Re: [OpenAFS] openafs without pam

2003-08-14 Thread Charles Clancy
rnatively, you could edit the Makefile, removing the line: ${COMPILE_PART1} pam ${COMPILE_PART2} ;; \ [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] pam_openafs_session source

2003-06-08 Thread Charles Clancy
Hasn't pam_krb5 with built-in AFS support pretty much obsoleted pam_openafs-session? On Sat, 7 Jun 2003, Derek Atkins wrote: > If you find out, let me know.. I'd like to include it in the Red Hat RPMs. > > -derek > > Richard Wallace <[EMAIL PROTECTED]> writes: > > > Hey guys, > > > > Does anyone

Re: [OpenAFS] afsd.exe paramaters to disable kaserver authentication

2003-06-07 Thread Charles Clancy
e Rx vunerability, as long as you "fs setcrypt on", you'd only have to worry about a denial of service attack. Of course, you're running Win98, so an AFS DoS is the least of your worries. [ t. charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ]

Re: [OpenAFS] afsd.exe paramaters to disable kaserver authentication

2003-06-07 Thread Charles Clancy
rce of my > > > troubles running aklog.exe to get Kerberos5/AFS tokens. > > > The "troubles" are that everytime a run aklog.exe on Windows 98, it crash. > > > Thank you. > > > > I'm looking at main() in src/WINNT/afsd/afsd95.c. I see none. > &

Re: [OpenAFS] OpenAFS and Krb5 on Win98

2003-06-07 Thread Charles Clancy
On Thu, 5 Jun 2003, Ryan Underwood wrote: > On Wed, Jun 04, 2003 at 11:12:44PM -0500, Charles Clancy wrote: > > > > Best bet: download krb5-win32.exe from ftp.cmf.nrl.navy.mil. It has a > > krb5 client and a functional aklog.exe. Install Win9x version of the > > Ope

Re: [OpenAFS] MIT -> Heimdal

2003-06-05 Thread Charles Clancy
or your help, It will not affect any of your data. For that matter, it won't even affect your existing accounts (you could theoretically have both MIT and Heimdal running simultaneously). You're *adding* a new key, not *overwriting* the existing key in this process. [ t. charles clan

Re: [OpenAFS] fs setcrypt?

2003-06-05 Thread Charles Clancy
> Do the AFS servers need special > configuration for encryption to work? Nope. [ t. charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] OpenAFS and Krb5 on Win98

2003-06-05 Thread Charles Clancy
a krb5 client and a functional aklog.exe. Install Win9x version of the OpenAFS client, and be sure to start it with the appropriate command line argument to disable kaserver authentication. It should all just work. [ t. charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] __

Re: [OpenAFS] networking thought/question

2003-03-18 Thread Charles Clancy
On Mon, 17 Mar 2003, seph wrote: > Charles Clancy <[EMAIL PROTECTED]> writes: > > > On Mon, 17 Mar 2003, Tim C. wrote: > > > >>server fs1.afs partition /vicepa RW Site > >>server fs1.afs partition /vicepa RO Site > > > > What p

Re: [OpenAFS] FW: Error 8 (user doesn't exist)

2003-03-12 Thread Charles Clancy
y in kerberos, you need to create a ptserver entry in AFS. Try "pts adduser [username]". [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Getting tokens for non-interactive services

2003-03-05 Thread Charles Clancy
On Wed, 5 Mar 2003, Frank Burkhardt wrote: > On Tue, Mar 04, 2003 at 09:47:08PM -0600, Charles Clancy wrote: > > > Have you considered using pam_krb5afs, rather than pam_krb5 and > > pam_openafs_session? > > Can pam_krbafs be used with mit-krb5 ? > The pam_krb5afs

Re: [OpenAFS] Getting tokens for non-interactive services

2003-03-04 Thread Charles Clancy
On Tue, 4 Mar 2003, Frank Burkhardt wrote: > On Sat, Mar 01, 2003 at 11:13:53PM -0600, Charles Clancy wrote: > > On Sat, 1 Mar 2003, Frank Burkhardt wrote: > > > On Wed, Feb 26, 2003 at 02:01:49PM -0600, Charles Clancy wrote: > > > > > > > Try removing

Re: [OpenAFS] Sparse file support?

