Kerberos expertise?

2019-10-09 Thread Rendall, Steve
Hello Kerberos Consortium, I'm looking for some assistance finding some Kerberos expertise on a large defense contractor project that my company is working on. Any chance you could point me to some resources for Kerberos consulting and implementation services? Thanks! Steve Rendall Senior

Re: how to set default TGT file path

2014-12-24 Thread steve
these days. There is a keyring cache in the kernel. I think that's what you need. Cheers, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: How does the NFS client find a users tickets in a filesystem?

2014-09-15 Thread steve
On Mon, 2014-09-15 at 09:44 +0100, moritz.will...@ubs.com wrote: Wendy, rpc.gssd on Linux looks in /tmp for files which start with krb5cc. The location where rpc.gssd is looking can be overridden with the -d option. Hi On systemd they're not under /tmp but default to /run/user instead. Could

Re: Strange behaviour of kinit

2014-09-13 Thread steve
On Fri, 2014-09-12 at 22:08 +0200, Lars Hanke wrote: Am 12.09.2014 21:14, schrieb steve: DNS? Is the 386 client pointing _only_ at the Samba4 DC? The 386 client points to the AD DNS. Does Samba4 DC == AD DNS? Guessing: You don't want to use any domain services on the 386 client. You

Re: Strange behaviour of kinit

2014-09-12 Thread steve
On Fri, 2014-09-12 at 20:41 +0200, Dr. Lars Hanke wrote: Am 12.09.2014 19:15, schrieb steve: On Fri, 2014-09-12 at 18:59 +0200, Lars Hanke wrote: I'm currently migrating from a MIT Kerberos + LDAP infrastructure to a samba4 design. I set up test clients, which can connect to either server

tickets with wrong DNS

2014-06-07 Thread steve
Hi We have a Samba4 domain with some Linux clients joined under DHCP. We are updating their DNS records via the nsupdate facility in SSSD. All is fine, but the worrying issue is that the machines still function even with the wrong rr registered in dns. Is this correct behaviour? Thanks, Steve

Re: tickets with wrong DNS

2014-06-07 Thread steve
On Sat, 2014-06-07 at 14:31 +, Brandon Allbery wrote: On Sat, 2014-06-07 at 16:13 +0200, steve wrote: We have a Samba4 domain with some Linux clients joined under DHCP. We are updating their DNS records via the nsupdate facility in SSSD. All is fine, but the worrying issue

Re: NFSv4 and root access

2014-06-03 Thread steve
on the clients with at least Domain = mydomain in idmapd.conf, the files and directories in my mounted exports are all owned by nobody.nogroup. How do you prevent that? Hi Confirmed. rpc.idmapd has to be running at both ends. Maybe there are other ways to do the upcalls? Cheers, Steve

Re: CORRECTED TIME: 13:00 (1pm) Kerberos operators/administrators invited to monthly teleconference

2014-05-01 Thread steve
On Wed, 2014-04-30 at 15:05 -0400, Tom Yu wrote: A previous version of this announcement had inconsistent times listed for this teleconference. OMG. Inconsistent times? On the Kerberos list? Brilliant! Kerberos mailing list

Re: root login via Kerberos5 - User not known to the underlying authentication module - why?

2014-03-30 Thread steve
On Sat, 2014-03-29 at 21:33 +0100, Wendy Lin wrote: On 29 March 2014 16:07, steve st...@steve-ss.com wrote: On Sat, 2014-03-29 at 14:01 +0100, Wendy Lin wrote: login: pam_krb5[3808]: user 'root' was not authenticated by pam_krb5, returning User not known to the underlying authentication

Re: root login via Kerberos5 - User not known to the underlying authentication module - why?

2014-03-29 Thread steve
On Sat, 2014-03-29 at 14:01 +0100, Wendy Lin wrote: login: pam_krb5[3808]: user 'root' was not authenticated by pam_krb5, returning User not known to the underlying authentication module Hi Can root get a ticket? kinit -k root -t /etc/krb5.keytab

Re: Client keytab ignored

2014-03-26 Thread steve
which you are working. HTH Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Client keytab ignored

2014-03-26 Thread steve
? It is not only you who must authenticate, but also the machine upon which you are working. Hi Steve, you're right, it does *not* use the default keytab but it uses the default machine principal. The extra keytab I am using is a functional account in our Active Directory

Re: Transferring NFSv4 nfs/ keys from KDC to client?

2014-03-20 Thread steve
On Thu, 2014-03-20 at 00:52 +0100, Wendy Lin wrote: On 20 March 2014 00:04, Wendy Lin wendlin1...@gmail.com wrote: On 19 March 2014 23:36, steve st...@steve-ss.com wrote: On Wed, 2014-03-19 at 23:16 +0100, Wendy Lin wrote: On 19 March 2014 14:11, steve st...@steve-ss.com wrote: On Wed

Re: Transferring NFSv4 nfs/ keys from KDC to client?

2014-03-20 Thread steve
. Is there any chance you can upgrade? Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Transferring NFSv4 nfs/ keys from KDC to client?

2014-03-20 Thread steve
On Thu, 2014-03-20 at 13:05 +0100, Wendy Lin wrote: On 20 March 2014 11:03, steve st...@steve-ss.com wrote: On Thu, 2014-03-20 at 00:52 +0100, Wendy Lin wrote: I tried permitted_enctypes = des-cbc-crc des3-cbc-sha1 but this only gives me a new kind of (its mocking me?!) error message

Re: Transferring NFSv4 nfs/ keys from KDC to client?

2014-03-20 Thread steve
On Thu, 2014-03-20 at 09:16 -0400, Simo Sorce wrote: On Thu, 2014-03-20 at 13:05 +0100, Wendy Lin wrote: Doable, but it will take months to migrate. What do not understand is that no one, say Linus or friends, *test* their stuff it it is really interoperable with the rest of the world. It

Re: permitted_enctypes = des-cbc-crc triggers 'kinit: Generic error (see e-text) while getting initial credentials'

2014-03-20 Thread steve
On Thu, 2014-03-20 at 23:01 +0100, Wendy Lin wrote: I have this in my Suse 11.3 /etc/krb.conf for libdefaults: allow_weak_crypto = true # permitted_enctypes = des-cbc-crc arcfour-hmac des3-cbc-sha1 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha1-96 permitted_enctypes =

Re: Transferring NFSv4 nfs/ keys from KDC to client?

2014-03-19 Thread steve
On Wed, 2014-03-19 at 00:09 +0100, Wendy Lin wrote: On 18 March 2014 23:54, steve st...@steve-ss.com wrote: On Tue, 2014-03-18 at 23:20 +0100, Wendy Lin wrote: Asking here to make sure I got the mechanism right: I created the principal nfs/china.mytest@test1.mytest.org on the KDC

Re: Transferring NFSv4 nfs/ keys from KDC to client?

2014-03-19 Thread steve
On Wed, 2014-03-19 at 13:32 +0100, Wendy Lin wrote: On 19 March 2014 09:55, steve st...@steve-ss.com wrote: On Wed, 2014-03-19 at 00:09 +0100, Wendy Lin wrote: On 18 March 2014 23:54, steve st...@steve-ss.com wrote: On Tue, 2014-03-18 at 23:20 +0100, Wendy Lin wrote: Asking here to make

Re: Transferring NFSv4 nfs/ keys from KDC to client?

2014-03-19 Thread steve
On Wed, 2014-03-19 at 23:16 +0100, Wendy Lin wrote: On 19 March 2014 14:11, steve st...@steve-ss.com wrote: On Wed, 2014-03-19 at 13:32 +0100, Wendy Lin wrote: On 19 March 2014 09:55, steve st...@steve-ss.com wrote: On Wed, 2014-03-19 at 00:09 +0100, Wendy Lin wrote: On 18 March 2014 23

Re: Fwd: Kerberos5 ticket auto renewal

2014-03-18 Thread steve
expired? Confused. Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Transferring NFSv4 nfs/ keys from KDC to client?

2014-03-18 Thread steve
the CHINA$ key, so you can mount using that. The nfs server keytab should have both the nfs servivce and machine keys. There are many misunderstandings about kerberized nfs: http://linuxcostablanca.blogspot.com.es/2012/02/nfsv4-myths-and-legends.html HTH Steve

Re: Can't login via krb5 with User not known to the underlying authentication module error

2014-03-16 Thread steve
Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: ASCII dump of data in /etc/krb5.keytab?

2014-03-14 Thread steve
On Fri, 2014-03-14 at 12:22 +0100, ольга крыжановская wrote: Does Kerberos have a way to show me the data in /etc/krb5.keytab in ASCII form? Olga Hi We use: klist -ket /etc/krb5.keytab Do you want the content of keys themselves? HTH Steve

Re: password synchronization with samba3

2014-03-03 Thread steve
upgrade scripts available: samba-tool domain classicupgrade --help HTH/encourages, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: k5start -K and ticket renewals

2014-01-16 Thread steve
have to keep a domain alive. Every day. We are scared to death of Kerberos. -K works an absolute treat. We understand it. Could you please retain it? If you must make a change then could it be an addition? We'd suggest -J. If you already have -J then just choose another letter. Easy. Cheers, Steve

Re: k5start -K and ticket renewals

2014-01-16 Thread steve
On Thu, 2014-01-16 at 09:48 -0800, Russ Allbery wrote: steve st...@steve-ss.com writes: On Wed, 2014-01-15 at 18:51 -0800, Russ Allbery wrote: It's also sort of weird and complex, and people struggle to understand it. I'm therefore considering changing the next release to always acquire

Re: kinit error with systemd

2013-10-07 Thread steve
On Sun, 2013-10-06 at 12:37 -0400, Greg Hudson wrote: On 10/06/2013 06:18 AM, steve wrote: Thanks. It works fine. Just a pity that something like this had to change. It worked fine when the cache was create in /tmp. The upstream default is still /tmp/krb5cc_%{uid}. In 1.11 we added

Re: kinit error with systemd

2013-10-06 Thread steve
On Sat, 2013-10-05 at 13:10 -0400, Daniel Kahn Gillmor wrote: On 10/05/2013 12:59 PM, steve wrote: When trying to get Kerberos tickets, we get an error that the directory does not exist e.g. as root: kinit Administrator kinit: Credential cache directory /run/user/0/krb5cc does

kinit error with systemd

2013-10-05 Thread steve
in? Thanks, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: NFSv4

2013-10-02 Thread steve
to be there. Only the server must have the nfs/ service key. HTH, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: NFSv4

2013-09-30 Thread steve
/REALM principal in the default keytab is the nfs server: http://linuxcostablanca.blogspot.com.es/2012/02/nfsv4-myths-and-legends.html For Nfs4 clients, the host/REALM or client machine key are all that is required. HTH Steve Kerberos mailing list

Re: create root cache on boot

2013-05-02 Thread steve
On 02/05/13 06:45, Benjamin Kaduk wrote: On Wed, 1 May 2013, steve wrote: openSUSE 12.3 with Samba 4.0 KDC Hi Our Linux clients need a root cache available for cifs mounts. I have a machine key available on all clients. I've put: kinit -k -t /etc/krb5.keytab MACHINE$ in /etc/init.d

create root cache on boot

2013-05-01 Thread steve
and then refresh it via cron.hourly) Cheers, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Mit kerberos client with windows AD

2013-04-19 Thread steve
On 04/19/2013 11:34 AM, Rasanth Akali Kandoth wrote: Hi All, is it required that, for a linux client application to get tickets from windows AD, the linux box have to join the windows domain ? Hi No. You can kinit from a Linux client just fine.

Re: kerberos: how to create krb5cc cache [SOLVED]

2013-04-12 Thread steve
On 04/12/2013 10:00 PM, Russ Allbery wrote: steve st...@steve-ss.com writes: Thanks. pam_krb5 works fine. on openSUSE 12.3 the cache is created automatically upon login. On Ubuntu it isn't. We have to cater for both distros at the moment. Any Ubuntu krb5 users? Yes, lots. Sounds like you

Re: Kerberos contexts - definition?

2012-08-27 Thread steve
/anyname@REALM nfs/anyname@REALM host/anyname@REALM HTH Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Kerberos contexts - definition?

2012-08-27 Thread steve
On 27/08/12 20:59, Derek Warren wrote: Thank you for the insightful responses, Russ, Nico and Steve. On 2012-08-27, at 10:59 AM, st...@steve-ss.com wrote: For us, nfs4 with a Samba4 AD, gssd fails when it can't find e.g. a machine key in (by default) /etc/krb5.keytab Thank you, Steve. My

Re: Not strictly limited to Kerberos - long login delays when system is offline

2012-08-22 Thread steve
On 22/08/12 19:04, Darek M wrote: On Mon, Aug 20, 2012 at 12:09 PM, steve st...@steve-ss.com wrote: Hi I don't know whether caching is the clue here but we ditched nss-ldap in favour of nss-pam-ldapd. It's faster all around and has a good caching system, nslcd. The switchover from one

Re: Not strictly limited to Kerberos - long login delays when system is offline

2012-08-20 Thread steve
here but we ditched nss-ldap in favour of nss-pam-ldapd. It's faster all around and has a good caching system, nslcd. The switchover from one to the other is really easy and may be worth a try. Cheers, Steve Kerberos mailing list

Kerberized NFS root user access

2012-08-15 Thread steve
denied when the share is mounted krb5, even with the no_root_squash Cheers, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Kerberized NFS root user access

2012-08-15 Thread steve
On 15/08/12 17:27, Alexander Luedtke wrote: Hi Steve, no, thats becouse u need a ticket to get into the user directory. even if u make an su - username as root, u wont get into his homedirectory without the right user ticket - that what it is designded for, to protect the userdirectories

Re: longer ticket life vs auto renew

2012-08-14 Thread steve
is deleted or disabled. But if the client needs to do a renew request from time to time, the KDC might not issue new tickets if the client is deleted or disabled. Hi For long logons we use k5start. It renews tickets at given time intervals. Cheers, Steve

how to automount a cifs share from Samba4

2012-06-14 Thread steve
key. It's OK, but maybe you guys could point out any security risks and/or suggest a better method. Cheers, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Howto find if a user has tickets

2012-04-23 Thread steve
an old cache not destroyed. Is there and easy way to do this? Cheers, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Lion problems

2012-03-18 Thread steve
ads add cifs -U. . . On Linux, net is in the samba-client package. Cheers, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: a question on Kerberos TGS name

2012-02-16 Thread steve
-sha1, arcfour-hmac-md5, using arcfour-hmac-md5/arcfour-hmac-md5 Kerberos: Requested flags: renewable-ok HTH, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: can't unlock xscreensaver

2012-02-05 Thread steve
On 04/02/12 16:43, Mantas M. wrote: On Fri, Feb 03, 2012 at 04:40:16PM +0100, steve wrote: OK I've now seen that the xscreensaver shipped with openSUSE 12.1 does not support Krb5. Fine. This shouldn't make any difference if PAM is being used -- xscreensaver just calls pam_krb5 in that case

Re: can't unlock xscreensaver

2012-02-03 Thread steve
On 02/01/2012 06:46 PM, steve wrote: This is my first post here so hi everyone. We have a Lan of Linux and win 7 boxes under a Samba 4 pdc. On Linux, our Kerberos password does not unlock xscreensaver. We get 'Authentication failed'. openSUSE 12.1. a few files: /etc/krb5.conf

can't unlock xscreensaver

2012-02-01 Thread steve
? Thanks, Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Project Details

2010-09-07 Thread Steve Glasser
Maybe you should try reading the extensive documentation first. On Sep 7, 2010 9:54 AM, rajeev mundarinti rajeevmundari...@gmail.com wrote: Hello sir, My name is Rajeev presuing M.Tech in NMAMIT ,NITTE, KARNATAKA, INDIA. I am doing my 1 year project in network security by using KERBEROS

kpropd brain dead?

2010-03-04 Thread Steve Glasser
. Has anyone seen this behavior before? Thanks, -- Steve Glasser sgla9...@gmail.com Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: find inactive accounts

2010-01-21 Thread Steve Glasser
technique. Thanks, -- Steve Glasser sgla9...@gmail.com Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

find inactive accounts

2010-01-19 Thread Steve Glasser
, so to do date math for dates going back into last year is awkward at best. So... a) can I configure Kerberos to log month day year? b) is there a better way to do this audit? Thanks, -- Steve Glasser sgla9...@gmail.com Kerberos mailing list

unknown error occuring while using mit kerberos implementation

2009-12-14 Thread Steve
provide some clues to where I can research. I reviewed the environment and it looks like all the krb5.ini environment variables are the same. Thanks for the help in advance. Steve Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu

account lockout after n failed password attempts

2009-12-12 Thread Steve Glasser
attempts? Thanks, -- Steve Glasser sgla9...@gmail.com Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Problem using Kerberos for user authentication -- ChallengeResponseAuthentication

2009-11-12 Thread Steve Glasser
it having ever been fixed in redhat http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=339734 Setting PasswordAuthentication yes does work, at least in our environment. If anyone has any further information on this we'd appreciate it. Cheers, Steve On Wed, Nov 11, 2009 at 11:28 PM, Jeffrey Watts

Re: Problem using Kerberos for user authentication

2009-11-11 Thread Steve Glasser
the client and server for clues. Please post any errors. If you are following the sited howto, I assume you did test Kerberos authentication separately and it is working, right? Cheers, Steve On Wed, Nov 11, 2009 at 7:33 AM, Ryan Lynch ryan.b.ly...@gmail.com wrote: On Wed, Nov 11, 2009 at 04:46, Braden

Re: moving kerberos master to new server

2009-10-23 Thread Steve Devine
and you should be ok. I usually don't start kadmin right away so no one can reset their passwords until I am sure that I am going to leave it up. Actual down time is usually 30 minutes or less. /sd Steve Devine Email Storage Academic Technology Services Michigan State University 313 Computer

Re: nfs/kerberos problems

2009-08-18 Thread Steve Glasser
. Cheers -- Steve Glasser sgla9...@gmail.com Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

kdc listening on too many interfaces

2009-06-07 Thread Steve Devine
interface. Is this so or no? Lots of Googling have so far revealed nothing. /sd Steve Devine Email Storage Academic Technology Services Michigan State University Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo

Re: kdc listening on too many interfaces

2009-06-07 Thread Steve Devine
Quoting Ken Raeburn raeb...@mit.edu: On Jun 7, 2009, at 07:48, Steve Devine wrote: Everything works fine and in theory I see no harm but still it seems wrong. It seems like I ought to be able to disable listening on the backnet interface. Is this so or no? At present there is no way

Re: SA-2009-001 and SA-2009-002

2009-04-14 Thread Steve Devine
On Apr 13, 2:57 pm, Tom Yu t...@mit.edu wrote: Steve Devine devine.st...@gmail.com writes: Seems both of these patches expect the src tree to start with a or b IE: diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/ spnego/spnego_mech.c What am I missing

SA-2009-001 and SA-2009-002

2009-04-13 Thread Steve Devine
Seems both of these patches expect the src tree to start with a or b IE: diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/ spnego/spnego_mech.c What am I missing? Is this for a diff dist? /sd Kerberos mailing list

gss_krb5_ccache_name

2008-11-21 Thread Steve
I have memory leak in the function call gss_krb5_ccache_name. I am using kfw-3-2-2-final on win32. It is a multi-threaded application and I am using the api as followed. major_status =gss_krb5_ccache_name(minor_status,krb5- ccache_name, NULL); : major_status =

Re: Kerberos Digest, Vol 60, Issue 9

2007-12-10 Thread Steve Devine
On Dec 10, 10:11 am, Jeff Blaine [EMAIL PROTECTED] wrote: ... Key: vno 5, DES cbc mode with CRC-32, AFS version 3 ... ^ Have you tried using other salt types? -Marcus Watts I'm afraid I don't have

Re: password incorrect but it's not, works fine with Solaris + MIT?

2007-12-08 Thread Steve Devine
On Dec 7, 3:59 pm, Jeff Blaine [EMAIL PROTECTED] wrote: What am I doing wrong this time? -bash-2.05b# /usr/kerberos/bin/kinit [EMAIL PROTECTED] Password for [EMAIL PROTECTED]: kinit(v5): Password incorrect while getting initial credentials -bash-2.05b# -bash-2.05b# rpm -qa |

Re: kprop: Software caused connection abort while reading response from server

2007-11-28 Thread Steve Devine
On Nov 27, 5:25 am, Juri Dakua [EMAIL PROTECTED] wrote: Hello all, I am trying to configure a master KDC and a slave KDC. I am facing the following problem while trying to do so. It will be of great help if someone can kindly suggest me some solution. When I try to propagate the database

Adding supported enctypes to kdc

2007-11-16 Thread Steve Devine
don't intend to remove any enctypes just add them. Should I add anything else while I am at it? We are striving towards Microsoft Compatibility. Thanks Steve Devine MSU Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman

Kerberos for authentication, php for authorization

2007-06-07 Thread Steve Webb
Hello, I have been requested to build a web app for my medium sized organization that currently have Kerberos 5 running on the network. The webapp will require non-technical users to be able to log on remotely through a web browser (IE only is fine but there must not be any other client programs

Re: question about a kerberos play

2006-07-31 Thread Steve Feehan
/Kerberos/dialogue.html -- Steve Feehan Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

kadmin question.

2006-07-07 Thread Steve Devine
We are testing out some new policies. (MIT Kerberos5 1.4.3) We have found that a privileged principal ROOT/[EMAIL PROTECTED] cannot overrule the password history policy on a standard principle but it can/does ignore the password minimum life. Is this a feature or a bug?

HI

2005-10-13 Thread steve zhang
PROTECTED] sbin]# If you know about how to resolve it as to login by using krlogin with Kerberos ,please let me know. Thks. Best regards Steve zhang Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo

RE: Kerberos Digest, Vol 33, Issue 10

2005-09-12 Thread Barfield Steve
Please can you tell what jar file the following class is in com.sun.security.auth.module.Krb5LoginModule -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: 12 September 2005 17:02 To: kerberos@mit.edu Subject: Kerberos Digest, Vol 33, Issue 10 Send Kerberos

Java sample for SSO using JAAS on XP SP2,

2005-07-08 Thread Barfield Steve
Dear Kerberos, I have been asked if my java (jsp/servlets/beans) application could get the current user's id by using Kerberos tickets. If you could give me any advice I would be very grateful. Thanks Steve Kerberos mailing list

Kerberos Database Size

2005-01-20 Thread Steve Edgar
configuration, are there any other limiting factors? -- Steve. Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Is there a Win2k server equivalence to krb5.conf [domain_realm]?

2004-05-27 Thread Steve . Schwager
I'm setting a multi-realm (Windows/Unix) environment. I think I've got it all figured out except for one thing. How does the Windows KDC know that mymachine.unixnet.mycompany.com is in the realm UNIXNET.MYCOMPANY.COM? In the MIT implementation, client would have done this using [domain_realm]

Unable to d/l kerberos-2.5 for windows because i don't have IE 5.01(unavailable)

2004-03-05 Thread steve hauser
on their Win2000 systems. Thanks. Steve Hauser Kerberos mailing list [EMAIL PROTECTED] https://mailman.mit.edu/mailman/listinfo/kerberos

Re: you have tried to steal!

2004-02-25 Thread Steve Langasek
virus snipped And I would've gotten away with it, too, if it wasn't for those meddling kids! -- Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] https://mailman.mit.edu/mailman/listinfo/kerberos

Re: kerberos and freeradius

2003-12-19 Thread Steve Langasek
on it uses NetBSD. -- Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] https://mailman.mit.edu/mailman/listinfo/kerberos

Re: kerberos and freeradius

2003-12-19 Thread Steve Langasek
changes to CVS HEAD that I haven't tested on Heimdal, so I may have ruined that again ;). -- Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Create K5 account from PAM module

2003-10-04 Thread Steve Langasek
header files, so it's something of a bear to build. (There's really no way around this, since those are the only header files that let it connect to the MIT admin server in order to create principals.) ftp://ftp.netexpress.net/pub/pam/pam_krb5_migrate.tgz Cheers, -- Steve Langasek postmodern

Re: Security issue with pam-krb5 ?

2003-08-27 Thread Steve Langasek
passwords stash them in a file. Pure kerberos won't allow that to happen, since hosts never receive the user's password. Right. -- Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] https://mailman.mit.edu

Re: krb5-1.2.8 compile problem

2003-07-30 Thread Steve Langasek
On Tue, Jul 29, 2003 at 12:23:49PM +0200, Jerome Walter wrote: Hi. This is a known problem with the 1.2 version of krb5 that is fixed in the 1.3 release. Too bad for people out of US, that do not have 1.3 available yet. http://http.us.debian.org/debian/pool/main/k/krb5/ -- Steve

Re: krb5-1.2.8 compile problem

2003-07-30 Thread Steve Langasek
On Wed, Jul 30, 2003 at 11:30:57AM -0300, Andreas wrote: On Wed, Jul 30, 2003 at 09:10:56AM -0500, Steve Langasek wrote: On Tue, Jul 29, 2003 at 12:23:49PM +0200, Jerome Walter wrote: Hi. This is a known problem with the 1.2 version of krb5 that is fixed in the 1.3 release

Re: SSH as root with different principal

2003-07-30 Thread Steve Langasek
, you would add that principal to root's .k5login file; acquire a TGT for that user; and run 'ssh [EMAIL PROTECTED]' or 'ssh -l root server'. This will grant you Kerberos-based access to the root account. -- Steve Langasek postmodern programmer

Re: Password expiration

2003-03-07 Thread Steve Langasek
that they already have the tickets they need. :-) A Kerberized ssh client is still a must here, of course. My own deployments have involved ssh with the gssapi patches, plus pam_krb5 for backwards-compatible password auth. -- Steve Langasek postmodern programmer

Re: Error when running kadmin

2003-02-17 Thread Steve Langasek
'dns_lookup_kdc' nor 'dns_lookup_realm' says anything about using DNS to look up the admin server. The last, AFAIK, has not yet been implemented. -- Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] https

Re: [Fwd: Re: krb5 ticket cache]

2003-02-06 Thread Steve Langasek
) :) Just to comment, it sounds like your pop server has buggy PAM support. It's calling the PAM function that's writing out the ccache, but not calling the corresponding function to remove it (I'm assuming Solaris's pam_krb5 *does* implement this) when the session is over. -- Steve Langasek

March Madness

2003-02-03 Thread Steve Hawks
action! If you want to win, you need the right information. Just think about what you can do if you win big! My name is Steve "Black Eye" Hawks and I run one of the premier sports handicapping services in the country. I am personally writing to you because I understand you like to

Re: (MIT) Kerberos V and PHP(4)?

2002-12-28 Thread Steve Langasek
the Kerberos API to the weakly-typed PHP. -- Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] http://mailman.mit.edu/mailman/listinfo/kerberos

Re: w2k kerberos logon

2002-12-13 Thread Steve Langasek
then resolve the KDC addresses using DNS. An alternate approach would be for the client to issue queries exclusively using LDAP, and this is probably more scalable than depending on a WINS server. I believe the legacy NetBIOS domain is listed somewhere in LDAP, but I don't recall where. -- Steve

adding a host/principal behind a firewall

2002-10-30 Thread Steve Blackwell
of the firewall is set by my ISP using DHCP. Is it possible to add this computer to my realm and if so what name do I use? Thanks, Steve. Kerberos mailing list [EMAIL PROTECTED] http://mailman.mit.edu/mailman/listinfo/kerberos

Re: Kerberos authentication in PostgreSQL

2002-10-30 Thread Steve Langasek
-proxy approach to Kerberos like pam_krb5? Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] http://mailman.mit.edu/mailman/listinfo/kerberos

Re: Talking with Kerberized services using GSS-API

2002-10-18 Thread Steve Langasek
support encryption. I'm using SASL-enabled LDAP with GSSAPI authentication, and the data stream is automatically encrypted with certain LDAP clients. Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] http

kprop command

2002-10-14 Thread Steve Hu
When I call the kprop command, do I have to pass in the slave's host name? I've tried passing in the slave's IP but that doesn't work. Thanks for the help in advance. SteveDo you Yahoo!? Faith Hill - Exclusive Performances, Videos, & more faith.yahoo.com

Re: Win logon to a MIT Kerberos V KDC?

2002-09-26 Thread Steve Harper
: modify_principal -requires_preauth host/majorskan.MYDOMAIN.TLD HTH, Steve Harper University of Utah On Thu, 26 Sep 2002, Turbo Fredriksson wrote: 'a local or AD account'. I don't have AD, but I _DO_ have a local account. The keytab on the KDC. I got the error - s n i p - Sep 26 08

Re: Books on kerberos

2002-09-23 Thread Steve Freed
Yes, this is the 60 page POS that the original posting was about. -- Steve. On Mon, 23 Sep 2002, John Rudd wrote: I don't know if this one was mentioned yet, but there's also Kerberos: A Network Authentication System by Brian Tung (addison wesley) It's more of a booklet than a book

Re: Keberos with Mac OS X (10.2)

2002-09-17 Thread Steve Langasek
determines who they are (authentication). Steve Langasek postmodern programmer Kerberos mailing list [EMAIL PROTECTED] http://mailman.mit.edu/mailman/listinfo/kerberos

  1   2   >