Re: Linux authentication / credential management

Jan Harkes (jaharkes@cs.cmu.edu)
Wed, 9 Apr 2003 15:39:03 -0400


On Wed, Apr 09, 2003 at 04:12:14PM +0100, David Howells wrote:
> The first part of what I'm thinking of is a structure like the
> following that has a Process Authentication Group ID and a list of
> authentication tokens for filesystems such as AFS & NFSv4 kerberos
> keys, NTFS ACLs, SAMBA login details.

PAGs have been proposed over and over again and there is one fundamental
problem, my PAG isn't your PAG.

(although in this specific case, if you're looking at it with the AFS
hat it probably is).

Some people want to have an authentication identifier they can keep
synchronized across a cluster, so they want to be able to set the 'PAG'
to any arbitrary value. However Coda (and AFS) prefer to have something
that just guarantees to be a unique identifier for a group of related
tasks (aka. newpag). Allowing someone to set the pag in this case
nullifies the usefulness of the tag because there is no guarantee that
it is unique. It would be similar to allowing someone to specify their
own process id.

What happened to your 'task ornaments', I figured that that would have
been the best way to tag processes with information and allow individual
filesystems to define their own preferred semantics.

http://www.ussg.iu.edu/hypermail/linux/kernel/0201.3/0480.html

Jan

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/