> From [EMAIL PROTECTED] Fri Mar 15 23:02:57 2002 > Date: Fri, 15 Mar 2002 22:04:14 -0800 > From: Sam Noble <[EMAIL PROTECTED]> > To: [EMAIL PROTECTED] > Subject: LPRng: accounting and attributed usernames > > It seems that even when the permissions file is properly > configured for kerberos authentication, *any* user who is allowed to print > to a particular spooler can, with a valid kerberos ticket, impersonate > anyone he chooses. What I mean is that aparently, regardless of any > conflict between USER and AUTHUSER, USER is chosen to be recorded in my > accounting file by ifhp. > > Is there a straightforward way to fix this, i.e. record the > principal in the accounting file? > > /* Sam */
Hmmm... should be pretty simple to do. Will roll this in with the other stuff for authentication. Patrick ----------------------------------------------------------------------------- YOU MUST BE A LIST MEMBER IN ORDER TO POST TO THE LPRNG MAILING LIST The address you post from MUST be your subscription address If you need help, send email to [EMAIL PROTECTED] (or lprng-requests or lprng-digest-requests) with the word 'help' in the body. For the impatient, to subscribe to a list with name LIST, send mail to [EMAIL PROTECTED] with: | example: subscribe LIST <mailaddr> | subscribe lprng-digest [EMAIL PROTECTED] unsubscribe LIST <mailaddr> | unsubscribe lprng [EMAIL PROTECTED] If you have major problems, send email to [EMAIL PROTECTED] with the word LPRNGLIST in the SUBJECT line. -----------------------------------------------------------------------------
