[23046] in Kerberos
Re: kerberos/imap trouble
daemon@ATHENA.MIT.EDU (Thomas A. La Porte)
Fri Dec 10 14:56:36 2004
Date: Fri, 10 Dec 2004 11:48:34 -0800 (PST)
From: "Thomas A. La Porte" <tlaporte@anim.dreamworks.com>
To: Sam Hartman <hartmans@mit.edu>
In-Reply-To: <tslbrd2km4o.fsf@cz.mit.edu>
Message-ID: <Pine.LNX.4.44.0412101133300.29840-100000@sunset.anim.dreamworks.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
cc: Mark Hannessen <mark@nperfection.com>
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
On Fri, 10 Dec 2004, Sam Hartman wrote:
>No, the name a server advertizes does not affect what name a client
>uses to authenticate to that server for the gssapi sasl mechanism.
That's strange. I certainly wouldn't contradict what you're
saying, but the behaviour of our Cyrus IMAP server seems exactly
the same as that which Mark had described. And the fix was to
ensure that the names were the same.
I assume, then, that it has to do with our having a virtual
interface defined, rather than just a CNAME? The hostname that is
listed in our 'servername' parameter in /etc/imapd.conf is
configured on a virtual interface, it is not merely a CNAME for
the canonical FQDN of the host.
I can run 'imtest imap' (which is the virtual interface) and
successfully authenticate, whereas if I run 'imtest hostname'
with the canonical hostname of the IMAP server, the client
retrieves the proper imap/hostname service tickets, but the
connection is rejected by the IMAP server. The error message is:
GSSAPI [SASL(-13): authentication failure: GSSAPI Failure:
gss_accept_sec_context]
I thought that this might be the same problem, but perhaps not?
-- Tom
Thomas A. La Porte, DreamWorks SKG
<mailto:tlaporte@anim.dreamworks.com>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos