gss_pname_to_uid: is that the right interface

Sam Hartman hartmans at MIT.EDU
Wed Sep 21 13:15:45 EDT 2011

>>>>> "Simo" == Simo Sorce <simo at> writes:

    Simo> This is in fact, something I would like to see, and have
    Simo> already planned to take a stab into seeing how difficult it is
    Simo> to plug this in.

Provide an authorization plugin that calls out to sssd and attaches a
local name attribute to the name. If you're also implying authorization
then use local-login-userand then the existing gss_localname interface I
proposed will automagically work.  If you need to say the localname of
this gss name is hartmans but userok should fail, then we need a bit
more work.  I hope you don't need to say that.

More information about the krbdev mailing list