Derrick J Brashear wrote: > On Tue, 15 May 2007, Karen L Eldredge wrote: > >> The documentation that I've been looking at describes how to configure >> the Network Authenication Service servers using legacy configuration, >> which is when the configuration is stored in a database on the local >> system. > > Can you point us to what you're reading?
"Network Authentication Service" is IBM's name for their Kerberos v5 implementation. They have a nice GUI for IBM NAS available from IBM AlphaWorks written in Java. "Legacy" mode is simply using a stand-alone database for the Kerberos principals and policy. From a security perspective, a standalone database is going to be safer. However, you might find that there are better incremental propagation or multi-master options available using their LDAP backend. From the perspective of OpenAFS, it doesn't matter which you use. You should compare the available features and trade-offs and make your determination based upon that. Jeffrey Altman
smime.p7s
Description: S/MIME Cryptographic Signature
