home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.protocols.kerberos
- Path: sparky!uunet!ukma!usenet.ins.cwru.edu!agate!stanford.edu!RC.RUG.NL!HEEMSTRA
- From: HEEMSTRA@RC.RUG.NL ("Mente H. Heemstra")
- Subject: Re: What's the use of .klogin ?? (Conclusion)
- Message-ID: <MAILQUEUE-101.930120095529.416@rc.rug.nl>
- Sender: news@shelby.stanford.edu (USENET News System)
- Reply-To: M.H.Heemstra@RC.RUG.NL
- Organization: Internet-USENET Gateway at Stanford University
- Date: Wed, 20 Jan 1993 08:55:29 GMT
- Lines: 52
-
- Thanks for all your reactions; they set me thinking, and I found out at last
- how it works:
-
- 1) for services in local realm:
-
- - go to host2
- - run ext_srvtab host2
- - install host2-new-srvtab in /etc/athena/srvtab
-
- 2) for services in remote realm:
-
- - go to host1
- - create rcmd.host2
- - run ext_srvtab host2
- - transfer the host2-new-srvtab to host2
- - go to host 2
- - concatenate /etc/athena/srvtab with the host2-new-srvtab from host1
-
- 3) to connect:
-
- - go to host1
- - run kinit (local realm)
- - run rlogin host2 -k realm_of_host1 and there you are logged in to
- host2 using your local authentication.
-
- What I wished for really was cross-realm authentication and that doesn't seem
- to be working.
- What eventually appears to work is installing two keys (from different realms)
- onto a host.
- Of course, this shouldn't be the way to go ....: imagine the size and
- complexity of the srvtabs if you wish to communicate mainly on the basis of
- kerberos security at a university where there is a lot of inter-faculty
- traffic and each faculty runs its own kerberos server ....
- This will, I expect, undermine security severely, and I pity the
- administators ....
-
- Mente H. Heemstra
-
- P.S.: special thanks to Steve Dyer who pointed out to me what I wanted in
- the first place.
-
- _______________________________ ____________________________________________
- | | |
- | Mente H. Heemstra | Email : M.H.HEEMSTRA@RC.RuG.NL |
- | State University Groningen | Bitnet: HEEMSTRA@HGRRUG5.BITNET |
- | Computing Centre | X.400 : C=NL; ADMD=400net; PRMD=SURF; |
- | Network Management | O=RuG; OU=RC; S=HEEMSTRA; I=MH; |
- | P.O. Box 800 | Phone : + 31 50 633433/638080 |
- | 9700 AV Groningen | Fax : + 31 50 633406 |
- | Netherlands | |
- |_______________________________|____________________________________________|
-
-