2003-01-16 Thread Charles Clancy
On Thu, 16 Jan 2003, Chris (Ducky) Chapin wrote: > Does OpenAFS (or AFS, for that matter) support sparse files? I'm not > finding any definative info one way or the other (except for a 'no' for > pre 3.4 of Transarc AFS). =/ Nope. Use gzip. ;) [ t charles clan

Re: [OpenAFS] Cannot obtain a token from AFS-Client on Debian andWinXP

2003-01-06 Thread Charles Clancy
adow/www/afs/afs-with-kerberos.html A pretty good FAQ: http://www.mathematik.uni-karlsruhe.de/~iwrmm/Persons/Schulz/Unix/afs/afs-krb5.html [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [E

Re: [OpenAFS] File locking

2003-01-06 Thread Charles Clancy
che managers (client machines) who have a cached copy. There's a complete description in the wiki, AdminFAQ section 3.07: http://grand.central.org/twiki/bin/view/AFSLore/AdminFAQ#3_07_How_does_AFS_maintain_consi [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] __

Re: [OpenAFS] OpenAFS documentation

2002-12-19 Thread Charles Clancy
to start with the HTML versions and then convert them to the POD source you suggest. [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

[OpenAFS] ~/.AFSSERVER?

2002-11-26 Thread Charles Clancy
What's ~/.AFSSERVER for? I saw it in a recent truss output: open("/home/tclancy/.AFSSERVER", O_RDONLY) Err#2 ENOENT open("/.AFSSERVER", O_RDONLY) Err#2 ENOENT [ t charles clancy ]--[ [EMAIL PROTECTED] ]

Re: [OpenAFS] uid 0 im AFS

2002-11-25 Thread Charles Clancy
uot;/bin/sh"); } chown root it, chmod 4755 it, and then can easily get root on any client machine. I suppose we have to trust our AFS admins. ;) The fix is of course "fs setcell -nosetuid", but that could possible cause other problems, depending on what you're distributing o

Re: [OpenAFS] Token discarding

2002-11-07 Thread Charles Clancy
s? I suggest you follow all the steps from scratch in the README for getting your AFS and Kerberos keys configured. The one I suggested was just for setting the kvno on your Kerberos principal. There's also the issue of importing that key into AFS with asetkey. The documentati

Re: [OpenAFS] OpenSSH 3.5p1 + ~/.shosts + token passing?

2002-11-07 Thread Charles Clancy
From what I recall, it should work if you upgrade your SSH client. This code section seems particularly useful: /* XXX - punt on backward compatibility here. */ ... case SSH_CMSG_HAVE_AFS_TOKEN: packet_send_debug("AFS token passing disabled before authentication."); break; ... [ t cha

Re: [OpenAFS] "Value too large for defined data type"

2002-11-07 Thread Charles Clancy
s going again. Interestingly enough, two PowerPoint presentations I saved in AFS space from the XP client are perfectly readable under Solaris. Was it a Solaris bug, a Windows bug, or a general bug? [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] _

[OpenAFS] "Value too large for defined data type"

2002-11-07 Thread Charles Clancy
ut ones not compatable with Solaris? [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Token discarding

2002-11-07 Thread Charles Clancy
he _same_ as the highest kvno in your AFS KeyFile, e.g.: % ./asetkey list kvno3: key is: ... kvno5: key is: ... All done. % kadmin.local -q "modprinc -kvno 5 [EMAIL PROTECTED]" [ t ch

Re: [OpenAFS] Token discarding

2002-11-07 Thread Charles Clancy
#x27;asetkey list'. You probably mistyped something when you did your original asetkey. [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Help - Failed to load AFS client

2002-11-03 Thread Charles Clancy
response rather than a "closed" response, depending on what firewall is being used (if there even is one). [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] On Sun, 3 Nov 2002, Tommy Mann wrote: > > Tommy > > > On 3 Nov 2002, Derek Atkins wrote: > > >

Re: [OpenAFS] pam and openafs 1.2.7 for RH 7.2

2002-10-08 Thread Charles Clancy
inly does not involve PAM. The module pam_afs.so can only do password-based authentication. [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Multiple hosts behind firewall and AFS cell

