Re: Establish FAST encrypted channel between linux client and windows server

2015-02-12 Thread Faisal Ali
HA1|All} > You might want to use AES instead or include more enctypes with a | > > -Ross > > -Original Message- > From: Faisal Ali [mailto:faisal.ali@gmail.com] > Sent: Wednesday, February 11, 2015 4:49 AM > To: Wilper, Ross; kerberos@mit.edu > Subject: Re: Est

RE: Establish FAST encrypted channel between linux client and windows server

2015-02-11 Thread Wilper, Ross
Ross; kerberos@mit.edu Subject: Re: Establish FAST encrypted channel between linux client and windows server http://kerberos.996246.n3.nabble.com/Creating-a-keytab-with-ktpass-under-a-Computer-account-td14074.html I followed above link to create a computer account on Windows server and genera

Re: Establish FAST encrypted channel between linux client and windows server

2015-02-11 Thread Faisal Ali
http://kerberos.996246.n3.nabble.com/Creating-a-keytab-with-ktpass-under-a-Computer-account-td14074.html I followed above link to create a computer account on Windows server and generate keytab to be used for first kinit. It doesn't seem to work. Have I employed wrong procedure or was this expecte

RE: Establish FAST encrypted channel between linux client and windows server

2015-02-09 Thread Wilper, Ross
I would be interested to see if you can make this work. It's been a while since I've looked into this and did not get very far. It sounds like you are on the right path - one of the gotchas is that AD does not seem to support pkinit null, which is what many Kerberos implementations do to create