[23350] in Kerberos
Re: MIT + Heimdal + openssh == cross realm difficulties
daemon@ATHENA.MIT.EDU (Priit Randla)
Wed Feb 9 03:54:08 2005
Message-ID: <4209CF7D.4020004@eyp.ee>
Date: Wed, 09 Feb 2005 10:53:17 +0200
From: Priit Randla <priit.randla@eyp.ee>
MIME-Version: 1.0
To: "Henry B. Hotz" <hotz@jpl.nasa.gov>
In-Reply-To: <40c79bf4aad283e6a7b8b72141f9ae82@jpl.nasa.gov>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
Henry B. Hotz wrote:
> It's not clear to me why the MIT and Heimdal realms need to be
> different.
The reason is quite embarassing, actually - total re-branding. Total
renamification :-) from AAA to BBB.
Lotsa host/* principals to recreate and change. And 24/7/365 as usual.
So I have to simply
accept that those two realms have to exist and work together for some
unspecified time.
> You can import an MIT database into Heimdal with hprop. Google for
> the details, but you export a MIT dump file with some specific
> options and then use hprop to read it into Heimdal.
Dit it. Unfortunately, all password policies will get lost in the
process. Which reminds me that I didn't see a way to create and use
policies under Heimdal...
Major PIA if these aren't implemented.
Priit
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos