[22575] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Two basic (and probably stupid) Kerb5 questions

daemon@ATHENA.MIT.EDU (Kevin Coffman)
Mon Sep 27 09:44:07 2004

To: Konstantinos Agouros <elwood@agouros.de>
In-Reply-To: Message from Konstantinos Agouros <elwood@agouros.de> 
   of "Sun, 26 Sep 2004 18:55:35 GMT." <1096224935.298627@rumba.localnet> 
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Date: Mon, 27 Sep 2004 09:39:17 -0400
From: Kevin Coffman <kwc@citi.umich.edu>
Message-Id: <20040927133917.6654E1BB02@citi.umich.edu>
cc: kerberos@mit.edu
cc: Kevin Coffman <kwc@citi.umich.edu>
Errors-To: kerberos-bounces@mit.edu

> Hi,
> 
> I am just in the process of getting started with Kerberos (mainly
> for securing NFS) on Solaris.
> 
> First question: I know I have to set up principals for each user
> (and host/service etc). What if I already have a established userbase.
> Is there an easy way get principals for every user? Or do I really
> have to do this by hand?

I think the answer is that you need to create principals "by hand"
unless you are migrating from some other Kerberos environment.
 
> Second question (more NFS related): Am I right that in order to
> access NFS mounted directories (or is it the mount-operation?) I
> need to have a ticket?  The background is, that the NFS in question
> is used for an application that uses NFS to share data. Since the
> applications start autmatically on boot there is klogin happening
> so they might probably be denied access. Is there a good way to
> solve this besides someone sitting at the reboot (and whenever the
> login expires) and entering the password to get new tickets?

The answer here is to have a keytab on the client machine with an
entry the application can use to authenticate itself.


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post