[22532] in Kerberos

home help back first fref pref prev next nref lref last post

Re: ssh-krb5 problems

daemon@ATHENA.MIT.EDU (Douglas E. Engert)
Wed Sep 22 10:11:40 2004

Message-ID: <41518708.9050900@anl.gov>
Date: Wed, 22 Sep 2004 09:07:04 -0500
From: "Douglas E. Engert" <deengert@anl.gov>
MIME-Version: 1.0
To: Ken Raeburn <raeburn@mit.edu>
In-Reply-To: <C8B781C8-0C24-11D9-AA8B-000A95909EE2@mit.edu>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
cc: "'kerberos@mit.edu'" <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu



Ken Raeburn wrote:

> On Sep 21, 2004, at 17:29, rachel elizabeth dillon wrote:
> 
>> 1. Are you trying to ssh as a user that exists on the other machine?
>> If the user does not exist in the other machine's /etc/passwd, then
>> I don't believe the KDC will ever be queried.
> 
> 
> That sounds like an undesirable leak of information from the server, if 
> that's true.
> 

Yes, looks like OpenSSH-3.9 in auth_gssapi.c in user_auth_gssapi test
if(!authctxt->valid ||...
and  returns if not a valid local ID.


> Ken
> 
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 
> 
> 

-- 

  Douglas E. Engert  <DEEngert@anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post