[30543] in Kerberos
Re: Kerberos auth based on ticket
daemon@ATHENA.MIT.EDU (Simon Wilkinson)
Tue Dec 16 09:25:23 2008
In-Reply-To: <7372D9734C591745A4C1D81017D5ABF6090F6B3C@NJCHLEXCMB01.cable.comcast.com>
Mime-Version: 1.0 (Apple Message framework v753.1)
Message-Id: <B43170A1-B5E3-40FF-9F83-A157A6218D85@sxw.org.uk>
From: Simon Wilkinson <simon@sxw.org.uk>
Date: Tue, 16 Dec 2008 14:20:35 +0000
To: "Rowley, Mathew" <Mathew_Rowley@cable.comcast.com>
Cc: kryanth@gopc.net, kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
On 16 Dec 2008, at 13:37, Rowley, Mathew wrote:
> If you have a kerberos ticket, and ssh to a box that has GSSAPI
> enabled, will that pass through/disregard the PAM stack?
With OpenSSH, it will use the setcred bit of the auth stack, and the
account and session stacks, but disregard the authentication portion
of the auth stack.
S.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos