Derrick J Brashear wrote:
> On Tue, 15 May 2007, Karen L Eldredge wrote:
> 
>> The documentation that I've been looking at  describes how to configure
>> the Network Authenication Service servers using legacy configuration,
>> which is when the configuration is stored in a database on the local
>> system.
> 
> Can you point us to what you're reading?

"Network Authentication Service" is IBM's name for their Kerberos v5
implementation.   They have a nice GUI for IBM NAS available from IBM
AlphaWorks written in Java.

"Legacy" mode is simply using a stand-alone database for the Kerberos
principals and policy.  From a security perspective, a standalone
database is going to be safer.  However, you might find that there are
better incremental propagation or multi-master options available using
their LDAP backend.  From the perspective of OpenAFS, it doesn't matter
which you use.  You should compare the available features and trade-offs
and make your determination based upon that.

Jeffrey Altman

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to