RE: Mod_auth_kerb and Windows XP SP2

2007-04-16 Thread Gopalan, Sriram
Allen, Thanks for you response. 1. I have seen auth dialog pops up on FF and IE after ctrl-alt-del (1 hour). But, its not consistant. 2. If I leave my desktop idle for 10 mins, out corporate policy locks the desktop, but it doesn't create a new ticket when I unlock it. Not sure if that's cont

Re: Mod_auth_kerb and Windows XP SP2

2007-04-16 Thread SriramG
Allen, Thanks for you response. 1. I have seen auth dialog pops up on FF and IE after ctrl-alt-del (1 hour). But, its not consistent. 2. If I leave my desktop idle for 10 mins, out corporate policy locks the desktop, but it doesn’t create a new ticket when I unlock it. Not sure if that’s con

Re: Mod_auth_kerb and Windows XP SP2

2007-04-16 Thread Michael B Allen
> > On the kerbtray I can see a valid ticket (non-expired). > > If the user locks the desktop(ctrl-alt-del) and unlocks it its starts > > working fine again. The TGT is expiring. TGT tickets have a "cumulative ticket life" that is limited by ticket renewal policy. When it expires the secret key is

Re: Mod_auth_kerb and Windows XP SP2

2007-04-16 Thread SriramG
I opened a support call with Microsoft and got an reply that they don't support kerberos authentication if the webserver is Apache even the client is XP-IE. They only support IE-IIS combination. Going back to NTLM is not an option. I can provide ethereal trace if anyone is interested in it. I f

Mod_auth_kerb and Windows XP SP2

2007-04-16 Thread Gopalan, Sriram
All, We are using Apache2 with mod_auth_kerb. Red Hat Enterprise Linux AS release 3 (2.4.21-40.Elsmp) Apache 2.0.49 (fork) mod_auth_kerb-5.3 MIT Kerberos Version 5, Release 1.5.2 Windows XP sp2 (desktop). 1. User logs on to their desktop. 2. I can see TGT using kerbtray. 3. Everything works f

Re: confusion in ank.

2007-04-16 Thread Russ Allbery
Vipin Rathor <[EMAIL PROTECTED]> writes: > While I was playing with kerberos, I came across this issue. > I created a principal 'bug' with the ank command like this: > kadmin: ank -pwexpire "5/5/2007 12:0:0 GMT" -randkey bug > ; it successfully created the principal but when I tried to see >

confusion in ank.

2007-04-16 Thread Vipin Rathor
hi all, While I was playing with kerberos, I came across this issue. I created a principal 'bug' with the ank command like this: kadmin: ank -pwexpire "5/5/2007 12:0:0 GMT" -randkey bug ; it successfully created the principal but when I tried to see this entry it is showing me Password e