[2947] in Kerberos-V5-bugs
krb5-appl/614: forwarded credentials do not work in rlogin
daemon@ATHENA.MIT.EDU (lio@ornl.gov)
Tue Jul 7 11:06:45 1998
Resent-From: gnats@rt-11.MIT.EDU (GNATS Management)
Resent-To: krb5-unassigned@RT-11.MIT.EDU
Resent-Reply-To: krb5-bugs@MIT.EDU, lio@ornl.gov
Date: Tue, 7 Jul 1998 10:57:03 -0400
From: lio@ornl.gov
Reply-To: lio@ornl.gov
To: krb5-bugs@MIT.EDU
Cc: lio@ornl.gov
>Number: 614
>Category: krb5-appl
>Synopsis: "rlogin -f" does not work
>Confidential: no
>Severity: non-critical
>Priority: medium
>Responsible: krb5-unassigned
>State: open
>Class: sw-bug
>Submitter-Id: unknown
>Arrival-Date: Tue Jul 07 10:58:01 EDT 1998
>Last-Modified:
>Originator: Dan Million
>Organization:
Oak Ridge National Laboratory
>Release: krb5-1.0.5
>Environment:
IBM RS/6000, AIX 4.1.5
System: AIX hpss1 1 4 000041156600
>Description:
I just upgraded 2 of our development machines from KRB5 1.0.1 to
1.0.5. Now when I do "rlogin -f" to log onto a remote host and
forward my Kerberos tickets, the credentials cache file does not
get changed to be owned by me. It is still owned by "root", so
I can't read it, and thus cannot use it for anything.
When I log into the remote host as "lio", this is what I see in
/tmp:
-rw------- 1 root sys 509 Jul 7 10:53 /tmp/krb5cc_p36138
So the credentials cache is being created, but its ownership is
not being set correctly.
This all worked fine in 1.0.1.
>How-To-Repeat:
See Description above.
>Fix:
None known other than avoiding forwarded credentials.
>Audit-Trail:
>Unformatted: