[22504] in Kerberos
Re: UNIX GSS-API / Windows SSPI :
daemon@ATHENA.MIT.EDU (Jacques Lebastard)
Mon Sep 20 14:38:20 2004
Message-ID: <414F1384.6090309@evidian.com>
Date: Mon, 20 Sep 2004 19:29:40 +0200
From: Jacques Lebastard <Jacques.Lebastard@evidian.com>
MIME-Version: 1.0
To: kerberos@mit.edu
In-Reply-To: <414B3A28.9090300@anl.gov>
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Errors-To: kerberos-bounces@mit.edu
Douglas E. Engert wrote:
>>> If your service is running on Unix, then you must make sure that
>>> you create a keytab containing entries for each of the keys that
>>> Windows can produce for the SPN. (RC4-HMAC, DES-CBC-MD5, DES-CBC-CRC).
>>> The DES enctypes will only be used if the account associated with
>>> the SPN is marked DES only.
>>
>> How can I check this and, second question, how can I generate a keytab
>> with RC4-HMAC encryption ? The ktpass tool does not accept the
>> RC4-HMAC crypto type:
>
> If you knew the password (or key) added to AD, you could try using ktutil,
> instead of ktpass.
> Use addent ... -e arcfour-hmac-md5
>
> Ktutil let me create a keytab, I don't know if is correct.
No such 'addent' command for ktutil running on Solaris 9 :-( :
--
Mr. Jacques LEBASTARD mailto:jacques.lebastard@evidian.com
EVIDIAN S.A. www.evidian.com
Rue Jean Jaurès Tel: +33 1 30 80 77 86
F-78340 LES CLAYES SOUS BOIS Fax: +33 1 30 80 77 99
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos