[29403] in Kerberos

home help back first fref pref prev next nref lref last post

Re: kinit pkinit question.

daemon@ATHENA.MIT.EDU (Kevin Coffman)
Sat Mar 1 13:24:09 2008

Message-ID: <4d569c330803011020n5b39175exddfde592752db6c3@mail.gmail.com>
Date: Sat, 1 Mar 2008 13:20:48 -0500
From: "Kevin Coffman" <kwc@citi.umich.edu>
To: "Matthew Andrews" <matt@slackers.net>
In-Reply-To: <47C8FBB6.4030306@slackers.net>
MIME-Version: 1.0
Content-Disposition: inline
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On Sat, Mar 1, 2008 at 1:46 AM, Matthew Andrews <matt@slackers.net> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
>  Hash: SHA1
>
> | Matt,
>  | The obvious question is whether your KDC is properly configured for
>  | pkinit?  Also, is the client configured to require preauthentication?
>  | If so, the KDC should offer the pkinit preauth method to the client in
>  | a preauth-required message.  Unlike the Heimdal client, the MIT client
>  | will not send padata automatically just because you specified
>  | pkinit_identity and pkinit_anchors.
>  |
>  | K.C.
>  |
>  |
>
>  well, I have the following in the kdc.conf in the realms stanza entry
>  for the realm in question:
>
>
>
>  again I'm still not sure what I'm missing. I'm sure that in the end
>  it'll be something that I go "oh, DUH!" about but for now I don't see
>  it. Thanks for the help.

I haven't looked closely at the KDC cert, but you didn't mention
whether the client principal's DB entry has the requires_preauth flag
set.  Does the KDC not offer pkinit as a valid patype?

K.C.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post