Re: ping for kdc utility?

2014-04-03 Thread Elia Pinto
I am written a script for this. I can share if interested. Best regards Il 02/apr/2014 21:24 Wang Shouhua shouh...@gmail.com ha scritto: Is there such an utility which can issue a ping (null command) to the kdc to see if it is still responding? Wang -- Wang Shouhua - shouh...@gmail.com

Re: Fwd: Kerberos5 ticket auto renewal

2014-03-18 Thread Elia Pinto
On linux sssd can do ticket renewal and much more. Best regards Il 18/mar/2014 15:18 Predrag Zecevic [Unix Systems Administrator] predrag.zece...@2e-systems.com ha scritto: On 03/18/14 03:00 PM, Wendy Lin wrote: On 18 March 2014 13:54, Tomas Kuthan tomas.kut...@oracle.com wrote: Hi Wendy,

Re: kerberos and selinux

2013-05-23 Thread Elia Pinto
It is a selinux question. So the selinux or the fedora selinux mailing is a better place to ask this questions. Best 2013/5/23, Chris Hecker chec...@d6.com: I run with SELinux enabled, and krb5kdc and kadmin both want read access to /etc/pki/tls on startup. I'm using ldaps as the protocol

Trasparent SSO Kerberos with HPC web portal

2013-04-19 Thread Elia Pinto
Hello A client of mine asked me how it can be complex if not impossible to find a WORKING HPC web Job Scheduler (http://en.wikipedia.org/wiki/Job_scheduler) that supports trasparent SSO in a mixed windows / linux env with an AD as domain dontroller (KERBEROS master KDC ). This web HPC job

Re: Does the KDC provided by MicroSoft AD server work well with client API provided by MIT?

2012-12-26 Thread Elia Pinto
Samba could create keytab, service principal on windows ad best 2012/12/26, Russ Allbery r...@stanford.edu: shuaijie wang wangshuai...@gmail.com writes: Currently I have this requirements: 1. We use Microsoft Active Directory. 2. We have some client programs that build on top of krb5 libs

Re: kerberos / spnego

2012-10-09 Thread Elia Pinto
Sorry for the top posting. Have you seen what authentication mechanism the server offer using for example an explorer plug-ins for dumping the http headers 2012/10/9, miten mehta imi...@yahoo.com: Hi Anurag, I am using Internet Explorer 9 since I read that it supports spnego.  As such I

SPNEGO auth with service principal in other realm work with IE and not with Firefox

2011-10-19 Thread Elia Pinto
Hi to all I have an authentication infrastructure with Windows 2003 AD (realm XXX.EXAMPLE.COM) and clients with windows XPSP3 (XXX.EXAMPLE.COM dns domain). I have a web server web1.YYY.EXAMPLE.COM (YYY.EXAMPLE.COM is also an AD domain in the same forest with a cross trust kerberos auth with

Re: SPNEGO auth with service principal in other realm work with IE and not with Firefox

2011-10-19 Thread Elia Pinto
...@mit.edu [mailto:kerberos-boun...@mit.edu] On Behalf Of Elia Pinto Sent: Wednesday, October 19, 2011 9:38 AM To: kerberos@mit.edu Subject: SPNEGO auth with service principal in other realm work with IE and not with Firefox Hi to all I have an authentication infrastructure with Windows

Re: SPNEGO auth with service principal in other realm work with IE and not with Firefox

2011-10-19 Thread Elia Pinto
2011/10/19 Douglas E. Engert deeng...@anl.gov: On 10/19/2011 10:37 AM, Elia Pinto wrote: Hi to all I have an authentication infrastructure with Windows 2003 AD (realm XXX.EXAMPLE.COM) and clients with windows XPSP3 (XXX.EXAMPLE.COM dns  domain). I have a web server web1.YYY.EXAMPLE.COM

Re: Generic question regarding service principal required to access a kerberized ftp server

2010-05-12 Thread Elia Pinto
2010/4/10 Greg Hudson ghud...@mit.edu: On Sat, 2010-04-10 at 05:28 -0400, Elia Pinto wrote:  I can get a TGS ftp /KDC MVS hostname@ KDC MVS REALMS but it seems  that the client also requests a TGS host /KDC MVS hostname@ KDC MVS  REALMS but this one is not defined on the KDC MVS and so the ftp

Generic question regarding service principal required to access a kerberized ftp server

2010-04-12 Thread Elia Pinto
Hi to all I'm trying to do a ftp logon from a linux client (RHEL 5.4) authenticated via kerberos to an AD (Active Directory) domain to a KDC MVS RACF (SAF mode and nokeytab) in cross-domain realm trust with the AD. The ftp client I'm using is which is distributed by kerberos MIT on RHEL

Re: Generic question regarding service principal required to access a kerberized ftp server

2010-04-10 Thread Elia Pinto
Sorry if repost but i am not sure this mail was received. Hi to all I'm trying to do a ftp logon from a linux client (RHEL 5.4) authenticated via kerberos to an AD (Active Directory) domain to a KDC MVS RACF (SAF mode and nokeytab) in cross-domain realm trust with the AD. The ftp client