[30894] in Kerberos

home help back first fref pref prev next nref lref last post

Re: SASL authentication

daemon@ATHENA.MIT.EDU (Douglas E. Engert)
Thu Mar 19 21:09:59 2009

Message-ID: <49C2ECAF.4080405@anl.gov>
Date: Thu, 19 Mar 2009 20:09:03 -0500
From: "Douglas E. Engert" <deengert@anl.gov>
MIME-Version: 1.0
To: "Xu, Qiang (FXSGSC)" <Qiang.Xu@fujixerox.com>
In-Reply-To: <D8C9BC7FFCF8154FB7141EB8DB609C1727084681CD@SGPAPHQ-EXSCC01.dc01.fujixerox.net>
Cc: =?ISO-8859-1?Q?Michael_Str=F6der?= <michael@stroeder.com>,
   "kerberos@mit.edu" <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu



Xu, Qiang (FXSGSC) wrote:
>> -----Original Message-----
>> From: kerberos-bounces@mit.edu 
>> [mailto:kerberos-bounces@mit.edu] On Behalf Of Michael Str?der
>> Sent: Wednesday, March 18, 2009 2:34 PM
>> To: kerberos@mit.edu
>> Subject: Re: SASL authentication
>>
>> Did you try command-line option -A when invoking kinit as I 
>> suggested in my previous posting? It seems you probably 
>> should read a bit more about how Kerberos works especially 
>> regarding ticket types. There are tons of docs out there.
> 
> Yes, I have tried the option -A. Originally I was using "kinit -f ...". Now I am using "kinit -f -A ...". As far as I know, the option -A is "do not include addresses". I can't see any gain here. After using -A option, the error msg is still "82 Local error" when doing SASL binding.
> 
>>From Google, I can only get a small number of materials on how to create a service principal under Windows 2003 Server. But they are all somewhat ambiguous, and I still can't figure out how to create a keytab file for LDAP client's use.
> 

Start with:
http://technet.microsoft.com/en-us/library/bb742433.aspx
Then look for ksetup program and 2003.
Also look at Samba for net join and windbind  and also look for msktutil.
Solaris has a script to do this




> Thanks,
> Xu Qiang
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 
> 

-- 

  Douglas E. Engert  <DEEngert@anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post