Re: Possibility of not creating host principals and keytabs for Workstations

2008-01-16 Thread Richard E. Silverman
> "BK" == Barry King <[EMAIL PROTECTED]> writes: BK> I'm looking for a way to use a combination of kerberos & ldap BK> authentication for (primarily Fedora 8) Linux workstations. My BK> goal is to have an automated install that will allow users to BK> authenticate to kerberos

Re: Is "SPN advertisement" or well-known SPNs a security hole?

2008-01-16 Thread Srinivas Kakde
Jeffrey wrote: > For example, if you are trying to authenticate to the ftp server at > ftp.secure-endpoints.com you should be asking for the shared secret for > host/[EMAIL PROTECTED] But what if you > didn't ask for that but instead waited for the server to give you a > name. Let's say that

Possibility of not creating host principals and keytabs for Workstations

2008-01-16 Thread Barry King
I'm looking for a way to use a combination of kerberos & ldap authentication for (primarily Fedora 8) Linux workstations. My goal is to have an automated install that will allow users to authenticate to kerberos immediately after install, without the need to create host principals or extract keyta

enctypes - KDC

2008-01-16 Thread Wojtek
Howto adding supported enctypes to kdc? I want to add rc4-hmac, but i don`t know it is possible. Sorry for my english;) Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Creating and assigning policies

2008-01-16 Thread Dennis Putnam
I have an installed Kerberos database that I need to set up policies for. As such I have 2 questions: 1) This is an established working kda but no policies are assigned to any principals. However, when I do a listpol, I get back: policy1438560min. Is this a required default policy the insta

Re: kinit shows clear text password on terminal !

2008-01-16 Thread Philippe Marty
Michael Calmer wrote: > Am Mittwoch, 16. Januar 2008 schrieb Philippe Marty: >> >> # kinit user >> Password for [EMAIL PROTECTED]:password_in_clear_text_here! >> New ticket is stored in cache file /tmp/krb5cc_0 >> >> is this normal? > > Please check which kinit you use. > > $> which kinit > > I

KSU fails to select the correct cache

2008-01-16 Thread Amir Saad
Hi, I setup Kerberos and OpenLDAP successfully. I installed NFS4 and it is protected by Kerberos. Everything works fine at login, however; it fails when I ksu. If I login as user2 (1002) and then try to ksu user1 (1001), I get permission denied when I try to ls my home directory. I tried the o

Re: kinit shows clear text password on terminal !

2008-01-16 Thread Michael Calmer
Hi, Am Mittwoch, 16. Januar 2008 schrieb Philippe Marty: > Hi there, > > I just installed a krb5 server on a scientific linux box. > > I then have tested the basics: > > # kadmin -p user > Authenticating as principal user with password. > Password for [EMAIL PROTECTED]: > kadmin: quit > > this is

kinit shows clear text password on terminal !

2008-01-16 Thread Philippe Marty
Hi there, I just installed a krb5 server on a scientific linux box. I then have tested the basics: # kadmin -p user Authenticating as principal user with password. Password for [EMAIL PROTECTED]: kadmin: quit this is ok! # kinit user Password for [EMAIL PROTECTED]:password_in_clear_text_here!

Re: How to lock/unlock the user principal

2008-01-16 Thread Ido Levy
Kenneth, Thank you for the info ! What do you mean by saying "when building Kerberos named something like updates database" ? Did you test this feature ? Thanks, Ido Levy Kenneth Grady