On Mon, 29 Sep 2008, David P. Quigley wrote: > * New security flavor (auth_seclabel) to transport process label to > server. This is a derivative of auth_unix so it does not support > kerberos which has its own issues that need to be dealt with. This is a problem, as discussed last year: http://linux-nfs.org/pipermail/labeled-nfs/2007-November/000110.html We can't require the use of a new auth flavor which is incompatible with auth_gss. - James -- James Morris <jmorris@xxxxxxxxx> -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.