[29475] in Kerberos
Re: using UPN to auth
daemon@ATHENA.MIT.EDU (Terry)
Wed Mar 12 12:28:24 2008
Message-ID: <8ee061010803120927p1959eb17g6a5ffbe20475ce41@mail.gmail.com>
Date: Wed, 12 Mar 2008 11:27:45 -0500
From: Terry <td3201@gmail.com>
To: "Markus Moeller" <huaraz@moeller.plus.com>
In-Reply-To: <fr78bf$qvt$1@ger.gmane.org>
MIME-Version: 1.0
Content-Disposition: inline
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Also, your attachment was stripped.
On Tue, Mar 11, 2008 at 7:32 PM, Markus Moeller <huaraz@moeller.plus.com> wrote:
> You need a modified kinit which sets the principal type to 10 (enterprise
> name type). Windows will then use the UPN instead of the samaccountname to
> authenticate. (See attached sample mkinit.c)
>
> Markus.
>
> BTW If your client support client canonicalisation you can authenticate as
> jdoe@domain.com but get a ticket for samaccountname.
>
> "Terry" <td3201@gmail.com> wrote in message
> news:8ee061010803111146g3d5b36b2rd5e22be1d3961073@mail.gmail.com...
>
>
> > Hello,
> >
> > I am very new to this. I have a FQDN in AD set to domain.foo. The
> > UPN of a user is jdoe@domain.com. (note the difference between foo
> > and com).
> >
> > How can I authenticate with jdoe@domain.com? I am able to auth
> > correctly with the sAMAccountName.
> >
> > Thanks!
> > ________________________________________________
> > Kerberos mailing list Kerberos@mit.edu
> > https://mailman.mit.edu/mailman/listinfo/kerberos
> >
>
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
>
>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos