| |||
| [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] |
Henry B. Hotz wrote:
That still leaves the screen saver. What does it do with passwords, and how do I make it do the same as the other two mechanisms?
A less than trivial concern for sites that want to run all authentication through Kerberos, local accounts for emegencies only. I've dug around the documentation for screensaver but didn't see anything on the where and how of it's authentication process.
I think I disagree with having PAM call the security framework. If there is to be any hope of leveraging off of existing open source implementations then PAM should be usable by all three of the authentication routes I mentioned.
I am in agreement with Henry here. It was my impression from reading the docs that this was the intent when PAM support was added.
The alternative would be to provide a generic security framework wrapper for PAM code so it can be ported trivially by programmers ignorant of the security framework.
<nit>
I think it's better to have stuff in /usr/{include,lib}/pam/ than in /usr/{include,lib}/security/. Using the name /security/ is overblown and uninformative. Also changing it in open source code is something that can be done by "programmers ignorant of the security framework".
</nit>
<My $.02> I did not file the bug report about PAM's {include,lib} location because I think the name "security" is in anyway better than "pam". Neither did I file it because I can't/won't port my code to support the new location (I already have). I filed the bug because the world needs another vendor doing things "different" like I need a call from the IRS. This is about portability and compliance to standards, be they IETF or de facto. Right now PAM isn't that tightly integrated so moving the PAM stuff shouldn't be that great a burden, IMHO.
</My $.02>
| References: | |
| >Re: darwin-development digest, Vol 3 #574 - 10 msgs (From: "Henry B. Hotz" <email@hidden>) | |
| >Re: darwin-development digest, Vol 3 #574 - 10 msgs (From: "David M. Williams" <email@hidden>) |
| Home | Archives | FAQ | Terms/Conditions | Contact | RSS | Lists | About |
Visit the Apple Store online or at retail locations.
1-800-MY-APPLE
Contact Apple | Terms of Use | Privacy Policy
Copyright © 2007 Apple Inc. All rights reserved.