[29456] in Kerberos
Re: using UPN to auth
daemon@ATHENA.MIT.EDU (Ben W Young)
Tue Mar 11 22:43:56 2008
Date: Wed, 12 Mar 2008 13:42:11 +1100
From: Ben W Young <ben.w.young@det.nsw.edu.au>
To: <kerberos@mit.edu>
Message-ID: <C3FD8E33.10748%ben.w.young@det.nsw.edu.au>
In-Reply-To: <fr78bf$qvt$1@ger.gmane.org>
Mime-version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Markus,
I believe this is what I need to do and you may have commented on this for
me before in another thread.
How would I go about modifying kinit on os x as you have mentioned below?
Regards,
Ben W Young
> From: Markus Moeller <huaraz@moeller.plus.com>
> Date: Wed, 12 Mar 2008 00:32:41 -0000
> To: "kerberos@mit.edu" <mailto:kerberos@mit.edu>
> Subject: Re: using UPN to auth
>
> You need a modified kinit which sets the principal type to 10 (enterprise
> name type). Windows will then use the UPN instead of the samaccountname to
> authenticate. (See attached sample mkinit.c)
>
> Markus.
>
> BTW If your client support client canonicalisation you can authenticate as
> jdoe@domain.com but get a ticket for samaccountname.
>
> "Terry" <td3201@gmail.com> wrote in message
> news:8ee061010803111146g3d5b36b2rd5e22be1d3961073@mail.gmail.com...
>> Hello,
>>
>> I am very new to this. I have a FQDN in AD set to domain.foo. The
>> UPN of a user is jdoe@domain.com. (note the difference between foo
>> and com).
>>
>> How can I authenticate with jdoe@domain.com? I am able to auth
>> correctly with the sAMAccountName.
>>
>> Thanks!
>> ________________________________________________
>> Kerberos mailing list Kerberos@mit.edu
>> https://mailman.mit.edu/mailman/listinfo/kerberos
>>
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
**********************************************************************
This message is intended for the addressee named and may contain
privileged information or confidential information or both. If you
are not the intended recipient please delete it and notify the sender.
**********************************************************************
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos