[24282] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Windows SSH client that uses tickets not obtained from AD login

daemon@ATHENA.MIT.EDU (Christopher D. Clausen)
Tue Jul 12 03:27:15 2005

Message-ID: <077701c586b3$04b1db40$fdfefe0a@ad.uiuc.edu>
From: "Christopher D. Clausen" <cclausen@acm.org>
To: <kerberos@mit.edu>
Date: Tue, 12 Jul 2005 02:26:25 -0500
Errors-To: kerberos-bounces@mit.edu

jay alvarez <kerber0sb0y@yahoo.com> wrote:
> Hi,
>  Do you know any windows ssh client that can use
> gssapi authentication and not using SSPI(used by
> vintela and CSS putty versions)wherein it uses tickets
> that were obtained from an Active Directory login? I
> have downloaded KFW from MIT and I have successfully
> obtain tickets using Leash. I tried to use vintela's
> putty but I don't know how to tell it where Leash put
> my tickets. The vintela docs says it will use the
> tickets obtained upon an Active Directory login. In
> our case, we don't use AD service.

The version of putty at: http://www.sweb.cz/v_t_m/ works with tickets
obtained by MIT KfW.  However, it only works with gssapi-with-mic, so
you need to have OpenSSH 3.8 or higher on the server side.  I have been
using it for over a year without too many problems.  It works quite well
and the author even updated the source patch and the binary the two
times I've asked when security fixes were released for putty.

<<CDC
Christopher D. Clausen
ACM@UIUC SysAdmin


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post