[37572] in Kerberos
Re: A way to automatically get a ticket through ssh for a local user
daemon@ATHENA.MIT.EDU (Brandon Allbery)
Thu Jul 14 18:26:12 2016
From: Brandon Allbery <ballbery@sinenomine.net>
To: Mauro Cazzari <mymagicid@gmail.com>, "Kerberos@mit.edu" <Kerberos@mit.edu>
Date: Thu, 14 Jul 2016 22:25:50 +0000
Message-ID: <5D8D7E75-0525-4AA4-B39F-1F3B6E3EEF3D@sinenomine.net>
In-Reply-To: <CAFUXA2BwFds7zZ_4vKPDhTnBb_wFrw4jqwtmUDk5PAzUHr2RSg@mail.gmail.com>
Content-Language: en-US
Content-ID: <4B05297625608C4CA482D1E2D03E542C@mex09.mlsrvr.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit
On 7/14/16, 17:32, "kerberos-bounces@mit.edu on behalf of Mauro Cazzari" <kerberos-bounces@mit.edu on behalf of mymagicid@gmail.com> wrote:
# Kerberos options
KerberosAuthentication yes
KerberosOrLocalPasswd yes
KerberosTicketCleanup yes
#KerberosGetAFSToken no
#KerberosUseKuserok yes
I would turn these off; they refer to an older Kerberos API in ssh and may interfere with GSSAPI.
The others look correct. Note that if it is using public key authentication to get to the next server, it will not use the Kerberos code and therefore won’t forward (delegate) credentials to the next server. (Also note that if there are other matching Host blocks, the “Host *” block in ssh_config won’t be used.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos