Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Mikkel Kruse Johnsen
Hi Dirk It should have said: fs setacl /afs/.cbs.dk/home/mkj.lib mkj.lib all /Mikkel On Wed, 2007-08-01 at 11:42 +0200, Dirk Heinrichs wrote: Am Mittwoch, 1. August 2007 schrieb ext Mikkel Kruse Johnsen: fs setacl /afs/.cbs.dk/home/mkj.lib all Just a guess, but to whom do you

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Dirk Heinrichs
Am Mittwoch, 1. August 2007 schrieb ext Mikkel Kruse Johnsen: fs setacl /afs/.cbs.dk/home/mkj.lib all Just a guess, but to whom do you want to give all permissions on that directory? HTH... Dirk -- Dirk Heinrichs | Tel: +49 (0)162 234 3408 Configuration Manager |

[OpenAFS] Usernames in pts

2007-08-01 Thread Mikkel Kruse Johnsen
Hi All I'm trying to setup OpenAFS here at Copenhagen Businnes School (Denmark). We have a MS Active Directory where all users are created and on windows I will install OpenAFS for windows and hopefully be able to access the OpenAFS servers with the principle, but unfortunally all users have a

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Russ Allbery
Mikkel Kruse Johnsen [EMAIL PROTECTED] writes: All of this is checked. If I do the same with a user not containing a dot [EMAIL PROTECTED] then it works. So it is because there is a dot in my name. You're being bitten by the code that tries to convert Kerberos v5 principal names to the

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Mikkel Kruse Johnsen
Hi Dirk All of this is checked. If I do the same with a user not containing a dot [EMAIL PROTECTED] then it works. So it is because there is a dot in my name. fs la /afs/cbs.dk/home/mkj.lib Access list for /afs/cbs.dk/home/mkj.lib is Normal rights: system:administrators rlidwka mkj.lib

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Mikkel Kruse Johnsen
Hi Russ Just patched with attacted patch. But I don't work. Is that the only place. To me it seems that the name is spilt and it checks if the first char is '.' (a dot). It should not spilt the name. /Mikkel On Wed, 2007-08-01 at 03:20 -0700, Russ Allbery wrote: Mikkel Kruse Johnsen [EMAIL

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Mikkel Kruse Johnsen
Hi All Well it did work. My token must have expired or something. Cool, thanks alot Russ. Your the man. Is there any plan to make this default in future version 1.6 or something, when kerberos 4 is all gone ? /Mikkel On Wed, 2007-08-01 at 12:42 +0200, Mikkel Kruse Johnsen wrote: Hi Russ

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Jeffrey Altman
Mikkel Kruse Johnsen wrote: Hi All I'm trying to setup OpenAFS here at Copenhagen Business School (Denmark). We have a MS Active Directory where all users are created and on windows I will install OpenAFS for windows and hopefully be able to access the OpenAFS servers with the principle,

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Ken Hornstein
Perhaps in the meantime we should add a command line switch --permit-dotted-krb5-names That would be fine with me; people who understood this issue could choose to disable the check. --Ken ___ OpenAFS-info mailing list OpenAFS-info@openafs.org

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Ken Hornstein
become the same string. In order to prevent joe.admin from becoming the administrative identity joe/admin we disable support for dots in Kerberos v5 principal names. And yet somehow this isn't an issue when you use the 524 translator. --Ken ___

Re: [OpenAFS] Usernames in pts

2007-08-01 Thread Jeffrey Altman
Mikkel Kruse Johnsen wrote: Hi All Well it did work. My token must have expired or something. Cool, thanks alot Russ. Your the man. Is there any plan to make this default in future version 1.6 or something, when kerberos 4 is all gone ? /Mikkel The plan is to modify AFS to support