[23004] in Kerberos

home help back first fref pref prev next nref lref last post

Re: ssh kerberos + forwarding ticket

daemon@ATHENA.MIT.EDU (Douglas E. Engert)
Mon Dec 6 16:19:07 2004

Message-ID: <41B4CC17.1010506@anl.gov>
Date: Mon, 06 Dec 2004 15:16:07 -0600
From: "Douglas E. Engert" <deengert@anl.gov>
MIME-Version: 1.0
To: Frederic Medery <dist-list@lexum.umontreal.ca>
In-Reply-To: <41B4C52F.2000805@lexum.umontreal.ca>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
cc: Mailing List Kerberos <kerberos@mit.edu>
Errors-To: kerberos-bounces@mit.edu



Frederic Medery wrote:

> Hello,
> 
> openssh version : openssh-3.9p1
> kerberos : krb5-server-1.2.7-28
> on Redhat AS V3
> 
> 
> I can connect t from station1 to server1 using kerberos auth. But the 
> tgt is not forwared (even if kinit -f).
> Server1 have a princ (host/server1) in the krb5 DB and krb5.keytab.
> 
> I thought that TGT forwarding was automatic.

The kinit -f indicates the ticket if forwardable.
You also need to tell ssh to forward the TGT.

   GSSAPIDelegateCredentials yes

For security reasons you only want to delegate to host you trust.
so you may want to add for selected hosts in your own ssh_config.

> 
> Do I need a princ host/station1 ?

No, not if station1 only the client.

> 
> 
> thanks !
> 
> 
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 
> 
> 

-- 

  Douglas E. Engert  <DEEngert@anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post