Re: AW: AW: Validation with Kerberos 5, SAP Linux, SNC for SSO

2005-04-07 Thread Jacques Lebastard
Jorge Manuel Vieira a écrit : Where I can found bc_snc_adapter_101.zip the link from download it`s not available anymore. http://www.sap.com/partners/icc/scenarios/technology/bc-snc.aspx Try this one : https://www.sdn.sap

Re: Getting single DES TGT[was Re: KDC: upgrade to 3DES]

2005-04-07 Thread Craig Huckabee
Tim, Thanks for the idea - but looks like they dropped Cybersafe in 10g. :( We were hoping to make this work on 8,9,&10. --Craig Tim Alsop wrote: If you use the CyberSafe adapter (also included in Oracle 8i and 9i) - this adapter uses GSS-API and calls our library, which supports 3DES. It loo

RE: Getting single DES TGT[was Re: KDC: upgrade to 3DES]

2005-04-07 Thread Tim Alsop
If you use the CyberSafe adapter (also included in Oracle 8i and 9i) - this adapter uses GSS-API and calls our library, which supports 3DES. It looks like you have noticed that the Oracle ASO 'Kerberos' adapter includes Kerberos code based on an old release of MIT libraries. However, the 'CyberSaf

Getting single DES TGT[was Re: KDC: upgrade to 3DES]

2005-04-07 Thread Craig Huckabee
Hi all, I saw this discussion on krb-dev on moving to 3DES support and wanted to ask a similar question (hopefully more appropriately on this list). We're trying to use the Advanced Security Option in Oracle 9.x/10.x to enable Kerberos authentication - unfortunately, they don't support 3DES

Re: netapp, nfs, kerberos, and ldap

2005-04-07 Thread Jeffrey Altman
user wrote: > I found out when the keytabs were created DES only > for the services. Also in the krb5.conf, we have > > [libdefaults] > ticket_lifetime = 600 > default_realm = EXAMPLE.COM > default_tkt_enctypes = des-cbc-crc > default_tgs_enctypes = des-cbc-crc >

Re: SSPI/GSS-API : mech_dh: Invalid or unknown error

2005-04-07 Thread Jeffrey Altman
Jacques Lebastard wrote: > > Hi folks, > > I wrote a SSPI Client / GSS-API Server application that works fine in a > tree of ActiveDirectory domains / Solaris realm environment where the > KDC are the AD domain controlers. > > Server application is located in mytree.dom and users in child.mytre

GSSAPI error - A token was invalid

2005-04-07 Thread Robert Haycock
Hi, Could someone please give me some idea what this means? ==> sasl_bind: dn="" mech= datalen=53 SASL [conn=0] Failure: GSSAPI Error: A token was invalid (No error) This is output by slapd when trying to get an initial context using sasl from my java app after a successful login, agai

Re: netapp, nfs, kerberos, and ldap

2005-04-07 Thread user
I found out when the keytabs were created DES only for the services. Also in the krb5.conf, we have [libdefaults] ticket_lifetime = 600 default_realm = EXAMPLE.COM default_tkt_enctypes = des-cbc-crc default_tgs_enctypes = des-cbc-crc it seemed to help --

AW: AW: Validation with Kerberos 5, SAP Linux, SNC for SSO

2005-04-07 Thread Jorge Manuel Vieira
Where I can found bc_snc_adapter_101.zip the link from download it`s not available anymore. http://www.sap.com/partners/icc/scenarios/technology/bc-snc.aspx Thanks, Jorge Vieira __

do_gss_auth errors

2005-04-07 Thread Jeff Muzerolle
Hello, I have a RedHat Enterprise 3 server running Netatalk 2.0.2 (which is configured to authenticate using Kerberos or the local password file) and when users try to connect via Kerberos logon, they get the error 'AFP server unavailable'. If I connect to this server authenticating against th

SSPI/GSS-API : mech_dh: Invalid or unknown error

2005-04-07 Thread Jacques Lebastard
Hi folks, I wrote a SSPI Client / GSS-API Server application that works fine in a tree of ActiveDirectory domains / Solaris realm environment where the KDC are the AD domain controlers. Server application is located in mytree.dom and users in child.mytree.dom. However, I sometimes get an erro