On Aug 3, 2010, at 7:02 PM, Trond Myklebust wrote: > On Tue, 2010-08-03 at 18:42 -0400, J. Bruce Fields wrote: >> On Tue, Aug 03, 2010 at 06:31:15PM -0400, Trond Myklebust wrote: >>> On Tue, 2010-08-03 at 18:23 -0400, J. Bruce Fields wrote: >>>> On Tue, Aug 03, 2010 at 06:15:19PM -0400, Trond Myklebust wrote: >> >>> 2) Why is AUTH_SYS so sacrosanct? >> >> Because it's what almost everyone uses. > > No. It's the _default_. ...and a really really bad default. The problem is the only supported alternative is to set up Kerberos. This is a lot of work, especially for established sites where it essentially requires every user to change their password during the migration. It also creates problems with ticket expiration if you have daemons or batch jobs that need continuous access to NFS filesystems. I've been looking at it for a while, because the 16-group limit is a problem for us, but it's a huge ball of wax. I understand the security benefits, but the sheer complexity of setting it up and then coming up with workarounds for ticket expiration has me a bit cowed. -- David Brodbeck System Administrator, Linguistics University of Washington -- To unsubscribe from this list: send the line "unsubscribe linux-nfs" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html