On Tue, Feb 16, 2016 at 04:59:28PM +0000, Daniel P. Berrange wrote: [..snip..] > I'm wondering if we shouldn't have a separate file(s) recording > the hostname/IP address mappings for the NSS module to read, > that we place somewhere dedicated to this purpose, so we can > grant permission to just the data NSS needs. Or rather maintain the entries in a separate process that can be talked to over a socket like nss-ldapd does? Cheers, -- Guido -- libvir-list mailing list libvir-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/libvir-list