[23350] in Kerberos

home help back first fref pref prev next nref lref last post

Re: MIT + Heimdal + openssh == cross realm difficulties

daemon@ATHENA.MIT.EDU (Priit Randla)
Wed Feb 9 03:54:08 2005

Message-ID: <4209CF7D.4020004@eyp.ee>
Date: Wed, 09 Feb 2005 10:53:17 +0200
From: Priit Randla <priit.randla@eyp.ee>
MIME-Version: 1.0
To: "Henry B. Hotz" <hotz@jpl.nasa.gov>
In-Reply-To: <40c79bf4aad283e6a7b8b72141f9ae82@jpl.nasa.gov>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Henry B. Hotz wrote:

> It's not clear to me why the MIT and Heimdal realms need to be  
> different.

    The reason is quite embarassing, actually - total re-branding. Total 
renamification  :-) from AAA to BBB.
Lotsa host/* principals to recreate and change. And 24/7/365 as usual. 
So I have to simply
accept that those two realms  have to exist and work together for some 
unspecified time.

> You can import an MIT database into Heimdal with hprop.  Google for 
> the  details, but you export a MIT dump file with some specific 
> options and  then use hprop to read it into Heimdal.

    Dit it. Unfortunately, all password policies will get lost in the 
process. Which reminds me that I didn't see a way to create and use 
policies under Heimdal...
 Major PIA if these aren't implemented.

Priit


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post