At Argonne, we have been running MIT kerberos clients using the
AFS Kaserver as the KDC. We have a modified kadmind which issues
"kas setkey" commands to stuff in a MIT form of a key into the
AFS database. We also use the CMU lifetime mods in the Kerberos
clients since AFS has a different interpretation of the lifetime
as well.

The transarc klog is smart enough to try both string to key
functions but not their kpasswd command. We have a modified
kpasswd for AFS users which will try both and contact the
modified kadmind.

Unmodified MIT clients can work with this system as well.

The hope is that eventually all the keys in the Kaserver database
will be generated using the MIT string_to_key function, which
will make it easier to convert to DCE.

I made this available via anonymous FTP over a year ago at
achilles.ctd.anl.gov:/pub/kerberos.v4. See the README file there
for more info.

           Douglas E. Engert
           Systems Programming
           Argonne National Laboratory
           9700 South Cass Avenue
           Argonne, Illinois  60439
           (708) 252-5444

           Internet: [EMAIL PROTECTED]

Reply via email to