Sample kinit (with Kerberos/Apache/Windows Server )



Hello,

I try to use a kerberos authentication with Windows
server and the module "modauthkerb".

First I have created a user into Ws Server.
Second I have mapped this user to my host ( ktpass
-princ HHTP/host@DOMAIN -mapuser myuser -out key)
Third, I move the key into my linux host.

Now :
I can connect with "kinit myuser" from the linux host.

BUT
1. I can't connect with "kinit HTTP/myhost". Why ? My
mapping is bad ??
The error is : "kinit(v5): Client not found in
Kerberos database while getting initial credentials"

2. I can't connect with "kinit myuser -k -t key".
Maybe the key is associated to the host... This is
something I don't understand...
The error is : "kinit(v5): Key table entry not found
while getting initial credentials"

Many Many Thanks for help !



----
my krb5.conf :

[libdefaults]
default_realm = DOMAIN

[realms]
DOMAIN = {
kdc = wsserver:88
admin_server = wsserver:749
default_domain = DOMAIN
}

[domain_realm]
domain = DOMAIN
.domain= DOMAIN







___________________________________________________________________________
Appel audio GRATUIT partout dans le monde avec le nouveau Yahoo! Messenger
Téléchargez cette version sur http://fr.messenger.yahoo.com
________________________________________________
Kerberos mailing list Kerberos@xxxxxxx
https://mailman.mit.edu/mailman/listinfo/kerberos

.



Relevant Pages

  • Re: Checking if User is in Role
    ... if you do not have the full credentials of a user ... kerberos authentication which allow the server to construct a windows token ...
    (microsoft.public.dotnet.framework.aspnet)
  • Kerberos authentication under IIS 5
    ... Kerberos authentication, ... used and IIS correctly delegates the credentials to the ... remote server via the ServerXMLHTTP object. ... delegation in this case does not work, ...
    (microsoft.public.inetserver.iis.security)
  • RE: Critical errors in security log
    ... the Kerberos authentication fails as it is unable to pass ... the DC is the time server and it has this ... Check the time zone setting. ... Make sure the Windows Time Service's startup is set as 'Automatic'. ...
    (microsoft.public.windows.server.sbs)
  • Virtual Server on DC wont register/recognize SPNs
    ... Both Virtual Server ... and Windows are the x64 editions and I get this error when I try to ... "The VMRC server cannot start because the service principal name ... required for Kerberos authentication could not be registered. ...
    (microsoft.public.windows.server.general)
  • Re: Mit Kerberos Client With trusted Active directories
    ... trust between Both AD servers. ... I want to do Kerberos authentication from machine which is joined to ... Domain_B Server. ... TGT is used against Domain_B to get a second TGT usable at Domain_A. ...
    (comp.protocols.kerberos)