Re: Problem using GSSAPI auth and CVS passwd file user mapping

From: Derek Robert Price
Subject: Re: Problem using GSSAPI auth and CVS passwd file user mapping
Date: Wed, 17 Nov 2004 16:57:21 -0500
Allen Sturtevant wrote:

>Neither of these worked.  Does GSSAPI authentication simply
>ignore the CVS passwd file?  


>If so, is there some other method
>I can use to obtain the desired user mapping?

Yeah, there is some funny Kerberos-specific code in server.c that
notes that it is doing something like this, but my knowledge of GSSAPI
and Kerberos, especially KDCs & tokens, is pretty limited.  You might
try to deciper the code in server.c to figure out where it is getting
the username from (krb5_aname_to_localname()?).

There's also a dearth of good Kerberos setup information in the public
domain as far as I can tell.  If anyone knowledgeable could let me
pick their brain for long enough for me get a Krb5 client and server
set up here, I've been wanting to take a shot at understanding the
GSSAPI code in CVS for some time.

I've got what I think are the working Krb5 clients and servers
distributed with RedHat Linux here, but as soon as I hit the section
on kdcs, principals, and tokens, my head starts to spin, currently.

Alternatively, a good GUI might serve as well.  One that simplified
things to the level of "add user", "give user privs to network", "put
user in group", "give groups privs to application on computer", that
sort of thing, if that's possible.


Email: address@hidden

