Re: Colon madness: Ticket cache: DIR::/run/user vs Ticket cache: DIR:/run/user

2014-09-17 Thread Predrag Zecevic [Unix Systems Administrator]
Hi, does your environment modifies KRB5* variables ? $ env | grep KRB5 Best regards. Predrag Zečević On 09/17/14 10:09 AM, Lionel Cons wrote: Why does klist -A use Ticket cache: DIR::/run/user with two colons instead of one, even if /etc/krb5.conf uses one colon? Lionel

Re: error: PAM: User account has expired for wlin from hongkong.test.org - why?

2014-04-01 Thread Predrag Zecevic [Unix Systems Administrator]
On 04/ 1/14 10:16 AM, Wendy Lin wrote: On 18 March 2014 22:11, Wendy Lin wendlin1...@gmail.com wrote: Can anyone explain this pam error to me? I have configured a machine (192.168.2.105) as Kerberos5 client on Suse 12.3 via yast talking to the kdc at 192.168.2.98 and now get this error on the

Re: error: PAM: User account has expired for wlin from hongkong.test.org - why?

2014-04-01 Thread Predrag Zecevic [Unix Systems Administrator]
On 04/ 1/14 10:54 AM, Wendy Lin wrote: On 1 April 2014 10:29, Predrag Zecevic [Unix Systems Administrator] predrag.zece...@2e-systems.com wrote: On 04/ 1/14 10:16 AM, Wendy Lin wrote: On 18 March 2014 22:11, Wendy Lin wendlin1...@gmail.com wrote: Can anyone explain this pam error to me? I

Re: root login via Kerberos5 - User not known to the underlying authentication module - why?

2014-03-24 Thread Predrag Zecevic [Unix Systems Administrator]
On 03/24/14 11:31 AM, Wendy Lin wrote: I am trying to allow user root (uid=0) to be authenticated via Kerberos5 at login time, too, but if I do I get a User not known to the underlying authentication module error and login is refused. OS is Suse 13.1 pam config is: grep -r krb5 /etc/pam.d/

Re: Fwd: Kerberos5 ticket auto renewal

2014-03-18 Thread Predrag Zecevic [Unix Systems Administrator]
On 03/18/14 03:00 PM, Wendy Lin wrote: On 18 March 2014 13:54, Tomas Kuthan tomas.kut...@oracle.com wrote: Hi Wendy, (I can only comment on Solaris) I suppose, you are referring to automatic renewal of tickets by ktkt_warnd. ktkt_warn service is enabled by default, but there are upgrade

Re: Password Ldap syncing

2013-03-21 Thread Predrag Zecevic [Unix Systems Administrator]
Hi, we have implemented shell/php scripts which change password for user (based on password policy) AND set kerberos password to be same as userPassword attribute. That way, both are in sync (only for users which are supposed to have krbPrincipalName defined)... Our implementation (MIT Kerberos

Re: Need Help on kinit authentication.

2012-03-15 Thread Predrag Zecevic [Unix Systems Administrator]
[Unix Systems Administrator] wrote: Hi, what is wrong with command line interface? kadmin -p root/admin \ -q change_password -pw $newPassword testu...@example.com P.S. we are using Keberos 5 1.9 and 389-DS as backend and that works. Regards. On 14.03.2012 11:46, Rajeswari Ramasamy