2002-10-04 Thread Charles Clancy
timeouts? In my experience, I can get one client to work fine from behind a NAT by using long UDP timeouts. However, dispite what others have reported, I've never been able to get multiple clients to work from behind a NAT (using both IPF on Solaris and Win2K Server's built-in NAT rou

Re: [OpenAFS] pam and openafs 1.2.7 for RH 7.2

2002-10-04 Thread Charles Clancy
ct with a verbose client: $ ssh -v -v -v user@host Check the massive amounts of debug info for things that look inappropriate. I don't recall if you said so earlier -- but does your pam_afs.so work with other applications? Is your SuSE box running the same version of sshd? [ t charles c

Re: [OpenAFS] Can't mount AFS on /afs(22)

2002-09-26 Thread Charles Clancy
ague idea, that this was what one could expect. Do you have an admin token? Do "vos remove wallace vicepa root.afs -localauth" from your AFS server. That avoids authentication and token problems. [ t charles clancy ]--[ [EMAIL PRO

Re: [OpenAFS] Token Persistency and GUI Problems on Mac OS X

2002-09-19 Thread Charles Clancy
ll existed (if not expired) by > typing "tokens" at terminal window. This is expected. Use "klog -setpag" if you want to create a PAG. I suggest you read the documentation on klog and pagsh. [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] __

Re: [OpenAFS] kerberos + openafs + windows = ?

2002-09-09 Thread Charles Clancy
utilities would presumably be run from some sort of login script or startup shortcut. Alternatively, there's a utility that combines the functionality of ms2mit and aklog into a single binary: http://www.rose-hulman.edu/TSC/software/wake/ [ t charles clancy ]--[ [EMAIL PROTECT

Re: [OpenAFS] kerberos + openafs + windows = ?

2002-09-09 Thread Charles Clancy
? There has got to be someone who has this available? Someone has got > to have used krb5 + windows before. How? Am I stuck trying to find a C > compiler and going from source? You have all the files; now you just need to get them all to play nicely together. [ t charles

Re: [OpenAFS] Kerberos with OpenAFS on Windows XP

2002-09-09 Thread Charles Clancy
n, you'll need the Kerberos 5 client and a copy of aklog.exe. Alternatively, you can try and use WinXP's built in kerberos support, and use ms2mit.exe with aklog.exe (or WAKE). [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] __

Re: [OpenAFS] Administration-Interface

2002-07-01 Thread Charles Clancy
-based tools for managing users, resetting passwords, home directory quotas, etc. I'm not aware of any pre-packaged web interfaces, however. [ t charles clancy ]-[ [EMAIL PROTECTED] ]-[ uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL

Re: [OpenAFS] Kerberos V integration?

2002-07-01 Thread Charles Clancy
l http://lists.openafs.org/pipermail/openafs-info/2002-March/003872.html http://ismene.csl.uiuc.edu/afs-mig/doc/ (Ken Hornstein's docs) [ t charles clancy ]-[ [EMAIL PROTECTED] ]-[ uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTE

Re: [OpenAFS] no quorum elected

2002-06-09 Thread Charles Clancy
is caused by AFS servers with their system clocks too skewed relative to one another. It doesn't seem to have much to do with your problem, though. [ t charles clancy ]-[ [EMAIL PROTECTED] ]-[ uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] client cache files clean-up

2002-05-06 Thread Charles Clancy
rking because your client isn't properly started, because the cache is hosed. So, try the "rm -rf" approach. Perhaps that's not "non-drastic" but rebuilding the cache isn't a big deal. [ t charles clancy ]-[ [EMAIL PROTECTED] ]-[ uiuc.edu/~tclancy ] _

Re: [OpenAFS] Converting kaserver to krb5/heimdal

2002-05-05 Thread Charles Clancy
inux, IRIX, Solaris, and AIX: http://ismene.csl.uiuc.edu/afs-mig/ [ t charles clancy ]-[ [EMAIL PROTECTED] ]-[ uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] ssh and afs

