Re: cross realm trusts ..

2013-11-30 Thread Dennis Davis
, they are not supported by very old versions of our GSSAPI implementation (krb5-1.3.1 and earlier). Services running versions of krb5 without AES support must not be given AES keys in the KDC database. -- Dennis Davis dennisda...@fastmail.fm

Re: ticket lifetime kerberos

2013-08-30 Thread Dennis Davis
/how-to-change-the-kerberos-default-ticket-lifetime may also be useful. -- Dennis Davis dennisda...@fastmail.fm Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Unable to change Kerberos Ticket Life and Renewal Life

2013-04-18 Thread Dennis Davis
existing principals. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK d.h.da...@bath.ac.uk Phone: +44 1225 386101 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Fwd: Kerb5 features

2013-04-18 Thread Dennis Davis
. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK d.h.da...@bath.ac.uk Phone: +44 1225 386101 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: TGT ticket for SSH login

2012-11-02 Thread Dennis Davis
with an earlier version of kerberos. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK d.h.da...@bath.ac.uk Phone: +44 1225 386101 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: 2 preauth questions

2011-11-18 Thread Dennis Davis
on service principals. Just in case we have old user principals still without +preauth. This shouldn't be the case, We're just being cautious. So this wrong behaviour in older software is fine with us. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK d.h.da...@bath.ac.uk

Kerberos Lockout Policies.

2011-11-03 Thread Dennis Davis
are considered sensitive. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK d.h.da...@bath.ac.uk Phone: +44 1225 386101 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: bind KDC to single interface?

2010-02-23 Thread Dennis Davis
principals if offline-password-attacks are a worry. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK d.h.da...@bath.ac.uk Phone: +44 1225 386101 Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman

Re: MIT e-mail phish attempt

2009-02-10 Thread Dennis Davis
which targets the Reply-To address. I also believe the Sanesecurity anti-phishing signatures at: http://www.sanesecurity.com/ will defend against some of these attacks. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK d.h.da...@bath.ac.uk Phone: +44 1225 386101

Re: can't build 1.5 with --enable-static

2006-08-16 Thread Dennis Davis
version of make. But, as usual, I haven't a clue why two should give this problem and one doesn't. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK [EMAIL PROTECTED] Phone: +44 1225 386101 Kerberos mailing list Kerberos

Re: can't build 1.5 with --enable-static

2006-08-10 Thread Dennis Davis
\ ./plugins/kdb/db2/libdb2/btree \ ./plugins/kdb/db2/libdb2/recno \ ./plugins/kdb/db2/libdb2/clib do (cd $i; make OBJS.ST) done -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK [EMAIL PROTECTED] Phone: +44 1225 386101

Re: Unable to find requested database type

2006-07-19 Thread Dennis Davis
On Mon, 17 Jul 2006, Ken Raeburn wrote: From: Ken Raeburn [EMAIL PROTECTED] To: Dennis Davis [EMAIL PROTECTED] Cc: kerberos@mit.edu Date: Mon, 17 Jul 2006 09:06:32 -0400 Subject: Re: Unable to find requested database type On Jul 17, 2006, at 05:51, Dennis Davis wrote: As a Quick'N'Dirty

Re: Unable to find requested database type

2006-07-17 Thread Dennis Davis
. And sure enough, the generated file: krb5-1.5/src/include contains: /* Define if dlopen should be used */ /* #undef USE_DLOPEN */ As a Quick'N'Dirty fix, can I just alter the above to: #define USE_DLOPEN 1 after the configuration and just before the build? -- Dennis Davis, BUCS, University

Re: that interop mess: ldap, samba, kerberos

2005-11-23 Thread Dennis Davis
On Tue, 22 Nov 2005, Turbo Fredriksson wrote: From: Turbo Fredriksson [EMAIL PROTECTED] To: kerberos@mit.edu Date: Tue, 22 Nov 2005 17:30:54 +0100 Subject: Re: that interop mess: ldap, samba, kerberos Quoting Dennis Davis [EMAIL PROTECTED]: ... saslauthd certainly isn't buggy

