[22545] in Kerberos
Re: PAM_KRB5 Issue
daemon@ATHENA.MIT.EDU (Wyllys Ingersoll)
Wed Sep 22 19:27:14 2004
Message-ID: <415209FF.1050307@sun.com>
Date: Wed, 22 Sep 2004 19:25:51 -0400
From: Wyllys Ingersoll <wyllys.ingersoll@sun.com>
MIME-Version: 1.0
To: Norbert Klasen <norbert.klasen@avinci.de>
In-Reply-To: <CB00340D012DB8540D638F3B@[10.110.20.166]>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
cc: Tyson Oswald <oswaldt@ameritech.net>
Errors-To: kerberos-bounces@mit.edu
Norbert is correct. In Solaris 9, the default behavior for PAM-KRB5 is
to require a host key in the keytab file (/etc/krb5/krb5.keytab) in
order to properly authenticate that the ticket issued came from the
correct KDC.
-Wyllys
Norbert Klasen wrote:
>>
>> I do not actually. I never had to do that with Solaris 8, so I was
>> wondering. I'm in the process of gettign user IDs created in AD for the
>> system.
>
>
> The Solaris 9 module verifies the tgt. See
> <http://docs.sun.com/db/doc/817-3946/6mjgmt4nd?q=pam_krb5&a=view>.
> Probably Solaris 8 didn't do this.
>
> Norbert
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos