[14653] in Kerberos
Kerberos Client Q
daemon@ATHENA.MIT.EDU (Shaun McCullagh)
Wed Jul 11 10:54:40 2001
Message-ID: <3B4C66BE.C7B8E167@marviQ.com>
Date: Wed, 11 Jul 2001 16:46:22 +0200
From: Shaun McCullagh <shaun.mccullagh@marviQ.com>
MIME-Version: 1.0
To: kerberos@MIT.EDU
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Hi,
Is it possible for a client machine to be a member of more than one
realm?
Looking through the Kerberos FAQ I see it is possible for one machine
to act as a KDC for more than one realm.
So if machine 'A' can be a member of two realms presumably
it needs a principle in both realms.
The reason I ask this, is I want to organise users into `access groups'
to control which machines they have shell access to...
TIA
--
Shaun McCullagh mailto:shaun.mccullagh@marviQ.com
Senior Unix Administrator Office Phone +31 (0) 20 850 9342
marviQ BV Mobile +31 (0) 615 09 23 25
Ringwood Building
Nachtwachtlaan 20
1058 EA Amsterdam
The Netherlands