Re: ftp GSSAPI messages

2009-10-13 Thread peter sands
> Trace the ftp server and look for ENOENT errors.  I bet you'll find that > either the krb5.conf file or the krb5.keytab file are missing. > > Nico > -- Thanks, you're right I had the keytab but with wrong filename. Now I get another error : GSSAPI error major: Miscellaneous failure GSSAPI erro

Kerberos installation

2009-10-13 Thread sanka
Hello everybody, I know that question I ask is a dummy one, but I hope someone can help me. I would like to install Kerberos V5 as follows: - a KDC server on a LINUX machine - a client on a Windows machine Which steps I should do? Where are the download able files I should obtain? How can I chec

Re: Kerberos installation

2009-10-13 Thread Jonathan Ferguson
sanka wrote: > Hello everybody, > > I know that question I ask is a dummy one, but I hope someone can help me. > I would like to install Kerberos V5 as follows: > - a KDC server on a LINUX machine > - a client on a Windows machine I suggest that you start by Reading The Fine Manual: http://web.m

mod_auth_kerb realm stripping

2009-10-13 Thread Chris Cowley
Hello all I am trying to tweak my mod_auth_kerb setup. Currently it works nicely, I am able to authenticate to web pages on our intranet and everything is dandy. The problem I am having is the contents of Apache's REMOTE_USER variable. Currently it has my REALM on the end, which I do not want. I

Re: mod_auth_kerb realm stripping

2009-10-13 Thread Chris Cowley
On 13 Oct, 17:28, Chris Cowley wrote: > Hello all > > I am trying to tweak my mod_auth_kerb setup. Currently it works > nicely, I am able to authenticate to web pages on our intranet and > everything is dandy. > > The problem I am having is the contents of Apache's REMOTE_USER > variable. Currentl

Re: RFC 3962 and DK(tkey, "kerberos") function

2009-10-13 Thread kerberos
Hello, Thanks for your response! Further stuff inline. On Fri, Oct 9, 2009 at 12:28 PM, Tom Yu wrote: > > The IV is also known as the "cipher state" for CBC ciphers, and each > cryptosystem specification includes a default initial cipher state. > For "simplified profile" (e.g. DES3 and AES) cry

password expiration/change request fails to ask

2009-10-13 Thread Jeff Blaine
Solaris 10 SPARC OS Solaris 10 / Sun sshd MIT Kerberos 1.7 Russ Alberry's fantastic pam_krb5 3.15 linked to above Solaris 9 + MIT Kerberos + RA pam_krb5 works! RHELv5 with stock MIT Kerberos + RA pam_krb5 works! The setup above fails. On the client side, I merely see "Permission denied." instea

Re: password expiration/change request fails to ask

2009-10-13 Thread Russ Allbery
Jeff Blaine writes: > % ssh cairo > jbla...@cairo's password: > Permission denied, please try again. Judging from the password prompt that you're getting, you do not have ChallengeResponseAuthentication enabled on your ssh server, which means that it cannot do a full PAM dialogue. The simple Pa

Re: password expiration/change request fails to ask

2009-10-13 Thread Jeff Blaine
I had a look at sshd_config and saw this: # jblaine note: For some reason setting this to 'yes' does not work # with Solaris 10 sshd (not properly at least). PAMAuthenticationViaKBDInt no Who knows why or when I put that in our master Solaris 10 pam.conf. Turning it on solves the problem. Thank

Re: password expiration/change request fails to ask

2009-10-13 Thread Douglas E. Engert
Jeff Blaine wrote: > Solaris 10 SPARC OS > Solaris 10 / Sun sshd > MIT Kerberos 1.7 > Russ Alberry's fantastic pam_krb5 3.15 linked to above > > Solaris 9 + MIT Kerberos + RA pam_krb5 works! > > RHELv5 with stock MIT Kerberos + RA pam_krb5 works! > > The setup above fails. > > On the client s

kadmin on windows

2009-10-13 Thread Keshava, Pratap M (STSD)
Hi, I am working on a Windows Application. I need to administer Kerberos server present on Linux (or any other) from the application. I am looking for kadmin utility on windows which I can use to configure Kerberos server on Linux. I need to add principals, extract them to a file. Where can I f