[29475] in Kerberos

home help back first fref pref prev next nref lref last post

Re: using UPN to auth

daemon@ATHENA.MIT.EDU (Terry)
Wed Mar 12 12:28:24 2008

Message-ID: <8ee061010803120927p1959eb17g6a5ffbe20475ce41@mail.gmail.com>
Date: Wed, 12 Mar 2008 11:27:45 -0500
From: Terry <td3201@gmail.com>
To: "Markus Moeller" <huaraz@moeller.plus.com>
In-Reply-To: <fr78bf$qvt$1@ger.gmane.org>
MIME-Version: 1.0
Content-Disposition: inline
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Also, your attachment was stripped.

On Tue, Mar 11, 2008 at 7:32 PM, Markus Moeller <huaraz@moeller.plus.com> wrote:
> You need a modified kinit which sets the principal type  to 10 (enterprise
>  name type). Windows will then use the UPN instead of the samaccountname to
>  authenticate. (See attached sample mkinit.c)
>
>  Markus.
>
>  BTW If your client support client canonicalisation you can authenticate as
>  jdoe@domain.com but get a ticket for samaccountname.
>
>  "Terry" <td3201@gmail.com> wrote in message
>  news:8ee061010803111146g3d5b36b2rd5e22be1d3961073@mail.gmail.com...
>
>
> > Hello,
>  >
>  > I am very new to this.  I have a FQDN in AD set to domain.foo.  The
>  > UPN of a user is jdoe@domain.com.  (note the difference between foo
>  > and com).
>  >
>  > How can I authenticate with jdoe@domain.com?  I am able to auth
>  > correctly with the sAMAccountName.
>  >
>  > Thanks!
>  > ________________________________________________
>  > Kerberos mailing list           Kerberos@mit.edu
>  > https://mailman.mit.edu/mailman/listinfo/kerberos
>  >
>
> ________________________________________________
>  Kerberos mailing list           Kerberos@mit.edu
>  https://mailman.mit.edu/mailman/listinfo/kerberos
>
>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post