[29504] in Kerberos
cross-realm authentication works only with .k5login
daemon@ATHENA.MIT.EDU (Andrea)
Mon Mar 17 10:00:16 2008
From: Andrea <acirulli@gmail.com>
Date: Mon, 17 Mar 2008 06:57:00 -0700 (PDT)
Message-ID: <b66de008-26d7-48b7-9bc1-0f5e4756b71b@z38g2000hsc.googlegroups.com>
Mime-Version: 1.0
X-Complaints-To: groups-abuse@google.com
Complaints-To: groups-abuse@google.com
To: kerberos@mit.edu
Cc: domenico.pace@valueteam.com, andrea.cirulli@valueteam.com,
vincenzo.carnuccio@valueteam.com, stefano.veltri@valueteam.com
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Hi all,
I just setted up a multi realm KDC on a linux machine.
The 2 REALMS are named SOLARIS and SOLARIS2.
I want to put a trust relationship between the two REALMS, so I did
the following on each KDC:
addprinc -pw krbtgt/SOLARIS2 krbtgt/SOLARIS2@SOLARIS
addprinc -pw krbtgt/SOLARIS krbtgt/SOLARIS@SOLARIS2
In order to test cross realm authentication I tryed to single sign on
into a machine based on SOLARIS realm, with a ticket of SOLARIS2. The
SSO doesn't work, however if I run klist after trying SSO, it
yields:
[root@localhost ~]# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: andrea@SOLARIS2
Valid starting Expires Service principal
03/17/08 04:09:13 03/17/08 15:49:13 krbtgt/SOLARIS2@SOLARIS2
renew until 03/17/08 04:09:13
03/17/08 04:09:19 03/17/08 15:49:13 krbtgt/SOLARIS@SOLARIS2
renew until 03/17/08 04:09:13
03/17/08 04:09:19 03/17/08 15:49:13 host/andrea@SOLARIS
renew until 03/17/08 04:09:13
It seems that the cross realm authentication works, but the SSO no.
I can make the system successfully works inserting the .k5login file
into the home directory of the user who is attempting to SSO on the
machine with a ticket of SOLARIS2 REALM.
I want to ask to you:
Am I missing something on the configuration?
Is necessary to set up for each user on the system a .k5login?
Is it possible to avoid using the .k5login?
Thanks in advance!
best regards,
Andrea
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos