[22391] in Kerberos

home help back first fref pref prev next nref lref last post

Re: BC-SNC, MIT Kerberos V, SSO, GSS-API v2

daemon@ATHENA.MIT.EDU (Calin Barbat)
Tue Sep 7 09:41:41 2004

Message-ID: <413DBAB8.60905@osram.de>
Date: Tue, 07 Sep 2004 15:42:16 +0200
From: Calin Barbat <c.barbat@osram.de>
MIME-Version: 1.0
To: Norbert Klasen <norbert+lists.mit-kerberos@burgundy.dyndns.org>
In-Reply-To: <ADCD53A639590A6B051484A2@[10.110.20.166]>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
cc: cevat.guersoy@avinci.de
Errors-To: kerberos-bounces@mit.edu

Norbert Klasen wrote:

> some hints you might want to try:
> - use MIT Kerberos 1.3.x. It implements the native Windows enctype
> arcfour-hmac-md5 and supports TCP to connect to the KDC. (unlikely)
> - test if you can successfully establish a GSSAPI connection between your
> Windows workstation and your Unix server with gss-client and gss-server
> (Windows versions are included in the KfW package).
>
I tried available Kerberos releases 1.1.1, 1.2.x, 1.3.x and my findings 
are as follows:
    - older versions than 1.2.8 issue a relocation error in the shared 
library.
    - newer versions than 1.2.8 lead to a segmentation fault in the 
gsstest program.
Therefore I used 1.2.8.

I used Kermit 95 in order to do an ftp from a win2k client to the linux 
machine and telnet is also working, but only ftp is making use of the 
GSS-API. I think this is replacing the gss-server, gss-client test.

Calin Barbat.

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post