5 support directly. Don't go out of
>> your way to find problems.
>
> That would be too easy: In that setting there is now way to restrict
> who can log on to my machine since it is configured to use NIS as a
> user database. So, any NIS-user who obtains a Kerberos ticket can log
> in via ssh.
Really? Is the setting of AllowUsers in /etc/sshd_config ignored? That's=20
what I use ...
Cheers, Sebastian Hagedorn
--
Sebastian Hagedorn M.A. - RZKR-R1 (Geb=E4ude 52), Zimmer 18
Zentrum f=FCr angewandte Informatik - Universit=E4tsweiter Service RRZK
Universit=E4t zu K=F6ln / Cologne University - Tel. +49-221-478-5587
--==========232032DBCD0BAAD2B592==========
Content-Type: application/pgp-signature
Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (Darwin)
iEYEARECAAYFAkDSxBoACgkQGXsGmU0QW0Vk1ACfZlsK4zXH1gu9dB0ci0w6rlTH
4GEAoOJPnnROrWiT6BVmFWWp0/EK2Tyt
=q79j
-----END PGP SIGNATURE-----
--==========232032DBCD0BAAD2B592==========--