[29581] in Kerberos
Re: AdressLess Ticket restriction by KDC server side
daemon@ATHENA.MIT.EDU (Andrea Cirulli)
Tue Mar 25 12:20:10 2008
Message-ID: <191a80d00803250915o1c850d5fo688d72260db73704@mail.gmail.com>
Date: Tue, 25 Mar 2008 17:15:39 +0100
From: "Andrea Cirulli" <acirulli@gmail.com>
To: jaltman@secure-endpoints.com
In-Reply-To: <47E9202C.2060400@secure-endpoints.com>
MIME-Version: 1.0
Content-Disposition: inline
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
The problem is properly that I'm in an environment in which there are some
old clients, which doesn't request for addressless tickets and doesn't not
care about the entry noaddresses= true.
This is the reason for which I'm looking for a kdc server side solution.
Howevere,thanks
On Tue, Mar 25, 2008 at 4:54 PM, Jeffrey Altman <
jaltman@secure-endpoints.com> wrote:
> Andrea wrote:
> > Hi all,
> > I'm looking for a way to force the KDC server to release only
> > addressless tickets, that is, even if a client is looking/asking for
> > a ticket with address, the KDC will always give back an addressless
> > ticket.
> >
> > So, is there an entry on the kdc.conf or something else that allow me
> > to obtain what I said above?
> >
> > P.S: The solution on which I have to put just into krb5.conf an entry
> > such as noaddresses=true doesn't accomplish my goal.
> >
> Recent clients only request addressless tickets unless
> 'noaddresses=false' is set
>
>
>
--
Andrea Cirulli
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos