[7902] in Kerberos

home help back first fref pref prev next nref lref last post

Re: request for Suggestions

daemon@ATHENA.MIT.EDU (Jason Gabler)
Tue Sep 3 19:52:20 1996

To: kerberos@MIT.EDU
Date: 3 Sep 1996 23:03:45 GMT
From: ccjason@quadrophenia.ucdavis.edu (Jason Gabler)

Dany Said (dany@cyberia.net.lb) wrote:
: Hello,

: I am working on installing kerberos on a Univesity network.
: I would like to have the following setup:

: - If someone is accessing the network from another domain( from outside
: the university network) , I would like to give him the ability to use
: kerberos for login and for transmitting  encrypted data.

1) you need to have that machine or machines domain (NOT realm, it would be the 
	same realm).  Or, you could do cross realm authentication if
	the domain where the user is coming from has kerberos 
	already, or can set it up there.

2) a principal for that host in your kdb
3) a principal for that user in your kdb.
4) appropriate srvtab and config files on the remote host (depending
	on wether you are using interdomain or interrealm authentication)
5) the necessary kerberized clients (i.e. rlogin, rsh, etc...)
6) appropriate services additions for kerberos

: - If someone is in the dimanin name of the university and wnats to
: access a remte machinr in the network,, I would like him to be able to
: uses kerbero for login but not to encrypt data.

Most steps above are the same except:

5) In addition to the clients (although the clients arent necessary
	for this part) you'd need the daemons (i.e. rlogind, rshd) that
	are kerberized on the remote host.

6) In addition to the services file additions, you need to appropriate
	inetd.conf additions.

: - else if he is on the same machine, I don't want him to be able to use
: kerberos.

I am not sure I understand this.  I cant really see why someone would be
	rlogining/telnetting from and to the same machine.  Also, why
	wouldn't you want them to use kerberos in that situation;
	although its superfluous, its no big deal.

: I want to control the mode of access af a user on the University network
: according to his IP address.
: Could I do it using Kerberos?

That'd depend on what you mean by "mode of access" I suppose.

: Any comment or suggestion is appreciated.

: Dany Said


--
Lehitra'ot!
 		jason 
.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,.,
`Jason Gabler                      Home Office: 415-752-1969 (M-W,F)     `
'Programmer/Analyst                Campus Office: 916-752-9215 (Th)      '
`Information Technology - DCAS     E-Page: jygabler@dcaspager.ucdavis.edu'
'University of California, Davis   http://quadrophenia.ucdavis.edu       `
`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'`'

home help back first fref pref prev next nref lref last post