[22193] in Kerberos

home help back first fref pref prev next nref lref last post

Can't get ssh over k5/afs working well

daemon@ATHENA.MIT.EDU (Sensei)
Mon Aug 16 12:27:33 2004

From: Sensei <noone@nowhere.org>
Date: Fri, 13 Aug 2004 15:18:27 +0200
Message-ID: <2o3td3F64groU1@uni-berlin.de>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Hi.

I have a mixed linux lab. A server based on debian (ssh 3.4p1) and 
clients based on gentoo (ssh version 3.8p1). My infrastructure is based 
on mit kerberos 5 and openafs. All I'd like to do is to make ssh 
sessions passwordless, based on the tickets. On both systems I use pam 
authentication via libpam-krb5 and gain the token via 
libpam-openafs-session && aklog (the debian packages). The pam_krb5.so 
module has flags ``use_first_pass forwardable''.

Now, how do I enable passwordless ssh GAINING the correct tickets and 
tokens? Those are my settings:

=== ssh 3.8p1 sshd_config excerpt:

KerberosAuthentication yes
KerberosTicketCleanup yes
GSSAPIAuthentication yes
GSSAPICleanupCredentials yes

=== ssh 3.8p1 ssh_config excerpt:

GSSAPIAuthentication yes
GSSAPIDelegateCredentials yes

=== ssh 3.4p1 sshd_config excerpt:

KerberosAuthentication yes
KerberosTicketCleanup yes
KerberosTgtPassing yes
GSSAPIAuthentication yes
GSSAPIKeyExchange yes
GSSAPIUseSessionCredCache yes

=== ssh 3.4p1 ssh_config excerpt:

KerberosAuthentication yes
KerberosTGTPassing yes
GSSAPIAuthentication yes
GSSAPIDelegateCredentials yes
-- 
Sensei    <mailto:senseiwa@tin.it>
           <icqnum:241572242>
           <msn-id:Sensei_Sen@hotmail.com>
Error: Keyboard not found. Press F1 to continue...
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post