[22575] in Kerberos
Re: Two basic (and probably stupid) Kerb5 questions
daemon@ATHENA.MIT.EDU (Kevin Coffman)
Mon Sep 27 09:44:07 2004
To: Konstantinos Agouros <elwood@agouros.de>
In-Reply-To: Message from Konstantinos Agouros <elwood@agouros.de>
of "Sun, 26 Sep 2004 18:55:35 GMT." <1096224935.298627@rumba.localnet>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Date: Mon, 27 Sep 2004 09:39:17 -0400
From: Kevin Coffman <kwc@citi.umich.edu>
Message-Id: <20040927133917.6654E1BB02@citi.umich.edu>
cc: kerberos@mit.edu
cc: Kevin Coffman <kwc@citi.umich.edu>
Errors-To: kerberos-bounces@mit.edu
> Hi,
>
> I am just in the process of getting started with Kerberos (mainly
> for securing NFS) on Solaris.
>
> First question: I know I have to set up principals for each user
> (and host/service etc). What if I already have a established userbase.
> Is there an easy way get principals for every user? Or do I really
> have to do this by hand?
I think the answer is that you need to create principals "by hand"
unless you are migrating from some other Kerberos environment.
> Second question (more NFS related): Am I right that in order to
> access NFS mounted directories (or is it the mount-operation?) I
> need to have a ticket? The background is, that the NFS in question
> is used for an application that uses NFS to share data. Since the
> applications start autmatically on boot there is klogin happening
> so they might probably be denied access. Is there a good way to
> solve this besides someone sitting at the reboot (and whenever the
> login expires) and entering the password to get new tickets?
The answer here is to have a keytab on the client machine with an
entry the application can use to authenticate itself.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos