[22547] in Kerberos

home help back first fref pref prev next nref lref last post

Re: PAM_KRB5 Issue

daemon@ATHENA.MIT.EDU (Tyson Oswald)
Wed Sep 22 20:01:45 2004

In-Reply-To: <415209FF.1050307@sun.com>
Mime-Version: 1.0 (Apple Message framework v619)
Content-Type: text/plain; charset=US-ASCII; format=flowed
Message-Id: <90C84270-0CF3-11D9-8C84-000A958B2E00@ameritech.net>
Content-Transfer-Encoding: 7bit
From: Tyson Oswald <oswaldt@ameritech.net>
Date: Wed, 22 Sep 2004 20:00:22 -0400
To: Wyllys Ingersoll <wyllys.ingersoll@sun.com>
cc: kerberos@mit.edu
cc: Norbert Klasen <norbert.klasen@avinci.de>
Errors-To: kerberos-bounces@mit.edu

This would make sense from a security stand point.

thanks everyone for their help.

On Sep 22, 2004, at 07:25 PM, Wyllys Ingersoll wrote:

>
>
> Norbert is correct.  In Solaris 9, the default behavior for PAM-KRB5 is
> to require a host key in the keytab file (/etc/krb5/krb5.keytab) in
> order to properly authenticate that the ticket issued came from the
> correct KDC.
>
> -Wyllys
>
>
>
> Norbert Klasen wrote:
>>>
>>> I do not actually.  I never had to do that with Solaris 8, so I was
>>> wondering.  I'm in the process of gettign user IDs created in AD for 
>>> the
>>> system.
>> The Solaris 9 module verifies the tgt. See 
>> <http://docs.sun.com/db/doc/817-3946/6mjgmt4nd?q=pam_krb5&a=view>. 
>> Probably Solaris 8 didn't do this.
>> Norbert
>> ________________________________________________
>> Kerberos mailing list           Kerberos@mit.edu
>> https://mailman.mit.edu/mailman/listinfo/kerberos
>

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post