Re: pam_krb5 against w2k3 very slow?

2005-04-19 Thread Dave
Hi, we connected a linux box with w2k3 and installed pam_krb5 for sshd. In principle it works but it takes about 10sec to authenticate?! The servers work in a test environment means basically no load. The krb5 installation is heimdal 0.61 but I dont know if this really has do with the

replay cache proposal

2005-04-19 Thread Pitrich, Karl
Hi, I encounter problems with the replay cache on the client side while using a SPNEGO auth module for apache. The replay cache, per default, gets persisted in files. Under heavy load, the replay cache runs out of FD's ('to many open files'). Further, when using multiple kerberized Webservices

Kerberos API reference

2005-04-19 Thread Saber Zrelli
Hi , Is there any availabele API reference desribing the MIT kerberos KDC code. I need to know how to create and excange tickets between KDCs. any pointers are welcome. Many thanks. -- Saber ZRELLI [EMAIL PROTECTED] Japan Advanced Institute of Science and Technology Center of Information

Re: replay cache proposal

2005-04-19 Thread Jeffrey Altman
Pitrich, Karl wrote: Hi, I encounter problems with the replay cache on the client side while using a SPNEGO auth module for apache. The replay cache, per default, gets persisted in files. Under heavy load, the replay cache runs out of FD's ('to many open files'). Further, when using

MIT Kerberos on IBM Mainframes

2005-04-19 Thread Rahul.Jain
Does anyone use MIT KRB5 (preferably via GSS-API) on IBM mainframes with CICS? What about with Linux? TIA, Rahul Jain Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Problems with kadmind

2005-04-19 Thread Mike Friedman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 We're running a krb5-1.3.4 KDC on a Solaris 8 Ultra-10 box with 384Mb of real memory. Our database has about 280K principals (it's about 250Mb in size). Lately, we've been seeing problems with kadmin responses, in particular timing out on long

encryption type used by windows client for AS-REQ

2005-04-19 Thread Surendra
Hi Team, This is regarding Pre-auth issue: How can I know... what encryption type to be used for pre-authentication from KDC client? Some one has answered about 'Use DES' flag (mentioned in the mail below). But how to extract the Encryption information from the pre-auth reply error message?