[23025] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Preauth and ticket forwarding

daemon@ATHENA.MIT.EDU (Rachel Elizabeth Dillon)
Wed Dec 8 13:28:35 2004

Date: Wed, 8 Dec 2004 13:24:30 -0500
From: Rachel Elizabeth Dillon <red@mit.edu>
To: Chaskiel M Grundman <cg2v@andrew.cmu.edu>
Message-ID: <20041208182430.GY290@yiff.mit.edu>
Mime-Version: 1.0
In-Reply-To: <D8FB731AA84B4F085AF958F1@sphinx.andrew.cmu.edu>
cc: kerberos@mit.edu
Content-Type: multipart/mixed; boundary="===============88561530860648541=="
Errors-To: kerberos-bounces@mit.edu


--===============88561530860648541==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="I2bJ1vO3Y/RENlXz"
Content-Disposition: inline


--I2bJ1vO3Y/RENlXz
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Tue, Dec 07, 2004 at 05:57:47PM -0500, Chaskiel M Grundman wrote:
> you ought to be able to tell if the client is sending a second request by
> using tcpdump or ethereal to capture packets from the network while the
> client is attempting to authenticate. (tcpdump does not have much of a kr=
b5
> packet dissector, but you can capture packets on the kdc with tcpdump -w,
> and copy the file to another system to run ethereal)

This is absolutely the right thing to do, thank you; I hope to have a chanc=
e=20
to try that today and see what happens.=20
=20
> The two features are not related. It's possible that the operation of
> disabling preauth somehow is dissociating the principals from the policy
> object they were using before. make sure that the user's principal (or
> relevant policy) and the krbtgt principal (or relevant policy) does not
> have DISALLOW_FORWARDABLE set on it.

Turning off preauth for the krbtgt/REALM principal makes forwarding work=20
without preauthentication (thanks, Sam!). I'll let the list know what
happens with the Cisco box in case anyone runs into the same problem in the
future.

Thanks, all!

-r.

--I2bJ1vO3Y/RENlXz
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBt0berAG/UVUP/b0RAt/MAKC8SZK4biPUc+vPIdFGBoE41B54RQCgsBfz
TfcuCYKtck+5ckLvyiD24wI=
=Nyy3
-----END PGP SIGNATURE-----

--I2bJ1vO3Y/RENlXz--

--===============88561530860648541==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============88561530860648541==--

home help back first fref pref prev next nref lref last post