Re: using UPN to auth



Markus,

I believe this is what I need to do and you may have commented on this for
me before in another thread.

How would I go about modifying kinit on os x as you have mentioned below?

Regards,

Ben W Young


From: Markus Moeller <huaraz@xxxxxxxxxxxxxxxx>
Date: Wed, 12 Mar 2008 00:32:41 -0000
To: "kerberos@xxxxxxx" <mailto:kerberos@xxxxxxx>
Subject: Re: using UPN to auth

You need a modified kinit which sets the principal type to 10 (enterprise
name type). Windows will then use the UPN instead of the samaccountname to
authenticate. (See attached sample mkinit.c)

Markus.

BTW If your client support client canonicalisation you can authenticate as
jdoe@xxxxxxxxxx but get a ticket for samaccountname.

"Terry" <td3201@xxxxxxxxx> wrote in message
news:8ee061010803111146g3d5b36b2rd5e22be1d3961073@xxxxxxxxxxxxxxxxx
Hello,

I am very new to this. I have a FQDN in AD set to domain.foo. The
UPN of a user is jdoe@xxxxxxxxxxx (note the difference between foo
and com).

How can I authenticate with jdoe@xxxxxxxxxx? I am able to auth
correctly with the sAMAccountName.

Thanks!
________________________________________________
Kerberos mailing list Kerberos@xxxxxxx
https://mailman.mit.edu/mailman/listinfo/kerberos

________________________________________________
Kerberos mailing list Kerberos@xxxxxxx
https://mailman.mit.edu/mailman/listinfo/kerberos


**********************************************************************
This message is intended for the addressee named and may contain
privileged information or confidential information or both. If you
are not the intended recipient please delete it and notify the sender.
**********************************************************************
.



Relevant Pages

  • Re: using UPN to auth
    ... You need a modified kinit which sets the principal type to 10. ... Windows will then use the UPN instead of the samaccountname to authenticate. ...
    (comp.protocols.kerberos)
  • Re: using UPN to auth
    ... Windows will then use the UPN instead of the samaccountname to ... BTW If your client support client canonicalisation you can authenticate as ...
    (comp.protocols.kerberos)
  • Re: Possible scenario? was Re: HELP! Really strange problem w/AD and LDAP/LDIFDE
    ... be SAMACCOUNTNAME@DOMAIN so if you have someuser in the test.loc domain you will have a default UPN of someuser@xxxxxxxxx This is in place whether or not you have specified anything for the UPN attribute. ... This tends to come into play when people are setting UPNs that differ for the first portion from the sAMAccountName and they create an accidental collision. ... objectClass: user ... *IF* somehow we ended up with two users as the above, with the same userPrincipalName, could that cause the symptoms that I'm seeing, where I can do the simple bind with full DN, but not with UPN? ...
    (microsoft.public.windows.server.active_directory)
  • Kerberos.app AD UPN & SAM authentication issue
    ... Kerberos.app with an AD account with a different name for the UPN ... The SAM will authenticate but not the UPN? ...
    (comp.protocols.kerberos)
  • Re: Active Directory LDAP address book?
    ... which allows anonymous LDAP connections. ... Works fine as long as you authenticate. ... > Neil D. ... >> It's also referred to as your UPN. ...
    (microsoft.public.windows.server.active_directory)