Re: ssh GSSAPI and auth_to_local

2010-09-29 Thread Douglas E. Engert
On 9/27/2010 8:11 PM, Tom Parker wrote: I apologize for the long posting. I am stumped here and my scenario is a bit complex. As I am sure the list has noticed from all my questions, in the past few weeks I have been trying to build a distributed Kerberos/LDAP system with hosts

Re: ssh GSSAPI and auth_to_local

2010-09-29 Thread Tom Parker
On 09/29/2010 10:34 AM, Douglas E. Engert wrote: On 9/27/2010 8:11 PM, Tom Parker wrote: I apologize for the long posting. I am stumped here and my scenario is a bit complex. As I am sure the list has noticed from all my questions, in the past few weeks I have been trying to build a

Re: ssh GSSAPI and auth_to_local

2010-09-28 Thread Greg Hudson
On Mon, 2010-09-27 at 21:11 -0400, Tom Parker wrote: [realms] CENTRAL = { auth_to_local = RULE:[1:$...@central] auth_to_local = RULE:[2:$...@central] } This works great for ssh with passwords but it has totally broken the GSSAPI Single Sign On.

ssh GSSAPI and auth_to_local

2010-09-27 Thread Tom Parker
I apologize for the long posting. I am stumped here and my scenario is a bit complex. As I am sure the list has noticed from all my questions, in the past few weeks I have been trying to build a distributed Kerberos/LDAP system with hosts scattered around the Americas. Due to latency and