Solaris 9 Authentication

Configuration:
MIT Kerberos 1.4
Solaris 9 Master
Solaris 9, MAC OSX, & PC Clients
/usr/lib/ssh/sshd daemon using pam_krb5.so.1
Pre-Auth enabled

Issue:
MAC and PC clients using ssh authenticate successfully against Solaris 9 
servers and Kerberos system.
ssh -l <username> <hostA>
<username>@<hostA> Password: <Enter Kerberos Password>
Last login: Wed Jun 29 08:26:47 2005 from <client host>
motd message
$

Solaris 9 clients get the following error when using Kerberos 
authentication:
ssh -l <username> <hostA>
<username>@<hostA> Password: <Enter Kerberos Password>
Permission denied, please try again.
<username>@<hostA> Password: <Enter Shadow Password>
Last login: Wed Jun 29 08:26:47 2005 from <client hostA>
motd message
$

Master kdc.log:
Jun 29 08:43:55 <master kerberos server> krb5kdc[10062](info): AS_REQ (2 
etypes {3 1}) <hostA ip address> PREAUTH_FAILED: <username@REALM> for 
krbtgt@REALM, Decrypt integrity check failed

Steve
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

0
scanell (9)
6/29/2005 4:17:20 PM
comp.protocols.kerberos 5537 articles. 0 followers. jwinius (31) is leader. Post Follow

1 Replies
267 Views

Similar Articles

[PageSpeed] 10
Since ssh authentication is taking place on the SUN server, I took a 
copy of the keytab file from the Master kerberos server and placed it 
place of the one created by running ktadd on hostA... now hostA has a 
copy of the kadm5.keytab from the Master server.

Once I did this (and this was the same for the SLAVE Kerberos server), 
then pre-auth works and I was able to sign in to hostA from another 
Solaris box.

Can anyone tell me why this works... I am presuming it has something to 
do with local authentication on hostA that requires the keytab file from 
the Master where the ticket was originally created and thus the keytab 
has the data necessary for decryption.

Steve

scanell wrote:

> Configuration:
> MIT Kerberos 1.4
> Solaris 9 Master
> Solaris 9, MAC OSX, & PC Clients
> /usr/lib/ssh/sshd daemon using pam_krb5.so.1
> Pre-Auth enabled
>
> Issue:
> MAC and PC clients using ssh authenticate successfully against Solaris 
> 9 servers and Kerberos system.
> ssh -l <username> <hostA>
> <username>@<hostA> Password: <Enter Kerberos Password>
> Last login: Wed Jun 29 08:26:47 2005 from <client host>
> motd message
> $
>
> Solaris 9 clients get the following error when using Kerberos 
> authentication:
> ssh -l <username> <hostA>
> <username>@<hostA> Password: <Enter Kerberos Password>
> Permission denied, please try again.
> <username>@<hostA> Password: <Enter Shadow Password>
> Last login: Wed Jun 29 08:26:47 2005 from <client hostA>
> motd message
> $
>
> Master kdc.log:
> Jun 29 08:43:55 <master kerberos server> krb5kdc[10062](info): AS_REQ 
> (2 etypes {3 1}) <hostA ip address> PREAUTH_FAILED: <username@REALM> 
> for krbtgt@REALM, Decrypt integrity check failed
>
> Steve
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

0
scanell (9)
6/29/2005 9:41:17 PM
Reply:
Similar Artilces:

Re: [tao-users] CORBA::release() is causing core dump on solaris
Hi > TAO VERSION: 1.3.3 > ACE VERSION: 5.3.3 Thanks for using the PRF! > HOST MACHINE and OPERATING SYSTEM: > > SunOS portal42 5.8 Generic_108528-23 sun4u sparc SUNW,Ultra-80 > > If on Windows based OS's, which version of WINSOCK do you > use?: > > TARGET MACHINE and OPERATING SYSTEM, if different from HOST: > COMPILER NAME AND VERSION (AND PATCHLEVEL): > > CC: Sun WorkShop 6 update 1 C++ 5.2 Patch 109508-09 2002/07/08 > > AREA/CLASS/EXAMPLE AFFECTED: > [What example failed? ...

Software Express: get the development version of Solaris today
Buried deep in one of todays press releases: Software Express for Solaris is a Web-based program that gives customers a competitive edge, delivering state-of-the-art technologies with online support and a community forum. The program will include features of future versions of Solaris, such as NFS v4, the standards-based Network File System optimized for Internet use, DTrace -- a set of capabilities for rapidly diagnosing problems and bottlenecks in applications and Solaris Zones -- a server virtualization technology that provides security isolation and fault containment. T...

FAQ 4.33 How do I pad a string with blanks or pad a number with zeroes? #9
This is an excerpt from the latest version perlfaq4.pod, which comes with the standard Perl distribution. These postings aim to reduce the number of repeated questions as well as allow the community to review and update the answers. The latest version of the complete perlfaq is at http://faq.perl.org . -------------------------------------------------------------------- 4.33: How do I pad a string with blanks or pad a number with zeroes? In the following examples, $pad_len is the length to which you wish to pad the string, $text or $num contains the string to be padded, and $pa...

NYC LOCAL: Thursday 12 January 2012 UNIGROUP: Isaac Rozenfeld on Oracle Sun Solaris 11 Release
<blockquote what="official UNIGROUP announcement" assurance="there will be giveaways and food" rsvp="registration requested, see below" entrance-fee="yes, see http://www.unigroup.org/unigroup-fees.html" location="The Cooper Union School of Engineering, see below" info="http://www.unigroup.org" edits="some paragraphs removed so notice fits in mailboxen"> Date: Fri, 6 Jan 2012 08:18:49 -0500 (EST) From: Unigroup_of_NY <unilist@unigroup.org> Subject: UNIGROUP 12-JAN-2012 (2nd Thu): Solaris 11 Relea...

problems with compilation on Solaris 9
I am a complete newbie to sendmail compilation. But I keep getting a consistent error in the compilation. My OS is Solaris 9. The sendmail version is 8.12.11. I have BerkeleyDB.4.2 installed. I am compiling with GCC-version 3.4.0. I am using the regular ../devtools/OS/SunOS.5.9 config file included with the source files. I also have a site.config.m4 file under .../devtools/Site dir. APPENDDEF(`confLIBDIRS', `-L/usr/local/BerkeleyDB.4.2/lib -R/usr/local/BerkeleyDB.4.2/lib')dnl is the only line in the file. I would like to add MILTER later on after I put this compile error behi...

File Manager in CDE in Solaris 9
I'm using CDE with Solaris 9. I'd like to run (start) the file manager from the command line. What is the command I need to execute? Thanks! Erik Jensen wrote: > I'm using CDE with Solaris 9. I'd like to run (start) the file manager > from the command line. What is the command I need to execute? > > Thanks! man -k "file manager" | grep CDE dtfile dtfile (1) - the CDE File Manager dtfile.config dtfile.config (4) - CDE File Manager configuration file dtfile_copy dtfile_copy (1) - the CDE File Manager copy utility dtfile_error dtf...

Re: FireFox 0.9 problem
mark nassy wrote: > when i launch firefox 0.9 the application appears in the dock then > disappears. it does so over and over. one way i found to stop the > cycle is to log out and back in again. i am using nfs networked home > directories, and firefox is on an afp sharepoint. This sounds like what happened to me: I downloaded the Darwin version rather than the MacOS X version. ...

Spamassassin, Red Hat 9
I'm sorry to bother you all with this but I'm a part-time tech who's not very good with Linux and I've got a boss breathing down my neck to get Spamassassin installed and I'm having nothing but problems. The installation seems to be fine. spamd is up and running and procmail is pointing to spamc and sendmail seems to be configured to use procmail but e-mails don't have the spamassassin headers. Like I said, I'm not really good at Linux and I didn't know any sendmail before this. It seems to me that the link between sendmail and procmail is broken but it look...

Build failing on Solaris
I've tried to google-up an answer but am not finding it, even tho i have seen passing reference to what sounds like the same problem from others. On a Solaris-8 machine i'm trying to build Python-2.3.2. Using gcc-3.2. All seems to go pretty well for a while, but them i'm getting the following: -------------------- $ make .... case $MAKEFLAGS in \ *-s*) CC='gcc' LDSHARED='gcc -shared' OPT='-DNDEBUG -g -O3 -Wall -Wstrict-prototypes' ./python -E ./setup.py -q build;; \ *) CC='gcc' LDSHARED='gcc -shared' OPT='-DNDEBUG -g -O3 -Wall -Wstri...

Solaris term problem
I'm having a problem in console (not using X) on a x86 laptop. When I change the TERM variable the console changes where the # prompt starts at the top and when it gets to the bottom of the screen it erases the whole screen and starts at the top again. Any help would be appreciated. What are you setting term to? Are you using telnet across the network or hyperterminal to the serial port? Tim dacrud@gmail.com wrote: > I'm having a problem in console (not using X) on a x86 laptop. When I > change the TERM variable the console changes where the # prompt starts > at the ...

