Re: [SSSD] Remote user use-case

2010-11-08 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/07/2010 08:25 PM, Jeff Schroeder wrote: > Do you have users asking for this? The intention is fantastic, but the idea > sound scary. > Which part sounds scary? Also, yes. There are some deployments I'm aware of that would very much like to se

Re: [SSSD] Remote user use-case

2010-11-08 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/07/2010 08:36 AM, Simo Sorce wrote: > On Sun, 07 Nov 2010 07:00:04 -0500 > Stephen Gallagher wrote: > >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> On 11/05/2010 05:15 PM, Simo Sorce wrote: >>> On Fri, 05 Nov 2010 16:18:19 -0400 >>>

Re: [SSSD] Remote user use-case

2010-11-07 Thread Jeff Schroeder
Do you have users asking for this? The intention is fantastic, but the idea sound scary. Sent from my iPhone On Nov 7, 2010, at 8:36 AM, Simo Sorce wrote: > On Sun, 07 Nov 2010 07:00:04 -0500 > Stephen Gallagher wrote: > >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> On 11/05/201

Re: [SSSD] Remote user use-case

2010-11-07 Thread Simo Sorce
On Sun, 07 Nov 2010 07:00:04 -0500 Stephen Gallagher wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 11/05/2010 05:15 PM, Simo Sorce wrote: > > On Fri, 05 Nov 2010 16:18:19 -0400 > > Stephen Gallagher wrote: > >> One approach would be for GDM to provide an interface for a user >

Re: [SSSD] Remote user use-case

2010-11-07 Thread Simo Sorce
On Sun, 07 Nov 2010 07:16:24 -0500 Stephen Gallagher wrote: > I'm also wary of ever allowing an unauthenticated user access to a VPN > shared secret, but if it was contacting a special VPN concentrator > created for this purpose that only allowed authentication with > one-time-passwords and only

Re: [SSSD] Remote user use-case

2010-11-07 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/07/2010 06:28 AM, Sumit Bose wrote: > I like the idea of an 'emergency' VPN connection, because as Simo > mentioned it has a much broader use case then just the setting of the > initial password. But for this I'm thinking of a perhaps simpler > s

Re: [SSSD] Remote user use-case

2010-11-07 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/05/2010 05:15 PM, Simo Sorce wrote: > On Fri, 05 Nov 2010 16:18:19 -0400 > Stephen Gallagher wrote: >> One approach would be for GDM to provide an interface for a user who >> was not authenticated on the local machine to connect to a >> NetworkM

Re: [SSSD] Remote user use-case

2010-11-07 Thread Sumit Bose
On Fri, Nov 05, 2010 at 05:15:08PM -0400, Simo Sorce wrote: > On Fri, 05 Nov 2010 16:18:19 -0400 > Stephen Gallagher wrote: > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA1 > > > > One of SSSD's intended primary use-cases is that of the laptop user. > > We support cached, offline authenti

Re: [SSSD] Remote user use-case

2010-11-05 Thread Simo Sorce
On Fri, 05 Nov 2010 16:18:19 -0400 Stephen Gallagher wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > One of SSSD's intended primary use-cases is that of the laptop user. > We support cached, offline authentications to the local machine so > that when a laptop user picks their machin

[SSSD] Remote user use-case

2010-11-05 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 One of SSSD's intended primary use-cases is that of the laptop user. We support cached, offline authentications to the local machine so that when a laptop user picks their machine up from their desk and goes home with it, they can still log in. So wha