[24246] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Updating encryption types

daemon@ATHENA.MIT.EDU (Phil Dibowitz)
Thu Jul 7 20:47:15 2005

Date: Thu, 7 Jul 2005 17:46:18 -0700
From: Phil Dibowitz <phil@usc.edu>
To: Kevin Coffman <kwc@citi.umich.edu>, kerberos@mit.edu,
        Toan Nguyen <toan@usc.edu>
Message-ID: <20050708004615.GZ8907@usc.edu>
Mail-Followup-To: Kevin Coffman <kwc@citi.umich.edu>, kerberos@mit.edu,
	Toan Nguyen <toan@usc.edu>
Mime-Version: 1.0
In-Reply-To: <20050708003007.GY8907@usc.edu>
Content-Type: multipart/mixed; boundary="===============57947959745776823=="
Errors-To: kerberos-bounces@mit.edu


--===============57947959745776823==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="5mjPmdht4ZehXHR2"
Content-Disposition: inline


--5mjPmdht4ZehXHR2
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Jul 07, 2005 at 05:30:07PM -0700, Phil Dibowitz wrote:
> On Thu, Jul 07, 2005 at 02:22:59PM -0700, Phil Dibowitz wrote:
> > On Wed, Jul 06, 2005 at 07:21:17PM -0400, Kevin Coffman wrote:
> > > My guess is that your krbtgt/ISD.ISC.EDU@ISD.USC.EDU principal still
> > > only has a des key.  'cpw -randkey -keepold' on that principal to
> > > generate other keys.
> >=20
> > Nice. That works. I didn't realize that had to be updated. Which leaves=
 me
> > with a few more questions:
> >=20
> > 1. What's the difference between the principals krbtgt@ISD.USC.EDU and
> > krbtgt/ISD.USC.EDU@ISD.USC.EDU ? They both exist, but krbtgt/ISD.USC.ED=
U seems
> > to be the ACTUAL ticket granting principal, while krbtgt@ISD.USC.EDU ha=
s the
> > DISALLOW_ALL_TIX attribute.=20
>=20
> OK, so going back, I find that
>=20
> krbtgt/ISD.USC.EDU@ISD.USC.EDU is for crossrealm trust.
> krbtgt@ISD.USC.EDU was our original tgt.

Oh, I typoed. Which made me realize there's another issue. The cross-realm
princ is:

krbtgt/ICS.USC.EDU@ISD.USC.EDU

and the right tgt (based on Kerberos by Brian Tung), doesn't seem to be doi=
ng
anything:

krbtgt@ISD.USC.EDU

and the mystery ticket is doing everything:

krbtgt/ISD.USC.EDU@ISD.USC.EDU

Now I'm quite confused. Any thoughts would be appreciated.

--=20
Phil Dibowitz
Systems Architect and Administrator
Enterprise Infrastructure / ISD / USC
UCC 180 - 213-821-5427


--5mjPmdht4ZehXHR2
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQFCzczX7lkZ1Iyv898RAnJPAJ9osM0nSF2YbJdveVfZAMKRrWegHACeNugW
M2SzymvURjxAUp4R8Psy5/o=
=sqzh
-----END PGP SIGNATURE-----

--5mjPmdht4ZehXHR2--

--===============57947959745776823==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============57947959745776823==--

home help back first fref pref prev next nref lref last post