Re: [EXTERNAL] Re: FAST OTP

2016-08-29 Thread Machin, Glenn D
Pal" wrote: > > On 08/26/2016 04:38 PM, Diogenes Jesus wrote: > > > >> I was able to configure a krb5-1.14.2 KDC to use FAST OTP with an RSA Authentication Manager Radius server. > >> > >> I have a couple of questions:

Re: [EXTERNAL] Re: FAST OTP

2016-08-28 Thread Dmitri Pal
s SSSD, Kerberos client, DNS and other parts of the system. Thanks Dmitri > > Any help would be appreciated. > > > Glenn > > > > > On 8/26/16, 4:09 PM, "kerberos-boun...@mit.edu on behalf of Dmitri Pal" > wrote: > > On 08/26/2016 04:38 PM, Diog

Re: [EXTERNAL] Re: FAST OTP

2016-08-28 Thread Felix Weissbeck
Hello Glenn On Sonntag, 28. August 2016 01:10:12 CEST Machin, Glenn D wrote: > > Next step was to be able to use it for login/sudo.I modified the > pam_krb5 step to below in system-auth. What I see on the KDC are only > encrypted timestamp preauth. Even if you have configured OTP, auth vi

Re: [EXTERNAL] Re: FAST OTP

2016-08-27 Thread Machin, Glenn D
Any help would be appreciated. Glenn On 8/26/16, 4:09 PM, "kerberos-boun...@mit.edu on behalf of Dmitri Pal" wrote: On 08/26/2016 04:38 PM, Diogenes Jesus wrote: > >> I was able to configure a krb5-1.14.2 KDC to use FAST OTP with an RSA Authentication Ma

Re: FAST OTP

2016-08-26 Thread Dmitri Pal
On 08/26/2016 04:38 PM, Diogenes Jesus wrote: > >> I was able to configure a krb5-1.14.2 KDC to use FAST OTP with an RSA >> Authentication Manager Radius server. >> >> I have a couple of questions: >> >> >> · FAST requires an existing ticket ca

Re: FAST OTP

2016-08-26 Thread Diogenes Jesus
> I was able to configure a krb5-1.14.2 KDC to use FAST OTP with an RSA > Authentication Manager Radius server. > > I have a couple of questions: > > > · FAST requires an existing ticket cache. If you need a TGT to get a > FAST OTP TGT how do you do tha

FAST OTP

2016-08-26 Thread Machin, Glenn D
I was able to configure a krb5-1.14.2 KDC to use FAST OTP with an RSA Authentication Manager Radius server. I have a couple of questions: · FAST requires an existing ticket cache. If you need a TGT to get a FAST OTP TGT how do you do that? · The OTP preauth client is