* kerberos support for XCP
@ 2010-06-23 11:57 George Shuklin
2010-06-23 13:25 ` David Markey
0 siblings, 1 reply; 3+ messages in thread
From: George Shuklin @ 2010-06-23 11:57 UTC (permalink / raw)
To: xen-devel
Good day.
I was thinking, is it possible to add kerberos support to XCP? By Kerberos mechanism, all hosts can trust each other without passwords (for example, by using xcp/host@realm principals), and nfs4 identification will be possible...
--
wBR,George.
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: kerberos support for XCP
2010-06-23 11:57 kerberos support for XCP George Shuklin
@ 2010-06-23 13:25 ` David Markey
2010-06-23 13:33 ` Michal Novotny
0 siblings, 1 reply; 3+ messages in thread
From: David Markey @ 2010-06-23 13:25 UTC (permalink / raw)
To: George Shuklin; +Cc: xen-devel
[-- Attachment #1.1: Type: text/plain, Size: 526 bytes --]
Do you mean via ssh, or via OpenXenCenter?
On 23 June 2010 12:57, George Shuklin <nge@narod.ru> wrote:
> Good day.
>
> I was thinking, is it possible to add kerberos support to XCP? By Kerberos
> mechanism, all hosts can trust each other without passwords (for example, by
> using xcp/host@realm principals), and nfs4 identification will be
> possible...
> --
> wBR,George.
>
> _______________________________________________
> Xen-devel mailing list
> Xen-devel@lists.xensource.com
> http://lists.xensource.com/xen-devel
>
[-- Attachment #1.2: Type: text/html, Size: 925 bytes --]
[-- Attachment #2: Type: text/plain, Size: 138 bytes --]
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xensource.com
http://lists.xensource.com/xen-devel
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: kerberos support for XCP
2010-06-23 13:25 ` David Markey
@ 2010-06-23 13:33 ` Michal Novotny
0 siblings, 0 replies; 3+ messages in thread
From: Michal Novotny @ 2010-06-23 13:33 UTC (permalink / raw)
To: admin; +Cc: xen-devel, George Shuklin
I think that George is thinking about implementing krb5 (Kerberos)
mechanism for Xen host authorization directly into the XCP platform,
i.e. the kerberos credentials (obtained by kinit) could be useful when
the company is using one kerberos server infrastructure which means the
one-password infrastructure and they can be using it for various
authorizations when the ticket is already obtained and it could be
useful for e.g. accessing websites, accessing some intranet tools as
well as this is the request to implement it into the Xen infrastructure
so the ticket could be used for everything in their company/network
until the ticket expires.
Michal
On 06/23/2010 03:25 PM, David Markey wrote:
> Do you mean via ssh, or via OpenXenCenter?
>
> On 23 June 2010 12:57, George Shuklin <nge@narod.ru
> <mailto:nge@narod.ru>> wrote:
>
> Good day.
>
> I was thinking, is it possible to add kerberos support to XCP? By
> Kerberos mechanism, all hosts can trust each other without
> passwords (for example, by using xcp/host@realm principals), and
> nfs4 identification will be possible...
> --
> wBR,George.
>
> _______________________________________________
> Xen-devel mailing list
> Xen-devel@lists.xensource.com <mailto:Xen-devel@lists.xensource.com>
> http://lists.xensource.com/xen-devel
>
>
>
> _______________________________________________
> Xen-devel mailing list
> Xen-devel@lists.xensource.com
> http://lists.xensource.com/xen-devel
>
--
Michal Novotny<minovotn@redhat.com>, RHCE
Virtualization Team (xen userspace), Red Hat
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2010-06-23 13:33 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-06-23 11:57 kerberos support for XCP George Shuklin
2010-06-23 13:25 ` David Markey
2010-06-23 13:33 ` Michal Novotny
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).