[23006] in Kerberos
Preauth and ticket forwarding
daemon@ATHENA.MIT.EDU (Rachel Elizabeth Dillon)
Tue Dec 7 15:09:41 2004
Date: Tue, 7 Dec 2004 15:07:15 -0500
From: Rachel Elizabeth Dillon <red@mit.edu>
To: kerberos@mit.edu
Message-ID: <20041207200715.GU290@yiff.mit.edu>
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="===============29760228235273489=="
Errors-To: kerberos-bounces@mit.edu
--===============29760228235273489==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="0UHrfMa04cc5CxVa"
Content-Disposition: inline
--0UHrfMa04cc5CxVa
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
I am one of many administrators for a network of 50 machines running
MIT Kerberos on Solaris. Recently, another administrator installed a=20
Cisco VPN Magic Box that supposedly uses Kerberos authentication, but
won't work unless preauthentication is turned off. With=20
preauthentication turned off for any given principal, ticket forwarding
no longer works for that principal. I guess my question is threefold:
1. What does preauth _actually_ do? From some reading, I believed it to
be based on clock skew, and fixed the clock skew between the VPN box
and the Kerberos server, but preauth still fails. All the KDC logs
say is that preauth is required just as they would for a successful
kinit, but with no successful kinit afterward. Of course, all the=20
Cisco box gives me is "Authentication Failure." Unfortunately, I do
not have a choice as to whether or not to use this product.
2. Assuming I have no choice but to turn off preauth for the Cisco box,
is there any way to make SSH ticket forwarding work with preauth
turned off? It works just fine as my system stands with preauth turned
on, but when preauth goes off, ticket forwarding stops working. This
makes sense as a security feature and I realize I am shooting myself
in the foot, but I am being ordered to shoot myself in the foot, and=20
I am trying to minimize immediate bleeding. :)
3. Does anyone have experience making MIT Kerberos work with a Cisco=20
VPN 3000? I've looked through the Cisco documentation and it doesn't
mention preauth or really much of anything except how to format your
@ signs.=20
Any suggestions would be greatly appreciated; thank you.
-r.=20
--0UHrfMa04cc5CxVa
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFBtg1zrAG/UVUP/b0RAnq/AJ464+4b+9iAHPM7Avqi5sl0dKV+TQCgwwT2
rU0UzvR8h9xywNyZeWtgSUM=
=NwRe
-----END PGP SIGNATURE-----
--0UHrfMa04cc5CxVa--
--===============29760228235273489==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos
--===============29760228235273489==--