Re: Kerberos documentation website down?

2017-03-13 Thread Tom Yu
"Earl A. Killian" writes: > Reference #97.9355434d.1489429031.113b6c49 I believe this is an error from the Akamai CDN. How recently did you receive this error? I know there was a possible connectivity issue at MIT that caused errors such as that, but I thought it was resolved.

Re: next Kerberos ops/admin teleconference March 7

2017-03-07 Thread Tom Yu
Meeting password: 2NBYnB26 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

next Kerberos ops/admin teleconference March 7

2017-03-06 Thread Tom Yu
do you wish you knew when you started working with Kerberos but had trouble discovering? * What Kerberos-related tasks do you find difficult or impossible that you wish were easier? You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT

Re: next Kerberos ops/admin teleconference February 7

2017-02-07 Thread Tom Yu
Meeting password: p4Xum9d3 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

next Kerberos ops/admin teleconference February 7

2017-02-06 Thread Tom Yu
? Recurring topics: * What do you wish you knew when you started working with Kerberos but had trouble discovering? * What Kerberos-related tasks do you find difficult or impossible that you wish were easier? You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting

Re: next Kerberos ops/admin teleconference January 3

2017-01-03 Thread Tom Yu
Meeting password: CF3YCs39 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

next Kerberos ops/admin teleconference January 3

2017-01-02 Thread Tom Yu
working with Kerberos but had trouble discovering? * What Kerberos-related tasks do you find difficult or impossible that you wish were easier? You can forward this invitation to others. Hello , Tom Yu changed the date for this online meeting. Topic: MIT Kerberos admin/ops feedback session Date

Re: next Kerberos ops/admin teleconference December 6

2016-12-06 Thread Tom Yu
Meeting password: 39DFZpD6 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

next Kerberos ops/admin teleconference December 6

2016-12-05 Thread Tom Yu
1.15 Recurring topics: * What do you wish you knew when you started working with Kerberos but had trouble discovering? * What Kerberos-related tasks do you find difficult or impossible that you wish were easier? You can forward this invitation to others. Hello , Tom Yu changed the date and

Re: no src/util/reconf

2016-12-03 Thread Tom Yu
Michael Ströder writes: > src/util/reconf is not available anymore in the source tree. > > Does that mean one should simply use plain autoreconf instead? Correct. We updated the documentation accordingly: http://web.mit.edu/kerberos/krb5-latest/doc/build/doing_build.html Perhaps we should mak

krb5-1.15 is released

2016-12-02 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.15. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING KER

Re: next Kerberos ops/admin teleconference November 1

2016-11-01 Thread Tom Yu
Meeting password: BJWJT586 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

next Kerberos ops/admin teleconference November 1

2016-10-31 Thread Tom Yu
re easier? You can forward this invitation to others. Hello , Tom Yu changed the date for this online meeting. Topic: MIT Kerberos admin/ops feedback session Date: The 1st Tuesday of every month, from Tuesday, November 1, 2016, to no end date Time: 1:00 pm, Eastern Daylight Time (New York,

Re: .kinit: Preauthentication failed while getting initial credentials

2016-10-27 Thread Tom Yu
Thomas Beaudry writes: > So i got it to work by switch the encryption type. In case anyone is > wondering i used: addent -password -p ${user} -k 1 -e rc4-hmac It's possible that the problem is related to password salting. (The RC4 enctype has no salt, but the AES ones do.) We've observed th

Re: Regarding the software MIT Kerberos for Windows version 4.1

2016-10-06 Thread Tom Yu
[Dropped krbdev from the CC list; please don't copy it on replies to this thread.] "Kumar, Ashish /CS" writes: > Hello Team, Please note this is a public Kerberos community support forum, not a private team contact point. The MIT Kerberos Team does not generally provide private customer suppor

next Kerberos ops/admin teleconference October 4

2016-10-03 Thread Tom Yu
ring topics: * What do you wish you knew when you started working with Kerberos but had trouble discovering? * What Kerberos-related tasks do you find difficult or impossible that you wish were easier? You can forward this invitation to others. Hello , Tom Yu changed the date for this on

Re: Questions about Kerberos V5

2016-09-23 Thread Tom Yu
houyuan <15606931...@163.com> writes: >I have a strange question here. I hope to get a solution. >I set the timing task to get the authentication information. > >but > > and KDC Server log It seems like you attached some images to yo

krb5-1.13.7 is released

2016-09-16 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.13.7. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

krb5-1.14.4 is released

2016-09-14 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.14.4. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

