Re: Using Smartcard with PK-INIT does not respond

2009-03-05 Thread Loren M. Lang
On Wed, 2009-03-04 at 12:11 -0600, John Hascall wrote: Mar 04 07:04:13 server krb5kdc[18148](info): AS_REQ (7 etypes {18 17 16 23 1 3 2}) 192.168.1.237: KDC_RETURN_PADATA: u...@example.com for krbtgt/example@example.com, Cannot allocate memory There is no memory crunch on the

Re: Using Smartcard with PK-INIT does not respond

2009-03-05 Thread Kevin Coffman
On Wed, Mar 4, 2009 at 7:40 PM, Loren M. Lang lor...@alzatex.com wrote: On Wed, 2009-03-04 at 12:16 -0500, Kevin Coffman wrote: On Wed, Mar 4, 2009 at 10:24 AM, Loren M. Lang lor...@alzatex.com wrote: On Wed, 2009-03-04 at 06:33 -0800, Loren M. Lang wrote: This symlinks point to missing

Re: Kerberos in Browser based Applications

2009-03-05 Thread Wyllys Ingersoll
I documented using Kerberos with an Apache Web server and Firefox a while ago (for Solaris 10), but the ideas are very similar for Linux or non-Solaris as long as you stick with Apache, Firefox, and a Kerberos package that is based-on MITs codebase.

Re: Kerberos in Browser based Applications

2009-03-05 Thread Love Hörnquist Åstrand
http://devel.it.su.se/pub/jsp/polopoly.jsp?d=1047 For tomcat, jboss, java-common, ruby examples how to get it working. Love 5 mar 2009 kl. 11:44 skrev Wyllys Ingersoll: I documented using Kerberos with an Apache Web server and Firefox a while ago (for Solaris 10), but the ideas are

Re: Using Smartcard with PK-INIT does not respond

2009-03-05 Thread Loren M. Lang
On Wed, 2009-03-04 at 12:16 -0500, Kevin Coffman wrote: On Wed, Mar 4, 2009 at 10:24 AM, Loren M. Lang lor...@alzatex.com wrote: On Wed, 2009-03-04 at 06:33 -0800, Loren M. Lang wrote: This symlinks point to missing certificates that have nothing to do with the pki

Creating a Kerberos user principal using LDAP

2009-03-05 Thread Dax Kelson
Given a KDC using the LDAP backend, has anyone created a stand alone tool to create user principals by directly adding a LDAP entry? Apparently the difficultly is correctly creating the ASN.1 encoded key attribute (krbPrincipalkey) which is harder still because of the need to encrypt it using the