[29848] in Kerberos

home help back first fref pref prev next nref lref last post

Problem when i use pkinit

daemon@ATHENA.MIT.EDU (=?gb2312?B?1cXB1Q==?=)
Sun May 18 14:01:04 2008

Message-ID: <BAY103-W46C3F423067AF6A154CEB7E0CA0@phx.gbl>
From: =?gb2312?B?1cXB1Q==?= <zhangl06843@hotmail.com>
To: <kerberos@mit.edu>
Date: Mon, 19 May 2008 02:00:22 +0800
In-Reply-To: <mailman.555.1210867585.30179.kerberos@mit.edu>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="===============2079147045=="
Errors-To: kerberos-bounces@mit.edu

--===============2079147045==
Content-Type: text/plain; charset="gb2312"
Content-Transfer-Encoding: 8bit


Hi,
   I use krb-1.6.3 to implement my pkinit according to the admin.pdf, 
I add X.509 cert to the directory, and I can get my TGT use 'kinit', but if I move my certs from the very directory, I can also get TGT, which puzzled me several days. Can you explain why ? 
   My question is  whether the preauthentication process of kerberos has been taken or not?
   My cert&key file format are both *.pem, rather than *.crt & *.key, and have assigned { +requires_preauth } in  kdc.conf. Is there anything wrong i made.
   Thanks,
--------------------------------------------Lin Zhang, Peking University, Beijing, China
_________________________________________________________________
Windows Live Photo gallery 数码相机的超级伴侣,轻松管理和编辑照片,还能制作全景美图!
http://get.live.cn/product/photo.html
--===============2079147045==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============2079147045==--

home help back first fref pref prev next nref lref last post