[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference bulova::decw_jan-89_to_nov-90

Title:DECWINDOWS 26-JAN-89 to 29-NOV-90
Notice:See 1639.0 for VMS V5.3 kit; 2043.0 for 5.4 IFT kit
Moderator:STAR::VATNE
Created:Mon Oct 30 1989
Last Modified:Mon Dec 31 1990
Last Successful Update:Fri Jun 06 1997
Number of topics:3726
Total number of notes:19516

2840.0. "VAXclusters and security" by SCHOOL::KOMAR (You can't fool Nature) Wed May 30 1990 18:26

	My workstation is a member of a Local Area VAXcluster.  The cluster is
	implemented as a single security domain [one UAF; security-homogeneous]

	When will DECwindows be able to take advantage of that, by allowing
	me to specify that when I am logged into a workstation, I may
	create windows on that server from anywhere in the cluster?

	Please, Please, Please.

	I know that x/DECWindows use DECnet and that VAXcluster and DECnet
	don't have a well defined interface, but I'm talking about a higher
	concept -- security.

	What do you say?

		Paul Komar.

		VAXcluster Architectur Support Program (ASP)

		"Asps.  Very Dangerous.  You first..."
T.RTitleUserPersonal
Name
DateLines
2840.1Not easy to doSTAR::VATNEPeter Vatne, VMS DevelopmentWed May 30 1990 18:407
I would really like to automatically allow connections for the same user
from anywhere in the cluster.  However, this is not as easy as it sounds.
The main problem is reliably determining whether the DECnet connection is
from your own VAXcluster or not!

Check back in two months to see if this made it into DECwindows V3.
The chances aren't too good right now, but you never know...
2840.2What do you need?HPSRAD::KOMARShouting Theater in a crowded fireFri Jun 01 1990 12:0112
    
    	In general terms, can you say what service(s) would ease the
    	problem?
    
    	[a network wide authentication service, of course, with full
    	 knowledge of clusters
    	]
    
    	We can take this discussion off line, I you would like...
    
    			-pk.
    
2840.3What I would love to have!STAR::VATNEPeter Vatne, VMS DevelopmentFri Jun 01 1990 12:388
>    	[a network wide authentication service, of course, with full
>    	 knowledge of clusters
>    	]

If we had a network-wide authentication service, then we could dispense
with nodenames and clusters altogether, and just do authentication based
on a network-wide username!  In the very long term (more than a couple
years out), I think this is a possibility.
2840.4That's my Job! (long-term)DEMOAX::HAYESBernard Hayes, Pilgrim Project LeaderMon Jun 04 1990 00:035
    That's what Athena did for Unix, and what Project Pilgrim at UMass
    is aiming to do for Unix and VMS.
    
    		BLH