[1529] in Kerberos

home help back first fref pref prev next nref lref last post

Authenticator bug in rcmd commands from server to client

daemon@ATHENA.MIT.EDU (Andrew Rieger, IS/UNIX-Supp., 215-)
Tue Aug 20 17:57:55 1991

Date: 20 Aug 91 18:34:13 GMT
From: dhct7zf@bpats.bell-atl.com (Andrew Rieger, IS/UNIX-Supp., 215-466-8724)
To: kerberos@shelby.Stanford.EDU


  We are trying to get kerberos version 4 running between a Sparc 2 
  and 2 Sparc 1+ workstations running SunOS 4.1.1.  The source is the 
  latest distribution from MIT and it compiles fine.  All of the 
  standard commands work as expected (klogin, kpasswd, etc.),
  but the rcmd set of commands (rcp, rlogin, rsh) fails to authenticate.
  The server name is yugo, the client is vega and the realm is 
  BELL_ATL.COM.  The following is the error message that we receive

  yugo% /usr/athena/kinit
  Bell Atlantic NSI (yugo)
  Kerberos Initialization
  Kerberos name: dhct7zf
  Password:
  yugo% /usr/athena/klist
  Ticket file:    /tmp/tkt156
  Principal:      dhct7zf@BELL-ATL.COM

    Issued           Expires          Principal
    Aug 20 13:42:09  Aug 20 21:42:09  krbtgt.BELL-ATL.COM@BELL-ATL.COM

  yugo% rlogin vega
  Kerberos rlogin failed: Can't decode authenticator (krb_rd_req)
  yugo% /usr/athena/klist
  Ticket file:    /tmp/tkt156
  Principal:      dhct7zf@BELL-ATL.COM

    Issued           Expires          Principal
    Aug 20 13:42:09  Aug 20 21:42:09  krbtgt.BELL-ATL.COM@BELL-ATL.COM
    Aug 20 13:43:31  Aug 20 21:43:31  rcmd.vega@BELL-ATL.COM

  from the output of the second klist, it looks like the proper tickets
  have been granted to use the rcmd services, but that the client
  machine does not know how to authenticate the user.  This same error
  occurs when rcmd commands are attempted between client and client,
  but not when rcmd's are tried from client to server.  A person is able
  to successfully rlogin (and rcp, rsh) from a client to the server.
  This further makes a case for the client simply being unable to 
  decode the rcmd authenticator tickets.  

  Does anyone have any ideas as to why this is happening?  Help would
  be most appreciated. 


<><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><><>
Andrew Rieger		dhct7zf@bpats.bell-atl.com	1717 Arch 6SW9
Unix Sysadmin		bagate!bpats!dhct7zf	        Philly, PA 19103
Permanent Student	Andrew@cs.swarthmore.edu	(215) 466-8724

home help back first fref pref prev next nref lref last post