Re: Unable to build 1.4.2 on FreeBSD

2005-08-11 Thread Dennis Davis
strings.h #endif + #ifdef __OpenBSD__ + #include stdio.h + #endif /* __OpenBSD__ */ + /* * errors: * GSS_S_BAD_NAMETYPE if the type is bogus Something similar may work for you on FreeBSD. Note that this *is* a bodge, not a fix. -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY

Re: Unable to build 1.4.2 on FreeBSD

2005-08-11 Thread Dennis Davis
On Thu, 11 Aug 2005, Vladimir Terziev wrote: From: Vladimir Terziev [EMAIL PROTECTED] To: Dennis Davis [EMAIL PROTECTED] Cc: [EMAIL PROTECTED], kerberos@mit.edu Date: Thu, 11 Aug 2005 13:29:04 +0300 Subject: Re: Unable to build 1.4.2 on FreeBSD This is from import_name.c: [snip

Re: Assertion failed w/krb5-1.4.1 on FreeBSD-5.3

2005-04-28 Thread Dennis Davis
on an (obsolete) OpenBSD3.3 system. My gut feeling (ie I could well be completely wrong) is that the --disable-thread-support argument to configure isn't being fully obeyed and some thread support is being picked up. I haven't even thought about how I'd look into this. -- Dennis Davis, BUCS

Re: Kerberos and windows problem ...

2005-03-16 Thread Dennis Davis
types specified in the System Administrator's Guide. For example: addprinc -e rc4-hmac:normal des-cbc-md4:normal ... (Oh boy, I hope I've got that right. Never used it myself, always relied on the defaults :-) -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK [EMAIL PROTECTED

Re: KADMIN error

2005-02-04 Thread Dennis Davis
On Thu, 3 Feb 2005, Tom Yu wrote: From: Tom Yu [EMAIL PROTECTED] To: Dennis Davis [EMAIL PROTECTED] Cc: Mike Dopheide [EMAIL PROTECTED], kerberos@mit.edu Date: Thu, 03 Feb 2005 13:15:54 -0500 Subject: Re: KADMIN error ... Ok, that is very useful information to have. The host-based

Re: KADMIN error

2005-02-03 Thread Dennis Davis
]# kadmin Authenticating as principal userhidden/[EMAIL PROTECTED] with password. kadmin: Database error! Required KADM5 principal missing while initializing kadmin interface -- Dennis Davis, BUCS, University of Bath, Bath, BA2 7AY, UK [EMAIL PROTECTED] Phone: +44 1225 386101

Re: kerberos/imap trouble

2004-12-10 Thread Dennis Davis
From: Mark Hannessen [EMAIL PROTECTED] To: [EMAIL PROTECTED] Date: Fri, 10 Dec 2004 14:27:30 +0100 I am trying to setup a kerberos v5 only cyrus imap server. that is: I would like all autherisation to be done by gssapi/kerberos. ... does anybody have a suggestion where I should look next? Is

Re: Problem with setting up Kerberos server

2003-12-01 Thread Dennis Davis
To: sam [EMAIL PROTECTED] References: [EMAIL PROTECTED] From: Sam Hartman [EMAIL PROTECTED] Date: Mon, 01 Dec 2003 08:37:09 -0500 cc: [EMAIL PROTECTED] Subject: Re: Problem with setting up Kerberos server sam == sam [EMAIL PROTECTED] writes: sam Dear all, I don't know how many of you setup

Re: GSS Server without secret key?

2003-11-07 Thread Dennis Davis
Subject: GSS Server without secret key? From: Oliver Schoett [EMAIL PROTECTED] Date: Thu, 06 Nov 2003 12:17:03 +0100 Organization: sdm AG, Muenchen, Germany To: [EMAIL PROTECTED] I have been playing with the Sun GSS/Kerberos sample code in

Re: host/*@REALM tickets with ssh, DNS

2002-08-09 Thread Dennis Davis
From: Josh Huber [EMAIL PROTECTED] Newsgroups: gmane.comp.encryption.kerberos.general Subject: host/*@REALM tickets with ssh, DNS Reply-To: Josh Huber [EMAIL PROTECTED] Date: Fri, 09 Aug 2002 11:38:30 -0400 ... I have a few general questions: 1) Here is the output from klist after logging in