Re: 'host' principals

2007-01-08 Thread Jeff Blaine
Excellent explanation, Ken. I don't feel stupid at all for asking my question now that I see it's not as obvious as I thought it would be. I'm glad I asked. Ken Hornstein wrote: >> What's the criteria host-principal-used-or-not is based on >> for various apps? There has to be some sort of crite

Re: 'host' principals

2007-01-08 Thread Ken Hornstein
>What's the criteria host-principal-used-or-not is based on >for various apps? There has to be some sort of criteria >I am not privvy to or maybe a documented list of common >apps and what they require? The base Kerberos protocol specification doesn't talk about naming, because naming ends up bei

Re: 'host' principals

2007-01-08 Thread Jeff Blaine
Ken Raeburn wrote: > On Jan 8, 2007, at 20:45, Jeff Blaine wrote: >> It's my understanding that any Kerberos application server >> (let's say we're going to offer FTP service) needs to have >> a host principal for the FTP server host *in addition to* >> an ftp/whatever principal. Why? I am clearl

Re: 'host' principals

2007-01-08 Thread Ken Raeburn
On Jan 8, 2007, at 20:45, Jeff Blaine wrote: > It's my understanding that any Kerberos application server > (let's say we're going to offer FTP service) needs to have > a host principal for the FTP server host *in addition to* > an ftp/whatever principal. Why? I am clearly failing to > remember s

'host' principals

2007-01-08 Thread Jeff Blaine
[ Really embarassing complete brain failure ] When I played with MIT Kerberos 1.4.3 11 months ago, I understood this concept. Apparently I'm not aging gracefully, as I can't seem to find the documentation that got me through it. I see no real explanation of 'host' principals in the MIT docs. Th

Re: kdb5_util core dumps

2007-01-08 Thread Ken Raeburn
On Jan 4, 2007, at 19:29, Jeff Blaine wrote: > MIT Kerberos 1.5.1 under Solaris 9 SPARC. > > dbx output below. > > The real problem: $(prefix)/var and $(prefix)/var/krb5kdc are > not made at 'make install' time. > > Solve this by making those dirs. This should be caught instead > of coredumping, a

Re: krb5-sync 0.3 released

2007-01-08 Thread g . w
On Jan 5, 7:25pm, Russ Allbery wrote: } Subject: krb5-sync 0.3 released Hi Russ, hope your week is starting out well. Greetings and similar wishes to the rest of the list. > I'm pleased to announce the initial public release of krb5-sync. > > krb5-sync is a toolkit for updating passwords and ac