Michael Joyner ᏩᏯ wrote:
> Whatever format is chosen, *COMMON* arguments should be able to be
> specified in a *COMMON* section, then overridden on a per daemon basis.

This is one of the goals.

> I was going nuts with the dots in principals thing, had to grep all the
> binaries to figure out which ones needed it turned off in, had to find
> the config file and add the args... And it doesn't help any when the man
> pages don't have the correct spellings for available options either. :-P

They do now and they are on the web site.

> FYI, not everyone who uses AFS is knowledgeable of the KRB config file
> format. Some people use W2K3/W2K8 for our KRB servers.

The point of this discussion is to provide you the opportunity to
make a suggestion.  If you have another file format that you think
would be a good idea, suggest it.

> And speaking of feature requests... is there a way to add "hooks" into
> the pts security database lookups?

Sure.  Take out your source code editor and your C Programmer's Manual
and add some.  If they are generic enough for common use, propose them
as an enhancement.   Many sites have done their own custom thing.
Several attempts have been made at using PTS as a proxy to LDAP or AD.
None of them have been sufficiently robust and generic to be useful to
the community at large.   One of the primary reasons is that
authorization tends to be very site specific.

But this is off topic for this discussion.   Please keep this thread
focused on the configuration file issue.

Jeffrey Altman

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to