[22402] in Kerberos

home help back first fref pref prev next nref lref last post

Re: BC-SNC, MIT Kerberos V, SSO, GSS-API v2

daemon@ATHENA.MIT.EDU (Calin Barbat)
Wed Sep 8 05:04:13 2004

Message-ID: <413EC492.5000707@osram.de>
Date: Wed, 08 Sep 2004 10:36:34 +0200
From: Calin Barbat <c.barbat@osram.de>
MIME-Version: 1.0
To: Norbert Klasen <norbert+lists.mit-kerberos@burgundy.dyndns.org>
In-Reply-To: <ADCD53A639590A6B051484A2@[10.110.20.166]>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
cc: cevat.guersoy@avinci.de
Errors-To: kerberos-bounces@mit.edu

Hello,

Norbert, you were right. I just tried to play around (locally) with the 
sserver/sclient from krb5-1.3.4/src/appl/sample and I got the following 
messages:

    In /var/log/messages something like:
        sserver: recvauth failed--Software caused connection abort

    And from sclient:
        connected
        ./sclient: Ticket expired while using sendauth

I used following commands:

    ./sserver -p 8888 -s host/<myhost>.<mydomain2>.<mydomain1>.de -S 
/etc/krb5.keytab

and

    ./sclient <myhost>.<mydomain2>.<mydomain1>.de 8888 
host/<myhost>.<mydomain2>.<mydomain1>.de

Any idea about the cause of this behaviour?

Calin.

Norbert Klasen wrote:

> some hints you might want to try:
> - use MIT Kerberos 1.3.x. It implements the native Windows enctype
> arcfour-hmac-md5 and supports TCP to connect to the KDC. (unlikely)
> - test if you can successfully establish a GSSAPI connection between your
> Windows workstation and your Unix server with gss-client and gss-server
> (Windows versions are included in the KfW package).
>
> Norbert
>


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post