[22878] in Kerberos

home help back first fref pref prev next nref lref last post

Re: How to Force a Kerb 4 Request

daemon@ATHENA.MIT.EDU (Rachel Elizabeth Dillon)
Tue Nov 23 16:33:30 2004

Date: Tue, 23 Nov 2004 16:32:47 -0500
From: Rachel Elizabeth Dillon <red@mit.edu>
To: "Henry B. Hotz" <hotz@jpl.nasa.gov>
Message-ID: <20041123213247.GK290@yiff.mit.edu>
Mime-Version: 1.0
In-Reply-To: <53B46DC2-3D96-11D9-BD74-000A95CA746C@jpl.nasa.gov>
cc: kerberos@mit.edu
Content-Type: multipart/mixed; boundary="===============022596689839018858=="
Errors-To: kerberos-bounces@mit.edu


--===============022596689839018858==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="GmiNL4+5WUWrod5m"
Content-Disposition: inline


--GmiNL4+5WUWrod5m
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

=46rom the kinit manpage in the most recent Debian version, which is 1.3.x:

OPTIONS
       -5     get Kerberos 5 tickets.  This overrides whatever the default=
=20
		built-in behavior may be.  This option may be used with -4

       -4     get  Kerberos 4 tickets.  This overrides whatever the default=
=20
		built-in behavior may be.  This option is only available if=20
		kinit was built with Kerberos 4 compatibility.  This option=20
		may be used with -5

I don't have a test server for Kerberos 4, but it works fine with my MIT
account.  Check your build for Kerberos 4 compatibility?

Best of luck,

-r.

On Tue, Nov 23, 2004 at 01:26:24PM -0800, Henry B. Hotz wrote:
> It appears that with 1.3.x you can't force it to make a kerberos 4 auth =
=20
> request.  I've tried putting only info in the [v4 realms]-like sections =
=20
> and disabling the DNS lookup on OSX 10.3, but then a kinit just fails.
>=20
> Is there any MIT equivalent to Heimdal kinit -4?
>=20
> Yes, I know this is a *BAD* idea and you-all hate it.  I just have a =20
> test case I need to support.
> ------------------------------------------------------------------------=
=20
> ----
> The opinions expressed in this message are mine,
> not those of Caltech, JPL, NASA, or the US Government.
> Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu
>=20
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos

--GmiNL4+5WUWrod5m
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBo6x/rAG/UVUP/b0RAvlGAKCugs3KOkNPaxm1UpRuIzuSXcRqvACfbxwq
hS3qg6PknQVncj65HPr33EU=
=Ns3w
-----END PGP SIGNATURE-----

--GmiNL4+5WUWrod5m--

--===============022596689839018858==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============022596689839018858==--

home help back first fref pref prev next nref lref last post