[23208] in Kerberos

home help back first fref pref prev next nref lref last post

AW: Example for kinit -S ... ?

daemon@ATHENA.MIT.EDU (Barbat, Calin)
Mon Jan 17 09:23:43 2005

content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Date: Mon, 17 Jan 2005 15:23:02 +0100
Message-ID: <7A05A249A3DE11459B154221006BDE6F03B61794@exc-mch01.mch.osram.de>
From: "Barbat, Calin" <c.barbat@osram.de>
To: <lukeh@padl.com>
Content-Transfer-Encoding: 8bit
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Hello Luke,

Ok. Suppose, I have two services (SAP R/3 instances) which call each other by kerberized RFC (remote function call).
Does every service need then a ticket for the other one, possibly in the own keytab?

Then I would do something like: kinit -k -t /etc/krb5.keytab <name1>/<domain>@<REALM> -S <name2>/<domain>@<REALM>
and the keytab would need to contain both entries if I understand it well. Or?

Thanks, 

Calin.

-----Ursprüngliche Nachricht-----
Von: Luke Howard [mailto:lukeh@padl.com]
Gesendet: Montag, 17. Januar 2005 15:15
An: Barbat, Calin
Cc: kerberos@mit.edu
Betreff: Re: Example for kinit -S ... ?

>can somebody explain to me when to issue kinit with -S <service>?
>Perhaps with an example, preferably applied to a GSS-API-application.
>
>My command so far: kinit -k -t /etc/krb5.keytab <name>/<domain>@<REALM>

When you want a ticket to the specified service rather than a ticket
granting ticket.

-- Luke

--


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post