[22504] in Kerberos

home help back first fref pref prev next nref lref last post

Re: UNIX GSS-API / Windows SSPI :

daemon@ATHENA.MIT.EDU (Jacques Lebastard)
Mon Sep 20 14:38:20 2004

Message-ID: <414F1384.6090309@evidian.com>
Date: Mon, 20 Sep 2004 19:29:40 +0200
From: Jacques Lebastard <Jacques.Lebastard@evidian.com>
MIME-Version: 1.0
To: kerberos@mit.edu
In-Reply-To: <414B3A28.9090300@anl.gov>
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Errors-To: kerberos-bounces@mit.edu

Douglas E. Engert wrote:
>>> If your service is running on Unix, then you must make sure that
>>> you create a keytab containing entries for each of the keys that
>>> Windows can produce for the SPN.  (RC4-HMAC, DES-CBC-MD5, DES-CBC-CRC).
>>> The DES enctypes will only be used if the account associated with
>>> the SPN is marked DES only.
>>
>> How can I check this and, second question, how can I generate a keytab 
>> with RC4-HMAC encryption ? The ktpass tool does not accept the 
>> RC4-HMAC crypto type:
> 
> If you knew the password (or key) added to AD, you could try using ktutil,
> instead of ktpass.
> Use addent ... -e arcfour-hmac-md5
> 
> Ktutil let me create a keytab, I don't know if is correct.

No such 'addent' command for ktutil running on Solaris 9 :-(  :


-- 
Mr. Jacques LEBASTARD            mailto:jacques.lebastard@evidian.com
EVIDIAN S.A.                     www.evidian.com
Rue Jean Jaurès                  Tel: +33 1 30 80 77 86
F-78340 LES CLAYES SOUS BOIS     Fax: +33 1 30 80 77 99
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post