Re: next Kerberos ops/admin teleconference September 6

2016-09-06 Thread Tom Yu
Meeting password: 3cU6TAk5 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

recent improvements to KDC database robustness

2016-09-05 Thread Tom Yu
We recently made two sets of commits to the master branch of the krb5 source tree that improve the robustness of the Berkeley DB btree ("DB2") KDC database back end against rare instances of database corruption. These improvements, which will be available in upcoming releases, are recursive dump su

next Kerberos ops/admin teleconference September 6

2016-09-05 Thread Tom Yu
. Hello , Tom Yu changed the date for this online meeting. Topic: MIT Kerberos admin/ops feedback session Date: The 1st Tuesday of every month, from Tuesday, September 6, 2016, to no end date Time: 1:00 pm, Eastern Daylight Time (New York, GMT-04:00) Meeting Number: 640 256 582 Meeting

Re: Update config.guess and config.sub

2016-08-31 Thread Tom Yu
Julien ÉLIE writes: > Could they be updated in the next release? (And, even better, could the > update of these two files be added in the release process so that they > are always kept up-to-date?) I've added this step to our release checklist as a manual step. I don't want it to happen auto

Re: build failure with openssl-1.1.0

2016-08-31 Thread Tom Yu
Eray Aslan writes: > Trying to build krb5-1.14.3 with openssl-1.1.0 fails in at least pkinit > and k5tls modules. Hopefully, someone has enough cycles to hava a look. There is an open pull request for openssl-1.1 compatibility: https://github.com/krb5/krb5/pull/447 This support will proba

Re: Gateway to comp.protocols.kerberos

2016-08-30 Thread Tom Yu
Julien ÉLIE writes: > This mailing-list is supposed to be bidirectionally gatewayed to the > comp.protocols.kerberos newsgroup. > I think it stopped working last year. Is it intentional? Otherwise, > could the gateway be restored? There was a hostname change on the usenet server that the lis

Re: krb5-1.14.3, make check, test3: btree: failed

2016-08-26 Thread Tom Yu
"squidmob...@fastmail.fm" writes: > i figured out the problem: lack of disk space. > Test 3: hash: small key, big data pairs > dbtest: write: Success > test3: hash: failed > make[3]: *** [check] Error 1 Thanks for following up. That makes sense. dbtest prints an error message w

Re: I have one problem, I do not know whether this is a bug.

2016-08-21 Thread Tom Yu
[dropped kerberos-announce-owner from CCs; please don't CC that address] hexiaowen writes: > The version of krb5 Iused is krb5-1.13.2-12.el7 > > I built a kerberos server, there are more than 20 principals in the database. > > Because of some reason, I do executed "kadmin -q "listprincs"" ervery

Re: next Kerberos ops/admin teleconference August 2

2016-08-02 Thread Tom Yu
Meeting password: SPGY5h68 Tom Yu writes: > Kerberos operators and administrators are invited to a public monthly > operations-focused teleconference. These take place the first Tuesday > of each month at 13:00 (1:00pm) US Eastern Time. The next one will be > on August 2. &g

next Kerberos ops/admin teleconference August 2

2016-08-01 Thread Tom Yu
* how to consolidate per-principal settings of ticket policy to a policy object, e.g., ticket lifetimes You can forward this invitation to others. Hello , Tom Yu changed the date for this online meeting. Topic: MIT Kerberos admin/ops feedback session Date: The 1st Tuesday of every month, from

Re: krb5-1.14.3, make check, test3: btree: failed

2016-07-30 Thread Tom Yu
"squidmob...@fastmail.fm" writes: > Test 3: btree: small key, big data pairs > page size 512 > page size 16384 > page size 16384 > page size 65536 > dbtest: write: Success > test3: btree: page size 65536: failed > > what does it mean? (other than the o

krb5-1.13.6 is released

2016-07-26 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.13.6. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

krb5-1.14.3 is released

2016-07-21 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.14.3. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

Re: Hadoop-Kerberos aunthentication flow

2016-07-12 Thread Tom Yu
This list forbids image attachments. Please post it on the web somewhere and send a link in your email. Thanks, -Tom "Mirkar, Shahezad" writes: > Hi, > > It seems image is filtered can you send it again? > > Thanks and Regards, > Shahezad Mirkar > > -Original Message- > From: kerberos-

kfw-4.1 is released

2016-07-01 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team is happy to announce the availability of the kfw-4.1 release. The KfW 4.1 series of releases is based on the MIT krb5 1.13 series of releases, modernizing the support relative to the KfW 4.0 series, which was based on the MIT krb5

canceled: Kerberos ops/admin teleconference July 5

2016-06-30 Thread Tom Yu
There will be no Kerberos ops/admin teleconference on July 5, due to the adjacent US Independence Day holiday. If you would like to suggest topics for future ops/admin telconferences, please send me email. Thanks, -Tom Kerberos mailing list

Re: Can't get a TGS ticket from read-only domain controller

2016-06-21 Thread Tom Yu
It looks like you sent an email with only text/html, which the mailing list software strips out. You might want to make sure that you configure your email to send text/plain as well. I'm quoting your previous message below so others can see it: writes: > Hmmm. Not sure what happened. Here's th

Re: next Kerberos ops/admin teleconference June 7

2016-06-07 Thread Tom Yu
meeting password: cDyjh727 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

next Kerberos ops/admin teleconference June 7

2016-06-06 Thread Tom Yu
UI compatibility to MIT ktutil * keytab manipulation in general; what else could be improved? You can forward this invitation to others. Hello , Tom Yu changed the date for this online meeting. Topic: MIT Kerberos admin/ops feedback session Date: The 1st Tuesday of every month, from Tuesday

Re: F5 seeing ASFD server as external device?

2016-05-24 Thread Tom Yu
"GALSTER, ALAN A CIV USAF AFMC AFLCMC/HNIA" writes: > Trying to implement F5 with BIG IP (Kerberos) and ran into this. Anyone seen > this before? I'm not finding any expansions of "ASFD" that make sense in context; perhaps you could elaborate a bit on what "ASFD" means and what you are trying

kfw-4.1-beta3 is available

2016-05-24 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 MIT Kerberos for Windows 4.1-beta3 is now available for download from http://web.mit.edu/kerberos/dist/testing.html The main MIT Kerberos web page is http://web.mit.edu/kerberos/ Please send comments to the krbdev list. Major cha

Re: next Kerberos ops/admin teleconference May 3

2016-05-03 Thread Tom Yu
Meeting password: 9KYUSZ66 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

next Kerberos ops/admin teleconference May 3

2016-05-02 Thread Tom Yu
reasons * Ease of building from source You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every month, from Tuesday, May 3, 2016, to no end date 1:00 pm | Eastern Daylight Time (New York

krb5-1.13.5 is released

2016-04-20 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.13.5. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

krb5-1.14.2 is released

2016-04-20 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.14.2. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

Re: Kerberos - Price

2016-04-11 Thread Tom Yu
Hi, please drop krb...@mit.edu from replies to this thread. The krbdev list is for communciation among participants in the MIT Kerberos open source project. Elna van Rooyen writes: > I would like to know what the new price for Kerberos is. > We are using HPUX and Windows and would like to setup

canceled: Kerberos admin/ops teleconference April 5

2016-04-04 Thread Tom Yu
There will be no Kerberos admin/ops teleconference on April 5. If you would like to suggest topics for future admin/ops telconferences, please send me email. Thanks, -Tom Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mail

krb5-1.13.4 is released

2016-03-07 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.13.4. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

krb5-1.14.1 is released

2016-03-01 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.14.1. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

Re: next Kerberos ops/admin teleconference March 1

2016-03-01 Thread Tom Yu
webex password is: Qg9Pim36 Tom Yu writes: > Kerberos operators and administrators are invited to a public monthly > operations-focused teleconference. These take place the first Tuesday > of each month at 13:00 (1:00pm) US Eastern Time. The next one will be > on March 1. &g

next Kerberos ops/admin teleconference March 1

2016-02-29 Thread Tom Yu
/Roadmap https://ist-jira.atlassian.net/issues/?filter=16402 You can forward this invitation to others. Hello , Tom Yu invites you to attend this online meeting. Topic: MIT Kerberos admin/ops feedback session Date: The 1st Tuesday of every month, from Tuesday, November 3, 2015, to no end date Time

Re: Full-text searchable mailing list archive

2016-02-09 Thread Tom Yu
Karl-Philipp Richter writes: > Is this list available in a full-text searchable mailing list archive? > [archive link] doesn't provide any practically usable search feature > because of the separation by date - downloading the mbox or gz archives, > extracting and grepping them with a script come

Re: next Kerberos ops/admin teleconference February 2

2016-02-02 Thread Tom Yu
Meeting password: cJpPw684 Tom Yu writes: > Kerberos operators and administrators are invited to a public monthly > operations-focused teleconference. These take place the first Tuesday > of each month at 13:00 (1:00pm) US Eastern Time. The next one will be > on February 5. &g

next Kerberos ops/admin teleconference February 2

2016-02-01 Thread Tom Yu
/kerberos/2016-February/021136.html * Making command line syntaxes more uniform by using getopt_long() * krb5-1.15 release feature requests * Roadmap feedback and feature requests http://k5wiki.kerberos.org/wiki/Roadmap You can forward this invitation to others. Hello , Tom Yu invites you

KDC UDP behavior change on multihomed hosts on older OSes

2016-02-01 Thread Tom Yu
Hi, This message probably only concerns you if you are running a multihomed KDC on an operating system that lacks support for IP_PKTINFO or IPV6_PKTINFO. We are working on a set of changes to the network code of the KDC and kadmind that could cause a behavior change for such systems: UDP packets

Re: kprop with multiple or NATted IP address

2016-01-28 Thread Tom Yu
Russ Allbery writes: > Jerry Shipman writes: > >> (I thought about that about 5 minutes after I sent the email — oops.) > >> I guess my question is: does kprop do anything other than: secrecy of >> the data in transmission, integrity of the transmission, kdb5_util >> dump/load ? Or can I really

Re: Newbie

2016-01-21 Thread Tom Yu
andrey writes: > Guys, may I ask if > http://web.mit.edu/kerberos/krb5-latest/doc/build/doing_build.html way > of installing kerberos sould work? Unfortunately, that documentation is "frozen" to the krb5-1.14 release, and doesn't reflect changes since then. Documentation such as that located

Re: Newbie:

2016-01-21 Thread Tom Yu
andrey writes: > test reply. Please note that your messages were caught in the moderation queue because you're not subscribed to the list. Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Even following kerberos5.1-14's installing guide, there are two stange problems.

2016-01-13 Thread Tom Yu
Hi. Someone (perhaps me) will probably answer this query later. Please drop krb5-bugs from the CC line, because this is not a bug report. We might need to improve our documentation, but I prefer to have a good proposal of specific changes before opening a bug report about it. -Tom George Lin

Re: next Kerberos ops/admin teleconference January 5

2016-01-05 Thread Tom Yu
The WebEx password for today's call is ahmuM387 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

next Kerberos ops/admin teleconference January 5

2016-01-04 Thread Tom Yu
http://k5wiki.kerberos.org/wiki/Roadmap You can forward this invitation to others. Hello , Tom Yu invites you to attend this online meeting. Topic: MIT Kerberos admin/ops feedback session Date: The 1st Tuesday of every month, from Tuesday, November 3, 2015, to no end date Time: 1:00 pm

krb5-1.12.5 is released

2015-12-16 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.12.5. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

krb5-1.13.3 is released

2015-12-04 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.13.3. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

meeting password for today's Kerberos ops/admin teleconference

2015-12-01 Thread Tom Yu
The meeting password is: i6fMU5x7 Tom Yu writes: > Kerberos operators and administrators are invited to a public monthly > operations-focused teleconference. These take place the first Tuesday > of each month at 13:00 (1:00pm) US Eastern Time. The next one will be > on December 1.

next Kerberos ops/admin teleconference December 1

2015-11-30 Thread Tom Yu
/wiki/Roadmap You can forward this invitation to others. Hello , Tom Yu invites you to attend this online meeting. Topic: MIT Kerberos admin/ops feedback session Date: The 1st Tuesday of every month, from Tuesday, November 3, 2015, to no end date Time: 1:00 pm, Eastern Standard Time (New York

krb5-1.14 is released

2015-11-20 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.14. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING KER

meting password for today's Kerberos ops/admin teleconference

2015-11-03 Thread Tom Yu
The meeting password is: Wkp4wK38 Tom Yu writes: > Kerberos operators and administrators are invited to a public monthly > operations-focused teleconference. These take place the first Tuesday > of each month at 13:00 (1:00pm) US Eastern Time. The next one will be > on November 3.

