[30842] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Authenticating using lower case domain/realm

daemon@ATHENA.MIT.EDU (Luke Howard)
Mon Mar 9 17:52:52 2009

Message-Id: <DBA6F037-B434-400E-B877-63660E6E4743@padl.com>
From: Luke Howard <lukeh@padl.com>
To: Santos <sansancasd@gmail.com>
In-Reply-To: <d2912e600903090917t71df6e6dl9f637a42555fbda@mail.gmail.com>
Mime-Version: 1.0 (Apple Message framework v930.3)
Date: Tue, 10 Mar 2009 08:51:54 +1100
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu


On 10/03/2009, at 3:17 AM, Santos wrote:

>> On Mon, Mar 9, 2009 at 1:35 PM, Luke Howard <lukeh@padl.com> wrote:
>>
>>> MIT Kerberos 1.7 adds the -C (canonicalize) and -E (enterprise
>>> principal name) options to kinit, which may help.
>>
>>
>
> Actualy my main priority is to use pam_krb5.
>
> If i compile MIT kerberos 1.7 on ubuntu 8.10. Will pam_krb5 be able  
> to use
> those flags? Does the krb5.conf file have any settings to enable those
> settings as default?

It doesn't but you should be able to easily modify pam_krb5 to call  
krb5_get_init_creds_opt_set_canonicalize(), and to call  
krb5_parse_name_flags(KRB5_PRINCIPAL_PARSE_ENTERPRISE) rather than  
krb5_parse_name(). Of course, this should be made configurable.

-- Luke
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post