[ANN] Ruby-VPI 9.0.0
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Version 9.0.0 (2006-10-28) Ruby-VPI is a Ruby interface to Verilog VPI. It lets you create complex Verilog test benches easily and wholly in Ruby. Website: http://ruby-vpi.rubyforge.org Install: gem install ruby-vpi Summary This release improves the automated test generator and adds new content to the user manual. Acknowledgments Thanks to Matt Fischler for helping test and debug the installation of Ruby-VPI on Windows. Notice * The command-line options for generate_test.rb have changed. Run the command generate...

oracle 9.0.1.2 memory leak?
Hi, I am running Oracle 9.0.1.2.0 64-bit on Solaris 8 SPARC. After a few days of uptime (the db is used by Java web applications), the Oracle processes will start using a lot of CPU cycles and memory, the queries will become very slow ... The resources won't be released and the performaces won't be restored, unless the Oracle database is restarted. Any idea on what could be the problem? Would applying the latest Oracle 9i R1 patchset help? Thanks. On Fri, 03 Sep 2004 14:47:23 +0200, cat54me <cat54me@yahoo.it> wrote: >Hi, >I am running Oracle 9.0.1.2.0 64-bit on So...

BIND 9.2.3rc2 brings entire machine down
I have a Mandrake 9.2 box which I've used every day for months with no problems. Recently I installed BIND 9.2.3rc2. I set up zones for local (LAN) names. I set my windows PC to use the Mandrake box for DNS. Everything works fine at first. And then, evenually, it crashes linux. When I say it crashes linux, I mean all processes become non-responsive. No mouse movement. It's not just KDE, either, I can't ssh into the machine either. It takes about an hour or so to happen. Everything works fine at first. I can do requests from the win machine, or from the mandrake ...

SN#23246 Solaris and OpenSolaris Book Recommendations
SYSTEM NEWS FOR SUN USERS Vol 148 Issue 5 2010-07-01 Article 23246 from section "Publications" For Beginner-, Intermediate-, and Advanced-level Users Joerg Moellenkamp, who has authored and published a set of tutorials on the "Less Known Solaris Features", has offered a list of must-have book recommendations on the Oracle Solaris and OpenSolaris operating systems. He has categorized these references for beginner-, intermediate-, and advanced-level users. Details at http://sun.systemnews.com/g?A=23246 Have a custom version...

v880, solaris 10, dual channel scsi cards, hangs during "boot -r"
I have a v880 with 16G memory, 3 x Sun dual channel SCSI3 with VHDCI interfaces, Solaris 10. I have 3 RAID units (Arena Maxtronic), each with dual SCSI interfaces. Each RAID is configured to present 2 LUNs to the SUN, with 2 of the interfaces presenting 3 LUNs. Bottom line, the SUN should see 14 targets from these 6 interfaces. At the OK prompt, a 'probe-scsi-all' does return all 14 of the targets described above (in addition to the system disk and cd drive). So, it seems that hardware wise, the SUN sees all my devices. But if I do a "boot -r" at the OK prompt, my system w...

US-MI-Auburn Hills: Solaris Eng., 3-5yrs exp., UNIX, Solaris Engineering; 3M (45334314407)
US-MI-Auburn Hills: Solaris Eng., 3-5yrs exp., UNIX, Solaris Engineering; 3M (45334314407) ========================================================================================== Position: Solaris Eng. Reference: SMC01842 Location: Auburn Hills MI Duration: 3M Skills: UNIX 3-5 YEARS exp Solaris Applied Engineering Requirements determination Scope: Taking requirements from Solaris servers, developing Build documentation and creating work orders. Please send your curren...

Can't Open PSP Ultimage Images with PSP 9 113698
I cannot open images I've created or loaded into PSP Photo X2 Ultimate using PSP 9. My backup plan to use PSP 9 if I end up hating Ultimate is floundering. Does anyone know why PSP Ultimate images won't open with PSP 9? In article <181b1cd3-f609-4b10-8ee5-801ab2bd7902@j39g2000yqh.googlegroups.com>, GSHATTERHAND <gshatterhand@aol.com> wrote: > I cannot open images I've created or loaded into PSP Photo X2 Ultimate > using PSP 9. > My backup plan to use PSP 9 if I end up hating Ultimate is > floundering. Does anyone know why PSP Ultimate images won't ...

Disk Mirroring in Solaris
Install the OS in one hard disk, and put the second one before turning on the Server. Now go to the root and type format, it will list you the hard disk Number. (i.e) c2t0d0 (Primary hard disk =96 with partition info) and c2t1d0 (secondary disk) http://www.nalanta.com/2008/08/21/disk-mirroring-in-solaris/ ...

how to log successful logon in vsftpd authentication
Dear all, Does anybody know how to keep a log for the successful logon in vsftp authentication? vsftpd only log down the failed logon attemp in the /var/log/messages file and uploads/downloads transaction in /var/log/vsftpd.log file. Thanks sam On Mon, 10 May 2004 23:08:56 +0800, sam wrote: > Dear all, > > Does anybody know how to keep a log for the successful logon in vsftp > authentication? vsftpd only log down the failed logon attemp in the > /var/log/messages file and uploads/downloads transaction in > /var/log/vsftpd.log file. > > Than...

Solaris 9 vs. Solaris 10?
I recently changed my x86 version of Solaris 8 to Solaris 10 at home, and so far I really like what I see. I never installed Solaris 9. What were the major differences between Solaris 9 and Solaris 10? - Scott Smith: scott.smith@iphouse.com MySpace: http://www.myspace.com/choppersmith S. Smith <scott.smith@iphouse.com> wrote: > > I recently changed my x86 version of Solaris 8 to Solaris 10 > at home, and so far I really like what I see. > > I never installed Solaris 9. What were the major differences between > Solaris 9 and Sol...

DOVICO Timesheet 9.0
Successful companies become successful by constantly improving, and that starts by understanding exactly how your employees time & costs are being used every day. Budgets and estimates are only useful if they're actually implemented and that means tracking every hour in real time. Our software has been tested and proven by thousands of companies like IBM, Honeywell, Blue Cross and Motorola. Whether you're a leader in your field today or just on your way to becoming one, DOVICO Timesheet can help increase your profits. Whether you are managing projects or not, you'll...

US-CO-Boulder: System Mgt. Specialist, AIX, SUN Solaris, UNIX, Win 2000; 12M (45337657602)
US-CO-Boulder: System Mgt. Specialist, AIX, SUN Solaris, UNIX, Win 2000; 12M (45337657602) ========================================================================================== Position: System Mgt. Specialist Reference: MKL00850 Location: Boulder CO Duration: 12M Skills: AIX SUN Solaris UNIX Win 2000 Win NT Tivoli ITM Tivoli TMR Tivoli Config Mgr LAN/WAN TCP/IP Tivoli Scope: Tivoli Administration in UNIX and Wind...

DBLIB for Solaris 10
Hi all; I'm hoping you can help. We are running an old version of Sybase (11.0.3.3), and it is rinning on an old version of SOlaris (5.6). We have a bunch of executables running on an even older Sun box, running SunOS 4.1.3_DB 2. Our developer is trying to port these executables to SOlaris 10, but still connect to the existing DB. Apparently, they're running into issues with the DBLIB, and is looking for one that is compatible with SOlaris 10. I'm including the error messages he's running into, and his description of what we need. Can anybody shed any light on where...

Problem with compiling Ruby-1.9.1-p243
Hi...I am having problem to compile Ruby-1.9.1-p243 on AIX 5.3. Can anyone help me? Thanks Richard -- Posted via http://www.ruby-forum.com/. On Fri, Oct 30, 2009 at 02:33:07AM +0900, Richard Lee wrote: > Hi...I am having problem to compile Ruby-1.9.1-p243 on AIX 5.3. Can > anyone help me? Thanks Can you post the problem? -- Aaron Patterson http://tenderlovemaking.com/ On Thu, Oct 29, 2009 at 5:33 PM, Richard Lee <wing2@yahoo.com> wrote: > Hi...I am having problem to compile Ruby-1.9.1-p243 on AIX 5.3. =A0Can > anyone help me? =A0Thanks Not unless you explain som...

Question from AIX guy re language/date settings on Solaris
My question is, what controls character set/language and date format settings on Solaris? Does Solaris use $LANG? having installed Solaris there is no $LANG set The $LANG on my AIX box is en_US JL John Leslie <johnleslie@madasafish.com> wrote: > My question is, what controls character set/language and date format > settings on Solaris? > > Does Solaris use $LANG? having installed Solaris there is no $LANG set > > The $LANG on my AIX box is en_US There is LANG, but if you want different settings for the different LC_.* variables, you do not set it. Type 'local...