[32256] in Kerberos
Re: Generic question regarding service principal required to
daemon@ATHENA.MIT.EDU (Greg Hudson)
Sat Apr 10 13:12:22 2010
From: Greg Hudson <ghudson@mit.edu>
To: Elia Pinto <gitter.spiros@gmail.com>
In-Reply-To: <v2n4df72b1a1004100228g6cb4326mcec91bdcf3b759f0@mail.gmail.com>
Date: Sat, 10 Apr 2010 11:02:17 -0400
Message-ID: <1270911737.23242.29.camel@ray>
Mime-Version: 1.0
Cc: "kerberos@mit.edu" <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
On Sat, 2010-04-10 at 05:28 -0400, Elia Pinto wrote:
> I can get a TGS ftp /<KDC MVS hostname>@< KDC MVS REALMS> but it seems
> that the client also requests a TGS host /<KDC MVS hostname>@< KDC MVS
> REALMS> but this one is not defined on the KDC MVS and so the ftp
> client logon fail.
The ftp client tries to authenticate to ftp/hostname, then falls back to
host/hostname if that fails. So, no, you don't need a host/hostname
service, but you do have to figure out why the initial authentication is
failing.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos