From mboxrd@z Thu Jan 1 00:00:00 1970 From: Peter Braam Date: Fri, 08 Aug 2008 08:45:39 -0600 Subject: [Lustre-devel] security: rpc message vs bulk data In-Reply-To: <1218205536.814.55.camel@JimsOSlap> Message-ID: List-Id: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: lustre-devel@lists.lustre.org On 8/8/08 8:25 AM, "James Hughes" wrote: > > > On Wed, 2008-08-06 at 16:48 -0600, Peter Braam wrote: >> Of course the CMU research about NASD concluded the same 10-15 years ago - >> you need a different protocol here, calling it ad-hoc is not so positive, >> calling it the NASD protocol sounds rather nice. > > I am not following the thread here. > > The existing implementation leverages off of kerberos in the client machine > and does not leverage the NASD style ticket granting with versioning that the > CMU papers advocated. Going to the NASD protocol is OK, but that means either > abandoning Kerberos or adding Kerberos ticket honoring to the NASD versioned > ticketing. This is doable, but not trivial. > Not true. There are capabilities generated by the MDS, with something similar to versioning. GSS between clients and OSS nodes is merely used to send the capabilities encrypted. > > > Can you send pointers to the relevant NASD security papers so that we can have > a firm set of terminology to discuss this with? http://www.pdl.cmu.edu/ - click on NASD. Peter -------------- next part -------------- An HTML attachment was scrubbed... URL: