Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
comp . protocols . kerberos
This is a Usenet group - learn more
Find or start a Google Group about kerberos.
Group info
Language: English
Group categories:
Computers
More group info »
Discussions
View:  Topic list, Topic summary Topics 1 - 10 of 13445  Older »
Description: The Kerberos authentication server.
 

: 8th International Workshop on Critical Information Infrastructures Security (CRITIS 2013) 
  Amsterdam, The Netherlands September 16-18, 2013 [link] Important Dates Extended deadline for submission of papers: June 15, 2013 Notification to authors: June 30, 2013 Camera-ready papers: August 16, 2013
By publicitychaircri...@gmail.com  - May 23 - 1 new of 1 message    

kerberos and selinux 
  I run with SELinux enabled, and krb5kdc and kadmin both want read access to /etc/pki/tls on startup. I'm using ldaps as the protocol for talking to slapd, is this why? This is on Centos 5, which I know is a bit old. My KDC and kadmin work fine without allowing this access, and there's nothing in krb5kdc.log or kadmind.log, just the AVC's in audit.log.... more »
By Chris Hecker  - May 23 - 3 new of 3 messages    

Leverage Kerberos/Wallet for non-interactive SSH and script execution 
  Hi, I'd like to leverage our Kerberos (and Wallet) infrastructure to enable non-interactive SSH/SCP between two servers for a given user. Is this possible? Using MIT Kerberos 1.10 on Ubuntu 12.04 everywhere, currently still with Wallet from prior to 1.0 (but after 0.12). The scenario is this: We have a Jenkins build server (build01) and an... more »
By Andreas Ntaflos  - May 22 - 5 new of 5 messages    

Options for enforcing password policies 
  Hi everyone, What options are available for enforcing password policies for an MIT kerberos realm? The passwords policies would: * passwords must be a minimum length * passwords must contain at least one upper case letter, lowercase letter, number, and a special character. * passwords may not contain certain characters, like unicode or some ACSII characters... more »
By Edgecombe, Jason  - May 22 - 5 new of 5 messages    

Crash while freeing data. 
  Hi,   I am using kerberos 1.11.2 version for development while using the pkinit option for certificate implementation observed a crash. Steps followed:- Set pkinit details using krb5_get_init_creds_opt_set_pa -- set anchor and identity options.  krb5_get_init_creds_pass word - with password as empty since in certificate password will not be supplied and password promter as NULL and other details as mentioned in the documentation.... more »
By sasikumar bodathula  - May 21 - 6 new of 6 messages    

Multiple realms served by single kadmind 
  Hello Is it possible to server several realms from a single kadmind process? With the the krb5kdc process it's as simple as specifying multiple -r REALM flags on the command line? I have a server that needs to support 4 separate realms and the kdc is working fine but whenever users try to change their passwords they get:... more »
By Tom Parker  - May 21 - 2 new of 2 messages    

Help in incorporating PKINIT 
  Hi,   Starting new e-mail since felt that old e-mail was containing too much info (not clear one). I am using the MIT kerberos client API's to develop keberos client for a system. 1. Use custom named conf file for storing the realm, libdefaults etc this file once information is written is set to the  ... more »
By sasikumar bodathula  - May 21 - 2 new of 2 messages    

Kerberos FTP ticket filename 
  Hi all, I am having a problem here with the FTP authentication using Kerberos. What is happening is that when I connect from host_A to host_B using ftp, the acquired ticket (in host_B) is being stored as "/tmp/krb5cc_503_z2fgka". I also had this problem in SSH logins, and it seems to be related to a... more »
By Tiago Elvas  - May 20 - 10 new of 10 messages    

Incorrect delegation state shown on acceptor side by context flags 
  Hi, It seems there is a bug in MIT kerberos gss source code where the delegation state is set in context flags on acceptor side. I am using a keytab on server side to acquire credentials with in memory credential cache : *cred->usage == GSS_C_BOTH* Client has *delegation flag set to false* but has a *forwardable TGT*.... more »
By Vipul Mehta  - May 17 - 7 new of 7 messages    

Need help with PKINIT 
  HI,   Adding more information to the previous e-mail thread. In the conf file following information is stored. pkinit_anchors = FILE:<path>/cacert.pem   pkinit_identity = FILE:<path>/client.pem,& lt;path>/clientkey.pem When this was tested and same was captured in the wireshark it has AS_REQ messages not PA-PK-AS-REQ... more »
By sasikumar bodathula  - May 16 - 2 new of 2 messages    

1 - 10 of 13445   « Newer | Older »

XML