support for libressl 2.9

2019-11-05 Thread Jerry
Hi. I am trying to compile Kerberos v1.17 with LibreSSL 2.9.x, but I get error messages about not finding the header file 'asn1_mac.h'. In LibreSSL 2.9.0, that header file was removed. I tried a few obvious tricks with the #if #include options but encountered other errors. Is there a patch

Kerberos: How can I lock a user who fail to login after 3 unsuccesful attempts?

2006-06-26 Thread Jerry Jiang
Hi, $Subject. client use kerberos for authentication, my question is that is there anything i can do with kerberos server to reach this object? Or anything else can be helpful to this case? thanks Kerberos mailing list Kerberos@mit.edu

Small leak in kadm5_get_init_creds

2007-03-04 Thread Jerry James
;context, client); error: if (ccache != NULL && init_type != INIT_CREDS) krb5_cc_close(handle->context, ccache); Regards, -- Jerry James, Assistant Professor[EMAIL PROTECTED] Computer Science Department http://www.cs.usu.edu/~jerry/ Utah State University

kprop with multiple or NATted IP address

2015-12-23 Thread Jerry Shipman
, and I shouldn’t try to work around it? Thank you for your help, Jerry Shipman Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: kprop with multiple or NATted IP address

2016-01-27 Thread Jerry Shipman
corrupted in the copy). It seems like this would be a bad idea; just checking. Thanks again, Jerry > On Dec 24, 2015, at 12:21 AM, Greg Hudson wrote: > > On 12/23/2015 03:50 PM, Jerry Shipman wrote: >> Is there a way to do what I’m trying to do? >> Or, is there a reason th

Re: kprop with multiple or NATted IP address

2016-01-28 Thread Jerry Shipman
) without missing anything important? I guess I would lose out on the possibility of doing incremental propagation. Thanks again, Jerry > On Jan 27, 2016, at 6:43 PM, Russ Allbery wrote: > > Jerry Shipman writes: > >> It’s me again, who was trying to kprop through

"revoking" a TGT?

2016-08-05 Thread Jerry Shipman
e it doesn't matter. But I thought it was worth asking. Thanks for your help, Jerry Shipman Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

AD integration (ticket size) question

2016-11-15 Thread Jerry Shipman
didn't think of. I don't know if I would be able to implement any of those, even if they are possible...but, I am curious about whether there are any options. Thanks a lot, Jerry Shipman Kerberos mailing list Kerberos@mit.ed

propagation of new service principal keys

2017-03-10 Thread Jerry Shipman
But, I wondered what the usual way to prevent this is? Thanks a lot, Jerry Shipman Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

question about kdb5_util dump format

2017-10-26 Thread Jerry Shipman
Is there something reasonable I can do to definitively find out whether the user's old and new passwords are the same? Thank you for the help, Jerry Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Re: question about kdb5_util dump format

2017-10-26 Thread Jerry Shipman
ust the first one isn't. Sorry for the misinformation. I think it's not very important, and I can drop it. Thanks again, Jerry Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

kdb5_util -b7 dump format

2018-12-10 Thread Jerry Shipman
)? How can I tell by looking, which ones are the current keys vs the historical keys? I think the kvno is in there somewhere? I just want to make sure I am reading this right. Thank you for your help, Jerry Kerberos mailing list Kerber

unicode support?

2019-05-03 Thread Jerry Shipman
Hello, This might be a stupid question, but: can you tell me whether Kerberos works with unicode in the password? (Maybe: roughly in which version was that added?) I'm trying to track down a mysterious issue -- this might be one possible explanation. Thank you for the help,

clarify meaning of dns_lookup_kdc?

2019-11-08 Thread Jerry Shipman
. But experimentally, it does work. Doing some tcpdumping, I can see it do a DNS lookup to find the KDCs, even though dns_lookup_kdc is set false. Perhaps the dns_lookup_kdc only affects realms that are defined in your [realms] section? Thank you for your help,

Re: kprop with multiple or NATted IP address

2020-01-03 Thread Jerry Shipman
cally (instead of doing the full database dumps). I can do that and I guess it would work... but it would be nice to not do that. Or is there some better idea that we didn't think of? Thank you again for your help, Jerry -Original Message- From: Greg Hudson Date: Thursday, Decembe

Re: kprop with multiple or NATted IP address

2020-01-03 Thread Jerry Shipman
Aha! This (-x unlockiter) looks like it will solve my immediate problem. Thanks a lot. Happy new year! Jerry -Original Message- From: Greg Hudson Date: Friday, January 3, 2020 at 11:53 AM To: "Jeremiah E. Shipman" , "kerberos@mit.edu" Subject: Re: kprop with m

can realms get "aliased" when there is a one-way trust? or, what is going on here?

2022-08-04 Thread Jerry Shipman
mit.foo.cornell.edu and b...@foo.cornell.edu are totally different entities! Why would it do that? Is there a way to turn that off? Or, more generally... can you help me understand what is going on there? Thank you! Jerry Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos

Building from source question (krb5 1.2.5) ...

2002-06-12 Thread Jerry Heyman
got krb5 to compile on Sequent hardware? If so, any tricks that I should be aware of?? Thanks, jerry -- Jerry Heyman 919.224.1442 | IBM SWG/Tivoli Software|"Software is the Build Infrastructure Architect| 3901 S Miami Blvd | difference between [EMAIL PROTECTED]| Durham, NC

Re: Building from source question (krb5 1.2.5) ...

