All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Matt W. Benjamin" <matt@cohortfs.com>
To: "Christopher R. Hertel" <crh@redhat.com>
Cc: ceph-devel@vger.kernel.org
Subject: Re: Ceph authentication/authorization paradignms
Date: Thu, 28 Aug 2014 13:55:22 -0400 (EDT)	[thread overview]
Message-ID: <1925059576.144.1409248522066.JavaMail.root@thunderbeast.private.linuxbox.com> (raw)
In-Reply-To: <1220650621.35093917.1408643819096.JavaMail.zimbra@redhat.com>

Hi Chris,

----- "Christopher R. Hertel" <crh@redhat.com> wrote:

> Matt:
> 
> Thanks for the pointers.  I'm currently knee-deep in traditional
> Kerberos authentication code and trying to crack the FreeIPA PAM
> API.
> 
> I'm a community-oriented developer.  Any deeper dive you can
> provide would be encouraging.  :)
> 
> Chris -)-----


The two efforts I am aware of are rxgk (OpenAFS) and RPCSEC_GSSv3 (NFSv4).

The older of the two efforts I believe is rxgk, and had dual goals of addressing the AFS "cache poisoning" problem, and secondarily introducing support for separately managed (file) servers.  I believe RPCSEC_GSSv3 was initially conceived (by Nico Williams) as a means of addressing the NFSv4 equivalent of the cache poisoning problem, but the current work on it (by Andy Adamson) is as a dependency of NFSv4.2 server-side copy.  (Apologies to the participants if I am mis-reporting any of the history.)

The IETF discussion of these efforts is on Kitten and NFSv4.  There's interesting recent discussion on the Kitten WG alias.

Pointers:

http://www.ietf.org/internet-drafts/draft-wilkinson-afs3-rxgk-afs-06.txt
https://datatracker.ietf.org/doc/draft-ietf-nfsv4-rpcsec-gssv3

-- 
Matt Benjamin
CohortFS, LLC.
206 South Fifth Ave. Suite 150
Ann Arbor, MI  48104

http://cohortfs.com

tel.  734-761-4689 
fax.  734-769-8938 
cel.  734-216-5309 

  reply	other threads:[~2014-08-28 17:55 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <1288213759.97.1408639348899.JavaMail.root@thunderbeast.private.linuxbox.com>
2014-08-21 16:43 ` Ceph authentication/authorization paradignms Matt W. Benjamin
2014-08-21 16:44   ` Matt W. Benjamin
2014-08-21 17:56   ` Christopher R. Hertel
2014-08-28 17:55     ` Matt W. Benjamin [this message]
     [not found] <1642211910.31382003.1408036197918.JavaMail.zimbra@redhat.com>
2014-08-14 17:10 ` Christopher R. Hertel
2014-08-19 21:57   ` Gregory Farnum
2014-08-20 22:20     ` Christopher R. Hertel
2014-08-21 15:59       ` Gregory Farnum
2014-08-21 16:02         ` Sage Weil
2014-08-21 17:51           ` Christopher R. Hertel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1925059576.144.1409248522066.JavaMail.root@thunderbeast.private.linuxbox.com \
    --to=matt@cohortfs.com \
    --cc=ceph-devel@vger.kernel.org \
    --cc=crh@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.