create principals in kerberos + openldap as backend (kdb5_ldap_util)

2008-06-25 Thread amit pawar
Hi, I am working configuring MIT Kerberos with openldap as backend. Till now i have been successful with integrating openldap as backend for kerberos. I have followed instruction s from http://web.mit.edu/kerberos/krb5-1.6/krb5-1.6.3/doc/krb5-admin.html#Top and

GSSAPI + IAKERB

2008-06-25 Thread kul gupta
Hello I was going through IAKERB and have some doubts I will be highly thankful if anyone can clear my doubts. 1) Can someone please explain me the scenerio for using IAKERB.? 2) I have to go fopr GSSAPI for IAKERB implementation?? 3) Is there any sample code available for the same? Thanks

Re: GSSAPI + IAKERB

2008-06-25 Thread Jeffrey Hutzelman
--On Wednesday, June 25, 2008 05:04:18 PM +0530 kul gupta [EMAIL PROTECTED] wrote: Hello I was going through IAKERB and have some doubts I will be highly thankful if anyone can clear my doubts. 1) Can someone please explain me the scenerio for using IAKERB.? Take a look at section 1 of

KfW failure to get afs tokens

2008-06-25 Thread David Bear
Using KfW 3.2.2 I ran in to an issue today that I have not seen. Normally, we get the v5 credentials krbtgt/[EMAIL PROTECTED] [EMAIL PROTECTED] and the openafs cache manager also gets [EMAIL PROTECTED] However, today I installed kfw on a machine (windows xp prof) and gave it all the save

Re: strange problem with kinit

2008-06-25 Thread Rohit Kumar Mehta
Thanks Kevin, using k5start and a keytab seems is a much better solution! I did not know this existed. This seems to work quite well. However, if my echo password | kinit script should work, it might be worthwhile to figure out where the problem is. I have done some more tests and saved the

Re: KfW failure to get afs tokens

2008-06-25 Thread Douglas E. Engert
David Bear wrote: Using KfW 3.2.2 I ran in to an issue today that I have not seen. Normally, we get the v5 credentials krbtgt/[EMAIL PROTECTED] [EMAIL PROTECTED] What is the name of your realm? ASU.EDU or asu.edu? Kerberos is case sensitive, but of the KDC is Windows AD it can take either

Solaris 10 SMF manifest for slave KDC inetd stuff?

2008-06-25 Thread Jeff Blaine
Has anyone created a Solaris 10 SMF manifest for the following things which are *supposed* to go in /etc/inetd.conf? Maybe they won't work outside of inetd? krb5_prop stream tcp nowait root /usr/local/sbin/kpropd kpropd eklogin stream tcp nowait root /usr/local/sbin/klogind klogind

How we can enable trace for KINIT utility of Kerberos?

2008-06-25 Thread Din
Hi All, While executing KINIT utility i am getting an error (throwing some random error number) error number is different on different unix boxs. In the case of success KINIT should return 0 but in my case it is returning some error number. My requirement is - How i can enable the trace msgs

Re: strange problem with kinit

2008-06-25 Thread Paul Palacios
You might also want to look into mod_auth_kerb for apache. It may do all that you need and you can place setting in httpd.conf or equiv: IfModule mod_auth_kerb.c KrbAuthRealms XXX.COM KrbMethodNegotiate off KrbVerifyKDC off Krb5Keytab