2002-06-21 Thread Jerry Heyman
In article <ae7ssp$fn7$[EMAIL PROTECTED]>, [EMAIL PROTECTED] (Jerry Heyman) writes: >I don't know if this is the right place to ask, so I'll do so (and >expect corrections). > >I've downloaded the source from MIT and have been able to finagle >configure to wor

Re: Building from source question (krb5 1.2.5) ...

2002-06-21 Thread Jerry Heyman
On 21 June 2002 at 13:23, Sam Hartman <[EMAIL PROTECTED]> wrote: > >>>>> "Jerry" == Jerry Heyman <[EMAIL PROTECTED]> writes: > > Jerry> I've now confirmed that Dynix/PTX has a bad socket() (and > Jerry> friends) implementation.

kerberos 5 login (krb 5.1.2-5)

2002-07-16 Thread Jerry Heyman
tc/krb5.conf file is the identical file that has been used successfully for all the other platforms. # top shows login.krb5 utilizing 98% CPU - but load isn't showing 100% CPU utilization, so it must be wait stated. Accumulating time though. Any pointers/suggestions/ideas would be great

Re: kerberos 5 login (krb 5.1.2-5)

2002-07-18 Thread Jerry Heyman
- 1) != '/') sprintf(utmp_id, "k%s", cp - 1); else sprintf(utmp_id, "k0%s", cp); #endif strncpy(utx.ut_id, utmp_id, sizeof(utx.ut_id)); >From what I read, kAEy should be the right value for utx.ut_id, but I'm seeing a much longer string (see

Re: kerberos 5 login (krb 5.1.2-5)

2002-07-18 Thread Jerry Heyman
In article <ah74fd$5v4$[EMAIL PROTECTED]>, [EMAIL PROTECTED] (Jerry Heyman) writes: >In article <[EMAIL PROTECTED]>, > [EMAIL PROTECTED] (Sam Hartman) writes: >>I'd step through login in a debugger and see where it hangs. If you >>cannot do that, then start i

Re: kerberos 5 login (krb 5.1.2-5)

2002-07-18 Thread Jerry Heyman
In article <[EMAIL PROTECTED]>, [EMAIL PROTECTED] (Tom Yu) writes: >>>>>> "jerry" == Jerry Heyman <[EMAIL PROTECTED]> writes: > >jerry> In article <ah74fd$5v4$[EMAIL PROTECTED]>, >jerry> [EMAIL PROTECTED] (Jerry Heyman) writes: &

Installation of login authentication

2002-07-31 Thread Jerry Heyman
cutter set of instructions on how to force each of these different OSes to use the login.krb5 binary?? I apologize if this is in the FAQ - I've looked through it, and haven't found what I was looking for. jerry -- Jerry Heyman 919.224.1442 | IBM SWG/Tivoli Software|&qu

Re: Using non kerberized services on Solaris9 client

2004-06-29 Thread Gerald (Jerry) Carter
x27;ve seen but not had a chance to play with the gssapi module for proftpd (http://gssmod.sf.net/) And then there's always the GSSAPI SASL mechanism for things that support SASL (e.g. OpenLDAP). Hope this helps. cheers, jerry - --

Re: openldap principal

2004-07-02 Thread Gerald (Jerry) Carter
a the KDC and the OS calls to getpwnam(), et. al. go through NSS and out to LDAP. Hope this helps. Also you might be interested in the Heimdal+LDAP setup described at http://padl.com/esearch/Heimdal.html cheers, jerry - -

Re: openldap principal

2004-07-03 Thread Gerald (Jerry) Carter
incipal are unrelated. cheers, jerry > On 2-Jul-04, at 8:56 AM, Gerald (Jerry) Carter wrote: > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA1 > > > > On Thu, 1 Jul 2004, Frederic Medery wrote: > > > >> My question is : Do I have to create all the user

Re: How does IE handle Kerberos authentication??

2004-07-08 Thread Gerald (Jerry) Carter
://modgssapache.sourceforge.net/ cheers, jerry - -- Hewlett-Packard- http://www.hp.com SAMBA Team -- http://www.samba.org GnuPG Key http://www.plainjoe.org

Re: OpenLDAP -> GSSAPI (SASL) -> KERBEROS V Questions

2004-10-19 Thread Gerald (Jerry) Carter
like you are asking if you can use the same keytab for multiple OpenLDAP installations. Sorry if i misunderstood. cheers, jerry - - Alleviating the pain of Windows(tm) --- http://www.samba.org GnuP

Re: Samba 3 + Kerberized LDAP

2004-10-20 Thread Gerald (Jerry) Carter
for each | Matt> person. | | The samba client certainly supports Kerberos both for CIFS and LDAP | operations. I'm pretty sure this question was about smbd and not out client code. Our server code only supports simple binds to LDAP servers currently. It's our our todo list

Re: FW: krb5-1.3.5 build issues on Solaris 2.8

2004-10-31 Thread Gerald (Jerry) Carter
again). |> |>> <> I also tried with "/usr/ccs/bin"in my PATH and it |> still gives me the same problem. was /usr/ccs/bin in yoru path when you ran configure ? If not, then the makefile will still not find 'ar'. cheers, jerry - --

Re: help:Is there any kerberos version of ssh

2005-04-20 Thread Gerald (Jerry) Carter
ns sshd_config: GSSAPICleanupCredentials{yes|no} ssh_config: GSSAPIDelegateCredentials {yes|no} Running 'ssh - {host}' should display enough information for you to locate the gssapi-with-mic authentication mechanism in the logs to verify that things are working cor