Re: syncing MIT Kerberos to Active Directory

2015-10-19 Thread Mantas Mikulėnas
on't strictly need AD for that – if EAP is handled by FreeRADIUS, kcrap-lnf can handle MSCHAPv2 (i.e. the part ntlm_auth usually handles) directly using the MIT KDC database, as the rc4-hmac keys are compatible with what MSCHAPv2 needs. -- Mantas Mikulėnas ___

Re: krb5-1.13.1 is released

2015-02-17 Thread Mantas Mikulėnas
g RSA key 15024CD3749D7889 > gpg: requesting key 15024CD3749D7889 from hkp server pool.sks-keyservers.net > gpg: Total number processed: 1 > gpg: skipped PGP-2 keys: 1 > gpg: Can't check signature: No public key -- Mantas Mikulėnas

Re: kinit -k on boot

2014-09-18 Thread Mantas Mikulėnas
hanks for a answer, > > I didn't know that systemd was also stamping all over cron like that, That's because it doesn't. There is no code in systemd that would read crontab files, nor does it embed itself into a running crond to remove specific functions. -- Mantas Mikulėn

Re: KfW requests ticket with wrong SPN

2012-09-16 Thread Mantas Mikulėnas
he windows LSA credentials >> store, which is not populated by stock KfW 3.2. > > I am aware of that. I just wanted to know why he uses KfW at all and not > SSPI. If this is a simple Kerberos realm (not Active Directory), configuring LSA to obtain Kerberos credentials is much more troublesome than setting up KfW. -- Mantas Mikulėnas Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Two realms and access to Kerberized NFS areas?

2012-09-06 Thread Mantas Mikulėnas
the DIR type is only supported as of MIT Krb5 v1.10 and needs at least nfs-utils v1.2.7-rc5, as well as reconfiguring the client systems – both to create DIR ccaches on login (instead of FILE) and to use DIR for the default ccache. -- Mantas Mikulėnas _

Re: Wallet: a few questions on ACLs (and other animals)

2012-06-14 Thread Mantas Mikulėnas
and _kerberos-master._udp sharing daemons and ports, I see no reason there couldn't be a _wallet._tcp SRV record. > There are also security issues with trusting DNS if you don't have DNSSEC > configured. How are they different from trusting DNS to correctly

Re: Multiple KDCs with OpenLDAP

2012-05-31 Thread Mantas Mikulėnas
nly used when performing password changes or other write operations (kpasswd/kadmin), since normal kprop is unidirectional. But since the multi-master setup allows writing to any LDAP server, it's possible to have kadmind running on all KDCs, and modifications can be done on any of them. --

Re: a question on Kerberos TGS name

2012-02-16 Thread Mantas Mikulėnas
is example, both [kdc_cert] and [client_cert] sections: <http://k5wiki.kerberos.org/wiki/Pkinit_configuration#Extensions_file> -- Mantas Mikulėnas Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

SSH with Kerberos from Windows XP

2008-09-12 Thread Mantas Mikulėnas
l CD User: * I'd prefer to use Microsoft's Kerberos if such a thing exists (MIT Kerberos has a stupid interface) * I use PuTTY for SSH * I have the QuestPuTTY mod * I like command-line * I don't like Cygwin Server: * Heimdal Kerberos * Debian Linux * I know the realm and KDC serve