next Kerberos ops/admin teleconference November 3

2015-11-02 Thread Tom Yu
Kerberos operators and administrators are invited to a public monthly operations-focused teleconference. These take place the first Tuesday of each month at 13:00 (1:00pm) US Eastern Time. The next one will be on November 3. This is an opportunity for operators or administrators of Kerberos depl

next Kerberos ops/admin teleconference October 6

2015-10-05 Thread Tom Yu
forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date 1:00 pm | Eastern Standard Time (New York, GMT-05:00) | 1 hr JOIN WEBEX MEETING

Re: Account lockout / replication issue

2015-09-09 Thread Tom Yu
Mark Pröhl writes: > according to http://web.mit.edu/kerberos/krb5-1.13/doc/admin/lockout.html, > the account lockout state is represented by the three account properties "The > time of last successful authentication", "The time of last failed > authentication" and "A counter of failed attempt

next Kerberos ops/admin teleconference September 1st

2015-08-31 Thread Tom Yu
impossible that you wish were easier? To suggest additional topics, please send email to t...@mit.edu. You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November

canceled: August 4th Kerberos ops/admin teleconference

2015-08-03 Thread Tom Yu
Due to schedule conflicts, the August 4th Kerberos ops/admin teleconference is canceled. We expect to resume these monthly teleconferences on September 1st. Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/ke

Re: kerberos ticket cache

2015-07-10 Thread Tom Yu
Andrew Levin writes: > I have noticed that even after I delete my kerberos ticket cache, as below, I > remain authenticated (eg I can open files in an area where kerberos > authentication is required). How is this possible? > > [anlevin@lxplus0055 ~]$ klist > Ticket cache: FILE:/tmp/krb5cc_1353

next Kerberos ops/admin teleconference July 7th

2015-07-06 Thread Tom Yu
suggest additional topics, please send email to t...@mit.edu. You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date 1:00 pm

Re: Unable to access kdc after changing password

2015-06-19 Thread Tom Yu
"Podrigal, Aron" writes: > kadmin: change_password K/M > kadmin: quit > > Which should change the master password, no? > > But now i can't seem to get access to the database The master key K/M is special and can't be changed in a useful way by using the kadmin change_password command. It is pr

Re: Erratic behavior of full resync process

2015-06-10 Thread Tom Yu
Greg Hudson writes: > /dev/random starvation explains the clock skew errors This is a troubleshooting point that we should emphasize more: A Kerberos message might be within the clock skew tolerance when sent, but for whatever reason, the receiver might delay processing it until it is no longer

next Kerberos ops/admin teleconference June 2nd

2015-06-01 Thread Tom Yu
suggest additional topics, please send email to t...@mit.edu. You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date 1:00 pm

krb5-1.12.4 is released

2015-06-01 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.12.4. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

Re: PKINIT cert chains

2015-05-22 Thread Tom Yu
"Nordgren, Bryce L -FS" writes: > You've prompted me to draw a picture. The collection of "intermediate" > certificates is no such thing. I appear to have been given a bag of unrelated > fragments of CA chains. Many apologies for lack of due diligence. PKI tools > are still pretty awkward for

Re: PKINIT cert chains

2015-05-21 Thread Tom Yu
"Nordgren, Bryce L -FS" writes: > Attached, please find a tarball of config and certs and disposable private > keys on my test system (which has both KDC and client). Also, > home/bnordgren/mycert1.pem is the cert off of my smart card. Thanks. I think you're missing the "OU=Entrust Managed Se

Re: PKINIT cert chains

2015-05-21 Thread Tom Yu
"Nordgren, Bryce L -FS" writes: > 1] Does my KDC cert have to chain back to the same anchor as my smart card > certificates? I think no, in general, but configuration might be more complicated for your deployment if they're different. > 2] Is the error below related to the KDC's cert chain or

krb5-1.13.2 is released

2015-05-11 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.13.2. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

next Kerberos ops/admin teleconference May 5th

2015-05-04 Thread Tom Yu
suggest additional topics, please send email to t...@mit.edu. You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date 1:00 pm

next Kerberos ops/admin teleconference April 7th

2015-04-06 Thread Tom Yu
. You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date 1:00 pm | Eastern Standard Time (New York, GMT-05:00) | 1 hr JOIN

next Kerberos ops/admin teleconference March 3rd

2015-03-02 Thread Tom Yu
were easier? To suggest additional topics, please send email to t...@mit.edu. You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to

krb5-1.11.6 is released

2015-02-25 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.11.6. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

krb5-1.12.3 is released

2015-02-20 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.12.3. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

