[23115] in Kerberos
Re: kadmin can't use TGT based?
daemon@ATHENA.MIT.EDU (Sam Hartman)
Tue Jan 4 15:36:09 2005
To: Chaskiel M Grundman <cg2v@andrew.cmu.edu>
From: Sam Hartman <hartmans@mit.edu>
Date: Tue, 04 Jan 2005 15:36:23 -0500
In-Reply-To: <E98D45E83B83B5C1BC213F4E@sphinx.andrew.cmu.edu> (Chaskiel M.
Grundman's message of "Mon, 03 Jan 2005 17:08:42 -0500")
Message-ID: <tslr7l1kk3c.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
>>>>> "Chaskiel" == Chaskiel M Grundman <cg2v@andrew.cmu.edu> writes:
Chaskiel> --On Monday, January 03, 2005 00:19:47 +0000 Mark Roach
Chaskiel> <mrroach@okmaybe.com> wrote:
>> Hi, I'm fairly new to Kerberos. I want to verify that I
>> understand this item correctly: Is it true that you can not use
>> a TGT based ticket to connect to the kadmin server?
Chaskiel> If your realm is set up properly, then yes. It is proper
Chaskiel> practice to set DISALLOW_TGT_BASED on the kadmin/admin,
Chaskiel> kadmin/changepw, and changepw/kerberos service
Chaskiel> principals. that is however a policy decision, not
Chaskiel> anything that is fixed in the protocol.
Well, I think the MIT kadmind actually enforces this itself even if
you don't set the KDC policy.
--Sam
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos