[2947] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

krb5-appl/614: forwarded credentials do not work in rlogin

daemon@ATHENA.MIT.EDU (lio@ornl.gov)
Tue Jul 7 11:06:45 1998

Resent-From: gnats@rt-11.MIT.EDU (GNATS Management)
Resent-To: krb5-unassigned@RT-11.MIT.EDU
Resent-Reply-To: krb5-bugs@MIT.EDU, lio@ornl.gov
Date: Tue, 7 Jul 1998 10:57:03 -0400
From: lio@ornl.gov
Reply-To: lio@ornl.gov
To: krb5-bugs@MIT.EDU
Cc: lio@ornl.gov


>Number:         614
>Category:       krb5-appl
>Synopsis:       "rlogin -f" does not work
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    krb5-unassigned
>State:          open
>Class:          sw-bug
>Submitter-Id:   unknown
>Arrival-Date:   Tue Jul 07 10:58:01 EDT 1998
>Last-Modified:
>Originator:     Dan Million
>Organization:
	Oak Ridge National Laboratory
>Release:        krb5-1.0.5
>Environment:
	IBM RS/6000, AIX 4.1.5
System: AIX hpss1 1 4 000041156600


>Description:
	I just upgraded 2 of our development machines from KRB5 1.0.1 to
	1.0.5.  Now when I do "rlogin -f" to log onto a remote host and
	forward my Kerberos tickets, the credentials cache file does not
	get changed to be owned by me.  It is still owned by "root", so
	I can't read it, and thus cannot use it for anything.

	When I log into the remote host as "lio", this is what I see in
	/tmp:

	-rw-------  1 root  sys  509 Jul  7 10:53 /tmp/krb5cc_p36138

	So the credentials cache is being created, but its ownership is
	not being set correctly.

	This all worked fine in 1.0.1.

>How-To-Repeat:
	See Description above.
>Fix:
	None known other than avoiding forwarded credentials.
>Audit-Trail:
>Unformatted:

home help back first fref pref prev next nref lref last post