[22936] in Kerberos
Re: How to Force a Kerb 4 Request
daemon@ATHENA.MIT.EDU (Henry B. Hotz)
Tue Nov 30 04:26:33 2004
In-Reply-To: <C04466DC-674B-43CD-9977-4277B23E5E9B@mit.edu>
Mime-Version: 1.0 (Apple Message framework v619)
Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed
Message-Id: <C061353A-42B1-11D9-B7A8-000A95CA746C@jpl.nasa.gov>
Content-Transfer-Encoding: 7bit
From: "Henry B. Hotz" <hotz@jpl.nasa.gov>
Date: Tue, 30 Nov 2004 01:25:18 -0800
To: Alexandra Ellwood <lxs@mit.edu>
cc: Sam Hartman <hartmans@mit.edu>
cc: "'kerberos@mit.edu'" <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu
Except for the environment variable thing that's exactly what I did.
(I put the file in /Library/Preferences/edu.mit.Kerberos.)
I didn't do it myself, but someone else was able to use a close
relative of my krb5.conf file with RHEL 3. The kinit command
*required* the -4 option even though the JPL realm was defined to be K4
only.
On Nov 27, 2004, at 8:47 AM, Alexandra Ellwood wrote:
> Mac OS X's kinit does not support the -4 option because it is
> incompatible with the way the Kerberos Login Library manipulates
> tickets. In particular, the KLL defines the concept of a valid ticket
> cache as one which contains valid TGTs for all versions of Kerberos
> defined by the machine's Kerberos configuration (aka
> edu.mit.Kerberos). If we gave users the option of getting only v4
> tickets for a realm which supports both v4 and v5, other applications
> would display this ticket cache as invalid and confuse the user.
>
> If you need to solve this problem for a specific user, try creating a
> special edu.mit.Kerberos file which has "dns_fallback = no" set in
> [libdefaults] and only a v4 configuration (ie: [v4 realms] and [v4
> domain_realm] only). Then set the KRB5_CONFIG environment variable to
> point to that file and run kinit. I haven't tried this with all
> versions of Kerberos for OS X, but it should work.
>
> Note however that you may get the confusing behavior I described above
> if you attempt to use other applications (such as Kerberos.app) to
> examine the tickets.
------------------------------------------------------------------------
----
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos