Re: Openssh, kerberos and Solaris 10

2006-08-08 Thread Erich Weiler
Crud, I was hoping you wouldn't say that... :( -erich Will Fiveash wrote: > On Tue, Aug 08, 2006 at 04:49:14PM -0700, Erich Weiler wrote: >> Hi all- >> >> I'm not sure this is the correct place to post about this but I'm >> getting no response over an OpenSSH.org, if there is a more appropriate

Re: Openssh, kerberos and Solaris 10

2006-08-08 Thread Will Fiveash
On Tue, Aug 08, 2006 at 04:49:14PM -0700, Erich Weiler wrote: > Hi all- > > I'm not sure this is the correct place to post about this but I'm > getting no response over an OpenSSH.org, if there is a more appropriate > place to post please let me know... And the people at Sun scream at me > for

Problem with principal names

2006-08-08 Thread Mordur Ingolfsson
Hi, I'm new to kerberos. I wish to use Kerberos for password verification on a cyrus imap installation. My problem is, that since we serve multiple domains, the usernames are in the form "[EMAIL PROTECTED]" Is it possible to create principals in the form "user/[EMAIL PROTECTED]@REALM.NAME," and

Re: Openssh, kerberos and Solaris 10

2006-08-08 Thread Luke Howard
>libraries in... Not even sure they have GSSAPI at all, maybe just GSS? > Does anyone have any hints on this, or has anyone ever done it? Or >maybe a better place to post? Solaris supports GSS-API but does not expose the Kerberos API or any of the Kerberos mechanism-specific extensions. So w

Openssh, kerberos and Solaris 10

2006-08-08 Thread Erich Weiler
Hi all- I'm not sure this is the correct place to post about this but I'm getting no response over an OpenSSH.org, if there is a more appropriate place to post please let me know... And the people at Sun scream at me for even considering openssh when they supply their own version of SSH which

MITKRB-SA-2006-001: multiple local privilege escalation vulnerabilities

2006-08-08 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 MIT krb5 Security Advisory 2006-001 Original release: 2006-08-08 Topic: multiple local privilege escalation vulnerabilities Severity: serious SUMMARY === In certain application programs packaged in the MIT Kerberos 5 source di

Re: PAM hangs after authenticating against 2003 AD

2006-08-08 Thread Sensei
On 2006-08-08 15:03:46 +0200, "Jesper Angelo" <[EMAIL PROTECTED]> said: > Additional info: > > Local login works using pam_unix... > > Even if I put pam_unix to be optional (ie all passwords are accepted) > it works - except if I put in the right password from the AD. > > So its something with

Re: Problems with kpropd

2006-08-08 Thread Mike Dopheide
My first guess is that the slave KDC doesn't have a host/ entry in the principal database (and in it's krb5.keytab). Check your kerberos logs and see if you're getting a client not found error for host/rapanui.ph.ic.ac.uk Other common propagation problems come from missing entries in kpropd.a

Problems with kpropd

2006-08-08 Thread Juliet Kemp
Hi, I have a working Kerberos master server, and am attempting to set up replication via kpropd. I've followed the steps in the MIT documentation, but then from this command: kprop -f test_kerb_slave_db rapanui.ph.ic.ac.uk I get output: kprop: Cannot resolve network address for KDC in reques

PAM hangs after authenticating against 2003 AD

2006-08-08 Thread Jesper Angelo
Hi, I was looking for a PAM group, but couldnt find one, so I hope someone here might have the knowledge. I am trying to log into my linux box, using password from a Win 2003 AD. Everything seems to be talking, but after login, everything hangs for 30 seconds and then exits out. So if anyone ha