[22234] in Kerberos
Re: [OpenAFS] Using Windows AD generated Kerberos tickets without
daemon@ATHENA.MIT.EDU (Jeffrey Altman)
Wed Aug 18 15:34:38 2004
Message-ID: <41237D79.8040202@mit.edu>
Date: Wed, 18 Aug 2004 12:02:01 -0400
From: Jeffrey Altman <jaltman@mit.edu>
MIME-Version: 1.0
To: "Douglas E. Engert" <deengert@anl.gov>
In-Reply-To: <41237BFD.1050405@anl.gov>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
cc: openafs <openafs-info@openafs.org>
Errors-To: kerberos-bounces@mit.edu
Douglas E. Engert wrote:
> The long awaited change from Microsoft is finally out. The change to
> AD allows
> a bit to be set in the userAccountControl that says that service
> tickets created
> for this service should not include a PAC. This will make them
> substantially
> smaller, and usable with UDP or other places where size is a problem.
>
> This change was originally requested almost a year ago for use with
> OpenAFS.
> Since then OpenAFS in release 1.3.70 has made change to allow for
> larger tickets.
>
> But there may still be situations where this patch may be usefull,
> such as
> with other UDP based protocols, or with older Kerberos versions that
> do not
> support TCP to the KDC.
>
> "An update is available that introduces the NO_AUTH_REQUIRED flag to
> the UserAccountControl property in Windows 2000"
> http://support.microsoft.com/?kbid=832572
Or with 1.2.8 AFS Servers that can't handle large tickets in tokens.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos