[5219] in Kerberos
DCE KDC server for K4 client
daemon@ATHENA.MIT.EDU (Joe Ramus)
Mon May 22 18:37:00 1995
Date: Mon, 22 May 95 15:23:49 PDT
From: ramus@nersc.gov (Joe Ramus)
To: authtf@es.net, kerberos@MIT.EDU
We saw the attached article on the DCE News group.
This raises some questions:
a. Is it true that the DCE KDC will not serve a Kerberos 4 client?
The MIT version 5 KDC does support Kerberos 4.
I assume this means listening on port 750 and returning a Version 4
ticket when a Version 4 request is received.
b. We want to use the DCE KDC to get Forwardable Version 5 tickets.
Then we want to use krb524 (running on the DCE machine) to get
a Version 4 ticket and aklog to get an AFS token.
Is this procedure likely to work?
----------------------------------------------------------------
| Joe Ramus NERSC Livermore (510) 423-8917 ramus@nersc.gov |
----------------------------------------------------------------
---------------------------------------------------------------------------
> comp.soft-sys.dce #1001
> From: hal@darkstar.bos.locus.com (Harold Lockhart)
> [1] Re: DCE server to MIT Kerb. v4 client?
> Date: Wed May 17 06:52:20 PDT 1995
> Organization: Locus Computing Corp
> Lines: 23
> In article <3paf7f$mki@news.bu.edu>, Nik Conwell <nik@bu.edu> wrote:
> > Does the DCE server have the possibility to serve a Kerberos v4 client?
> No, and there are no plans to add this in the future.
> For an excellent paper on the issues of deploying Kerberos 4 & 5 &
> DCE Security see:
> http://www.es.net/pub/esnet-doc/auth-and-security/auth-pilot-report.ps
> These people (Energy Sciences Network) have also collected an excellent
> set of reference papers, available at the same web site.
> Regards,
> Hal
> =================================================================
> Harold W. Lockhart Jr. Locus Computing Corporation
> Chief Technical Architect 8 New England Executive Park
> Email: hal@locus.com Burlington, MA 01803 USA