[22234] in Kerberos

home help back first fref pref prev next nref lref last post

Re: [OpenAFS] Using Windows AD generated Kerberos tickets without

daemon@ATHENA.MIT.EDU (Jeffrey Altman)
Wed Aug 18 15:34:38 2004

Message-ID: <41237D79.8040202@mit.edu>
Date: Wed, 18 Aug 2004 12:02:01 -0400
From: Jeffrey Altman <jaltman@mit.edu>
MIME-Version: 1.0
To: "Douglas E. Engert" <deengert@anl.gov>
In-Reply-To: <41237BFD.1050405@anl.gov>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
cc: openafs <openafs-info@openafs.org>
Errors-To: kerberos-bounces@mit.edu

Douglas E. Engert wrote:

> The long awaited change from Microsoft is finally out. The change to 
> AD allows
> a bit to be set in the userAccountControl that says that service 
> tickets created
> for this service should not include a PAC. This will make them 
> substantially
> smaller, and usable with UDP or other places where size is a problem.
>
> This change was originally requested almost a year ago for use with 
> OpenAFS.
> Since then OpenAFS in release 1.3.70 has made change to allow for 
> larger tickets.
>
> But there may still be situations where this patch may be usefull, 
> such as
> with other UDP based protocols, or with older Kerberos versions that 
> do not
> support TCP to the KDC.
>
>   "An update is available that introduces the NO_AUTH_REQUIRED flag to
>    the UserAccountControl property in Windows 2000"
>    http://support.microsoft.com/?kbid=832572

Or with 1.2.8 AFS Servers that can't handle large tickets in tokens.


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post