Re: Kerberos ~/.k5user file

2008-04-08 Thread Janne Johansson
On Mon, 2008-04-07 at 20:48 -0700, Clint Pachl wrote:
 Is the ~/.k5user file supported in OpenBSD's Heimdal implementation? I'm

...

 BTW, what is /root/.klogin? Is it for kerberos 4? It doesn't have a man

Yes, it is (was) for krb4.

[demime 1.01d removed an attachment of type application/pgp-signature which had 
a name of signature.asc]



Kerberos ~/.k5user file

2008-04-07 Thread Clint Pachl
Is the ~/.k5user file supported in OpenBSD's Heimdal implementation? I'm 
running OBSD 4.1.


kadmin list *
root
pachl
default
root/root
pachl/root
pachl/admin
kadmin/admin
kadmin/hprop
kadmin/changepw
krbtgt/MOKAZ.COM
changepw/kerberos
host/htx.mokaz.com
host/kerberos.mokaz.com
host/morpheus.mokaz.com
host/hercules.dmz.mokaz.com

/root/.k5user on hercules.dmz.mokaz.com:
[EMAIL PROTECTED] /bin/ls

/etc/login.conf on hercules.dmz.mokaz.com contains:
auth-defaults:auth=krb5:

[EMAIL PROTECTED] su root -c '/bin/ls /root'

I have tried the passwords for root, root/root, and pachl and cannot get 
/bin/ls to execute. The password for pachl/root of course gives me full 
su privileges.


BTW, what is /root/.klogin? Is it for kerberos 4? It doesn't have a man 
page and doesn't seem to work. The ~/.k5login works properly.


-pachl