Cross realm authentication

2010-01-05 Thread BOUCHER, Flavien
Hi, I have some question about CROSS REALM authentication. I have two domains: TEST.COM and TEST2.COM These two domain use Windows server 2003, and there is a trust relationship two way between them. How could I setup a CROSS realm domain authentication ? Where should I setup a ktpass ? Where s

Re: Wrong principal in request

2010-01-05 Thread Jeffrey Altman
On 1/4/2010 8:42 PM, Russ Allbery wrote: > Jeff Blaine writes: > >> I happened to notice this (note the missing realm) after a >> failed GSSAPI attempt to the SSH server (mega): > >> [r...@mega ~]# klist >> Ticket cache: FILE:/tmp/krb5cc_0 >> Default principal: jbla...@foo > >> Valid starting

Re: openssh + kerberos + windows ad

2010-01-05 Thread Hans van Zijst
Hi Marcello, Ah, you didn't have a keytab. I assumed you did :) I used Windows to create the key and added it to /etc/krb5.keytab with ktutil. Perhaps these entries in /etc/krb5.conf make a difference. In your case, YaST has probably taken care of this file, but this is what I have put into it