[8036] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Help --- rlogin -x works one way only

daemon@ATHENA.MIT.EDU (Paul Leyland)
Thu Sep 19 07:41:10 1996

To: kerberos@MIT.EDU
Date: 19 Sep 1996 11:02:54 GMT
From: pcl@sable.ox.ac.uk (Paul Leyland)

In article <PCL.96Sep18181903@sable.ox.ac.uk> pcl@sable.ox.ac.uk (Paul Leyland) writes:

> I've just installed and set up K5B7 on a DEC Ultrix 4.5 KDC and with
> an Ultrix 4.3a client.   This is an experimental setup to enable a few
> of us to explore Kerberos and what it might be able to do for us.  The
> build and install seemed to go reasonably well.
> 
> The present state of play is that I can kinit as myself, pcl@OX.AC.UK,
> on the client and then successfully get an encrypted rlogin session to
> the KDC.
> 
> I cannot get an encrypted session the other way, from the server to the
> client.  A transcript of a sample session is:

Diagnostics deleted.

I have found an utterly inexplicable (to me) way of working around my
problem.  I can now get an encrypted session in both directions.

First hypothesis was that the host/*@OX.AC.UK principals and keytabs
were screwed, so I flushed the lot and created new ones.   No joy.

In desperation, I put tcp wrappers on the client's eklogin port, in the
hope that I might be able to pickup more diagnostic information.

Everything started working!

Someone else mailed me with a report of a similar problem to mine, but
with an Alpha OSF KDC.  I'll mail him personally with my findings.


Anyone prepared to guess what might be happening here?



Paul
--
Paul Leyland <pcl@oucs.ox.ac.uk>         | Hanging on in quiet desperation is
Oxford University Computing Services     |     the English way.
13 Banbury Road, Oxford, OX2 6NN, UK     | The time is gone, the song is over.
Tel: +44-1865-273200  Fax: 273275        | Thought I'd something more to say.
PGP KeyID: 0xCE766B1F

home help back first fref pref prev next nref lref last post