[29456] in Kerberos

home help back first fref pref prev next nref lref last post

Re: using UPN to auth

daemon@ATHENA.MIT.EDU (Ben W Young)
Tue Mar 11 22:43:56 2008

Date: Wed, 12 Mar 2008 13:42:11 +1100
From: Ben W Young <ben.w.young@det.nsw.edu.au>
To: <kerberos@mit.edu>
Message-ID: <C3FD8E33.10748%ben.w.young@det.nsw.edu.au>
In-Reply-To: <fr78bf$qvt$1@ger.gmane.org>
Mime-version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Markus,

I believe this is what I need to do and you may have commented on this for
me before in another thread.

How would I go about modifying kinit on os x as you have mentioned below?

Regards,

Ben W Young


> From: Markus Moeller <huaraz@moeller.plus.com>
> Date: Wed, 12 Mar 2008 00:32:41 -0000
> To: "kerberos@mit.edu" <mailto:kerberos@mit.edu>
> Subject: Re: using UPN to auth
> 
> You need a modified kinit which sets the principal type  to 10 (enterprise
> name type). Windows will then use the UPN instead of the samaccountname to
> authenticate. (See attached sample mkinit.c)
> 
> Markus.
> 
> BTW If your client support client canonicalisation you can authenticate as
> jdoe@domain.com but get a ticket for samaccountname.
> 
> "Terry" <td3201@gmail.com> wrote in message
> news:8ee061010803111146g3d5b36b2rd5e22be1d3961073@mail.gmail.com...
>> Hello,
>> 
>> I am very new to this.  I have a FQDN in AD set to domain.foo.  The
>> UPN of a user is jdoe@domain.com.  (note the difference between foo
>> and com).
>> 
>> How can I authenticate with jdoe@domain.com?  I am able to auth
>> correctly with the sAMAccountName.
>> 
>> Thanks!
>> ________________________________________________
>> Kerberos mailing list           Kerberos@mit.edu
>> https://mailman.mit.edu/mailman/listinfo/kerberos
>> 
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos


**********************************************************************
This message is intended for the addressee named and may contain
privileged information or confidential information or both. If you
are not the intended recipient please delete it and notify the sender.
**********************************************************************
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post