[7902] in Kerberos
Re: request for Suggestions
daemon@ATHENA.MIT.EDU (Jason Gabler)
Tue Sep 3 19:52:20 1996
To: kerberos@MIT.EDU
Date: 3 Sep 1996 23:03:45 GMT
From: ccjason@quadrophenia.ucdavis.edu (Jason Gabler)
Dany Said (dany@cyberia.net.lb) wrote:
: Hello,
: I am working on installing kerberos on a Univesity network.
: I would like to have the following setup:
: - If someone is accessing the network from another domain( from outside
: the university network) , I would like to give him the ability to use
: kerberos for login and for transmitting encrypted data.
1) you need to have that machine or machines domain (NOT realm, it would be the
same realm). Or, you could do cross realm authentication if
the domain where the user is coming from has kerberos
already, or can set it up there.
2) a principal for that host in your kdb
3) a principal for that user in your kdb.
4) appropriate srvtab and config files on the remote host (depending
on wether you are using interdomain or interrealm authentication)
5) the necessary kerberized clients (i.e. rlogin, rsh, etc...)
6) appropriate services additions for kerberos
: - If someone is in the dimanin name of the university and wnats to
: access a remte machinr in the network,, I would like him to be able to
: uses kerbero for login but not to encrypt data.
Most steps above are the same except:
5) In addition to the clients (although the clients arent necessary
for this part) you'd need the daemons (i.e. rlogind, rshd) that
are kerberized on the remote host.
6) In addition to the services file additions, you need to appropriate
inetd.conf additions.
: - else if he is on the same machine, I don't want him to be able to use
: kerberos.
I am not sure I understand this. I cant really see why someone would be
rlogining/telnetting from and to the same machine. Also, why
wouldn't you want them to use kerberos in that situation;
although its superfluous, its no big deal.
: I want to control the mode of access af a user on the University network
: according to his IP address.
: Could I do it using Kerberos?
That'd depend on what you mean by "mode of access" I suppose.
: Any comment or suggestion is appreciated.
: Dany Said
--
Lehitra'ot!
jason
.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,
`Jason Gabler Home Office: 415-752-1969 (M-W,F) `
'Programmer/Analyst Campus Office: 916-752-9215 (Th) '
`Information Technology - DCAS E-Page: jygabler@dcaspager.ucdavis.edu'
'University of California, Davis http://quadrophenia.ucdavis.edu `
`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'