2002-05-04 Thread Charles Clancy
at the same security hole exists in all the machines anyway. (Bad argument, I know...) [ t charles clancy ]-[ [EMAIL PROTECTED] ]-[ uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Home directory in AFS

2002-04-21 Thread Charles Clancy
ata. Wow. Use NFS. I apologize if my comments are a bit sardonic. If you're going to ignore our advise, don't ask for it. In my opinion, you are completely missing the point of AFS. From everything you've said, I strongly suggest you stick with NFS. It would be more appropriate

Re: [OpenAFS] Home directory in AFS

2002-04-20 Thread Charles Clancy
instead to get > the information needed? People have brought it up before, but it's just not practical. The data is *mostly* static, and not very redundant. Even in very large environments, moving to LDAP wouldn't make administration any more or less difficult. [ t. charles clancy

Re: [OpenAFS] Consistency problems with VLDB?

2002-04-07 Thread Charles Clancy
'vos remsite?' That would at least let me use my volumes again. As long as "vos listvol" doesn't show any real volumes in existance, you should be able to "vos syncvldb" to syncronize apparently confused VLDB with th

Re: [OpenAFS] Not a directory

2002-04-07 Thread Charles Clancy
gest trying to recreate the volume with a "vos backup user". If you have no desire to keep the volume, then delete it "properly" with a "vos remove papadoc vicepa user.backup". [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] AFS FTP Permissions

2002-03-18 Thread Charles Clancy
client > will do useful authentication Also any FTP server supporting PAM will work too. [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Backup to Harddisk ?

2002-03-15 Thread Charles Clancy
scripts, you should be able to get a reasonable backup system going. [ t charles clancy ]--[ [EMAIL PROTECTED] ]--[ www.uiuc.edu/~tclancy ] ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] MIT Kerberos V authentication with OpenAFS

2002-03-04 Thread Charles Clancy
00178374C00 > gcc --version 2.95.2 Any suggestions? Also -- are there any plans for an HP-UX port of OpenAFS? -- t. charles clancy <> [EMAIL PROTECTED] <> www.uiuc.edu/~tclancy ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Automated backups

2002-02-28 Thread Charles Clancy
of the AFS server as root, open two dtterm's, do a butc -localauth in one, and a backup -localauth in the other. -- t. charles clancy <> [EMAIL PROTECTED] <> www.uiuc.edu/~tclancy ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Making screensaver updating token on solaris

2002-02-26 Thread Charles Clancy
rt (MIT and Heimdal) and with AFS > support. The point of the original post was to be able to refresh tokens when unlocking the screensaver. How is that done in a program that natively supports kerberos and AFS? Can you tell it whether or not it should "-setpag" when it g

Re: [OpenAFS] fetchmail / procmail / afs

2002-02-26 Thread Charles Clancy
what you want to use. Incidentally, fetchmail didn't crash on me. $ fetchmail --version This is fetchmail release 5.1.0 SunOS ismene 5.8 Generic_108528-12 sun4u sparc -- t. charles clancy <> [EMAIL PROTECTED] <> www.uiuc.edu/~tclancy ___ Ope

Re: [OpenAFS] Newbie (or brain cramped question)

2002-02-26 Thread Charles Clancy
ls' root.cell's mounted. If you are using '-dynroot', trim your CellServDB to only include the cells you want to show up. Out of curiosity, what would happen during an 'ls /afs' if both '-afsdb' and '-dynroot' were used? -- t. charles clancy <>

Re: [OpenAFS] AFS client over NIS

2002-02-18 Thread Charles Clancy
have local /etc/passwd entries for this information. If you want to use NIS, I'd recommend setting the password field in the shadow map to "*NP*", so NIS only provides name service and not authentication. See one of the MANY responses to this exact question in the mailing l

Re: [OpenAFS] how to integrate auth with Linux system

2002-02-09 Thread Charles Clancy
to log in? If you want AFS users to log in, you'll want to double check the status of PAM support, or use Kerberos 5 support (if you are running kerberos 5 in your cell). -- t. charles clancy <> [EMAIL PROTECTED] <> www.uiuc.edu/~tclancy ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] how to integrate auth with Linux system

2002-02-05 Thread Charles Clancy
the security problem of NIS! -- t. charles clancy <> [EMAIL PROTECTED] <> www.uiuc.edu/~tclancy ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] File server allegedly unavailable

2002-02-05 Thread Charles Clancy
client UDP port changes? If so, then the client should continue to work (perhaps not optimally) without UDP timeout increased. -- t. charles clancy <> [EMAIL PROTECTED] <> www.uiuc.edu/~tclancy ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] File server allegedly unavailable

2002-02-05 Thread Charles Clancy
> Charles Clancy <[EMAIL PROTECTED]> writes: > > > Would this possibly fix the problem of multiple AFS clients behind a NAT > > gateway? > > No. You can already have multiple AFS clients behind a NAT -- you > just need to set the NAT UDP timeouts to be fair

Re: [OpenAFS] Commercial Support for OpenAFS

2001-12-14 Thread Charles Clancy
OpenAFS, see: http://www-106.ibm.com/developerworks/linux/library/os-afs.html -- t. charles clancy <> [EMAIL PROTECTED] <> www.uiuc.edu/~tclancy ___ OpenAFS-info mailing list [EMAIL PROTECTED] https://lists.openafs.org/mailman/listinfo/openafs-info

Re: [OpenAFS] Solaris 8, dtlogin and ~/.dt/session/lastsession

2001-11-09 Thread Charles Clancy
n admin token, even though root isn't logged in (since I didn't setpag, it's using UID to identify processes with access to the token). Then, dtlogin running as root is able to access users' ~/.dt directories. Of course, that only lasts 25 hours, before the token exp

Re: [OpenAFS] SAMBA - AFS bridge?

2001-11-09 Thread Charles Clancy
> Can anyone out there tell me if there is any kind of SAMBA - AFS > bridge?? (apologies to Charles Clancy for the mis-send) In which direction? Providing access to AFS via SMB, or providing access to SMB shares via AFS? For the first case, simply compile Samba with PAM support, and u

Re: [OpenAFS] Solaris 8, dtlogin and ~/.dt/session/lastsession

2001-11-09 Thread Charles Clancy
o apache can get to the ~/public_html directory and sendmail can get to the ~/Public/.forward file. Depending on your existing environment, you may decrease overall security by doing this. -- t. charles clancy <> [EMAIL PROTECTED] <> www.uiuc.edu/~tclancy _

Re: [OpenAFS] aklog PAM module

2001-05-31 Thread Charles Clancy
On 31 May 2001, Martin Schulz wrote: > Charles Clancy <[EMAIL PROTECTED]> writes: > > > So, I wrote a simple little PAM module that when used in conjunction with > > Kerberos PAM will get a TGT and AFS token for users logging in, regardless > > of what service the

Re: [OpenAFS] OpenAFS + KRB5 usage...

2001-04-27 Thread Charles Clancy
On Fri, 27 Apr 2001, Derrick J Brashear wrote: > On Fri, 27 Apr 2001, Charles Clancy wrote: > > > Is there any [easy] way to migrate accounts from the kaserver to krb5? I > > figure that since kaserver is basically krb4, there should be some sort of > > "upgrade

Re: [OpenAFS] OpenAFS + KRB5 usage...

2001-04-27 Thread Charles Clancy
asswords stored consistently between krb4 and krb5? Could that then be imported? I just don't to avoid assigning new passwords for all the accounts currently on the system. Thanks! _______ Charles Clancy -- [EMAIL PROTECTED] Senior UNIX Admini

Re: [OpenAFS] SAMBA as a CIFS <-> AFS gateway

2001-04-17 Thread Charles Clancy
and file service to NT workstations, but I couldn't get around the plain-text password requirement of Samba. _____ Charles Clancy, [EMAIL PROTECTED] Senior UNIX Administrator, Rose-Hulman CS ___ OpenAFS-info mail

Re: [OpenAFS] FTPD vulnerable to glob?

2001-04-17 Thread Charles Clancy
is-ftpd and pro-ftpd via PAM, and it works great. ___ Charles Clancy -- [EMAIL PROTECTED] Senior UNIX Administrator, Rose-Hulman Computer Science ___ OpenAFS-info mailing list [EMAIL PROTE