Re: using Kerberos V5 with network address translation firewall?

2001-07-12 Thread Jeffrey Altman
In article <[EMAIL PROTECTED]>, Jianlin Chang <[EMAIL PROTECTED]> wrote: : Searching through the Kerberos mailing list archive, especially the thread : on subject 'Patch for making Kerberos work through Firewalls and NATs', it : seems to indicate that there are still a number of problems, e.g, tic

Re: using Kerberos V5 with network address translation firewall?

2001-07-12 Thread Russ Allbery
Jeffrey Altman <[EMAIL PROTECTED]> writes: > If you can describe a good way to write the rule that says, replace > address FOO with address NAT we can certainly make the change in the > code. The problem in most cases is that there is no good way to know > what the NAT address is in the first pl

Re: using Kerberos V5 with network address translation firewall?

2001-07-12 Thread Michael Thomas
[EMAIL PROTECTED] (Jeffrey Altman) writes: > Now this wraps the forwarded credentials in an auth context which > is bound to the local address/port and remote address/port. There is > no method that allows you to perform this binding and say > > hey wait a minute, whenever you see the local ad

Re: using Kerberos V5 with network address translation firewall?

2001-07-12 Thread Jeffrey Altman
In article <[EMAIL PROTECTED]>, Russ Allbery <[EMAIL PROTECTED]> wrote: : Jeffrey Altman <[EMAIL PROTECTED]> writes: : : > If you can describe a good way to write the rule that says, replace : > address FOO with address NAT we can certainly make the change in the : > code. The problem in most c

check_delegate

2001-07-12 Thread ilslee
Hi, Somebody mentioned to me the check_delegate parameter in the client side configuration file, something like: [libdefaults] ... check_delegate = 0 ... I've never head of this before. Could enlighten me or point me to information about this paramter. TIA, Il-Sung.

Configuring Leash32 to use memory credentials

2001-07-12 Thread Hakan Lucas
I'm looking to use MIT's Leash32 credentials manager on Windows 2000. Does anybody know how I can configure Leash to store credentials in memory and NOT on file?

Re: using Kerberos V5 with network address translation firewall?

2001-07-12 Thread Donn Cave
Quoth Russ Allbery <[EMAIL PROTECTED]>: | Jeffrey Altman <[EMAIL PROTECTED]> writes: | | > If you can describe a good way to write the rule that says, replace | > address FOO with address NAT we can certainly make the change in the | > code. The problem in most cases is that there is no good way

Re: using Kerberos V5 with network address translation firewall?

2001-07-12 Thread Jeffrey Altman
In article <9ikkkt$qce$[EMAIL PROTECTED]>, Donn Cave <[EMAIL PROTECTED]> wrote: : If you're going to configure Kerberos for a several thousand people : whose ISPs are pushing NATs, and who have only a glimmer of a notion : what that means and will be using a variety of implementations, and : whos

RE: Configuring Leash32 to use memory credentials

2001-07-12 Thread Danilo Almeida
If you are using Kerberos for Windows 2.1, that should happen automatically. - Danilo -Original Message- From: Hakan Lucas [mailto:[EMAIL PROTECTED]] Sent: Thursday, July 12, 2001 12:14 PM To: [EMAIL PROTECTED] Subject: Configuring Leash32 to use memory credentials I'm looking to use M

Re: Configuring Leash32 to use memory credentials

2001-07-12 Thread Jeffrey Altman
In article <[EMAIL PROTECTED]>, Hakan Lucas <[EMAIL PROTECTED]> wrote: : I'm looking to use MIT's Leash32 credentials manager on Windows 2000. : Does anybody know how I can configure Leash to store credentials in : memory and NOT on file? What version are you using? Current builds only store th

Re: using Kerberos V5 with network address translation firewall?

2001-07-12 Thread Jeffrey Altman
In article <[EMAIL PROTECTED]>, Michael Thomas <[EMAIL PROTECTED]> wrote: : [EMAIL PROTECTED] (Jeffrey Altman) writes: : > Now this wraps the forwarded credentials in an auth context which : > is bound to the local address/port and remote address/port. There is : > no method that allows you to p