Re: krb5-1.13.1 is released

2015-02-20 Thread Tom Yu
Mantas Mikulėnas writes: > On 2015-02-13 02:45, Tom Yu wrote: >> -BEGIN PGP SIGNED MESSAGE- > > For the record, GnuPG v2.1.x dropped support for PGP-2 format keys > (aka version 3 keys), so these announcements cannot be verified anymore: > >> gpg: Signature m

krb5-1.13.1 is released

2015-02-12 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.13.1. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING K

next Kerberos ops/admin teleconference February 3rd

2015-02-02 Thread Tom Yu
forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date 1:00 pm | Eastern Standard Time (New York, GMT-05:00) | 1 hr [1]Join

Re: question about MIT kpasswd and RPCSEC_GSS

2015-01-21 Thread Tom Yu
Will Fiveash writes: > Thanks, I was looking through some older notes I made about this and the > code and felt I had entered a maze of twisty passages that all looked > alike. Anyway (to make sure I'm clear) it's my understanding that MIT > back in 1.4 added support for kadmin/kadmind communica

Re: question about MIT kpasswd and RPCSEC_GSS

2015-01-21 Thread Tom Yu
Will Fiveash writes: > When talking to a older Solaris KDC that only supports the RPCSEC_GSS > protocol for change password request, will the current MIT kpasswd > command just work or does it require some non-default configuration > (some parameter set in krb5.conf)? My recollection is that we

next Kerberos ops/admin teleconference January 6th

2015-01-05 Thread Tom Yu
forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date 1:00 pm | Eastern Standard Time (New York, GMT-05:00) | 1 hr

Re: Problems when using kadmin instead of kadmin.local

2014-12-18 Thread Tom Yu
Marc Richter writes: > your answer seems to have pointed me into the right direction: It > seems as if it stands in relation with the very large values I > assigned: [...] > Not sure if this has to be classified as a bug or not now > ... normally, kadmin and kadmin.local should behave the same

Re: Problems when using kadmin instead of kadmin.local

2014-12-17 Thread Tom Yu
Marc Richter writes: > root@deb-krb:/etc# kadmin.local -m -p user/ad...@example.com > Authenticating as principal user/ad...@example.com with password. > Enter KDC database master key: > kadmin.local: get_policy admin > Policy: admin > Maximum password life: 315360 Do you get a failure when

next Kerberos ops/admin teleconference December 2nd

2014-12-01 Thread Tom Yu
suggest additional topics, please send email to t...@mit.edu. You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date

next Kerberos ops/admin teleconference November 4th

2014-11-03 Thread Tom Yu
topics, please send email to t...@mit.edu. You can forward this invitation to others. Hello, Tom Yu changed the WebEx meeting information. MIT Kerberos admin/ops feedback session The 1st Tuesday of every 1 months, from Tuesday, November 4, 2014, to no end date 1:00 pm

krb5-1.13 is released

2014-10-15 Thread Tom Yu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The MIT Kerberos Team announces the availability of MIT Kerberos 5 Release 1.13. Please see below for a list of some major changes included, or consult the README file in the source tree for a more detailed list of significant changes. RETRIEVING KER

Re: documentation on how to set $KRB5CCNAME for kerberized/gssapi applications

2014-10-09 Thread Tom Yu
Natxo Asenjo writes: > When implementing rsyslog with gssapi > (http://www.rsyslog.com/doc/gssapi.html) I came accross the issue > that the rsyslog software expects the credentials cache of the host > principal in /tmp/krb5cc_0; the centos 6.5 hosts joined to a freeipa > kerberos domain save tha

next Kerberos ops/admin teleconference October 7th

2014-10-06 Thread Tom Yu
Kerberos operators and administrators are invited to a public monthly operations-focused teleconference. These take place the first Tuesday of each month at 13:00 (1:00pm) US Eastern Time. The next one will be on October 7th. This is an opportunity for operators or administrators of Kerberos dep

next Kerberos ops/admin teleconference September 2nd

2014-09-01 Thread Tom Yu
Kerberos operators and administrators are invited to a public monthly operations-focused teleconference. These take place the first Tuesday of each month at 13:00 (1:00pm) US Eastern Time. The next one will be on September 2nd. This is an opportunity for operators or administrators of Kerberos d

  1   2   3   4   5   6   >