Re: "Best practices" or "Best implementations"?

From: Christoph Weizen (cwei_at_gmx.net)
Date: 04/30/05


Date: Sat, 30 Apr 2005 16:21:57 +0200

Richard E. Silverman wrote:
>>>>>>"CW" == Christoph Weizen <cwei@gmx.net> writes:
>
> CW> Hi list, I wonder how to implement OpenSSH the smart way. We have
> CW> ~70 hosts (AIX 5.2/5.3), several with HACMP using r-tools and
> CW> Kerberos.
>
> OpenSSH works smoothly with Kerberos for both server and user
> authentication. With ticket forwarding, you can then use ksu for
> automatic, logged access to other accounts.

This sounds good. I'll have to go deeper into Kerberos.

> CW> Well, all have its pros and cons. I read SSH from O'Reilly - I
> CW> don't think I have technical problems, but more organisational
> CW> problems.
>
> We just finished the 2nd edition of the snail book, and it contains a
> substantial section on Kerberos & PKI with SSH (which I wrote).

So, the 2nd edition is now pre-ordered. ;)

Nevertheless I still wonder how other people implemented OpenSSH in a
big server environment (server farm).

cheers,
Christoph



Relevant Pages

  • Re: Working out a OS X 10.4 Tiger ssh implementation issue, slow logins
    ... port of the OpenSSH release; it has code added to it. ... order to construct a ticket request for the SSH server, ... for the ticket request instead of going to the DNS. ... client will try to find the Kerberos context for the server via the DNS ...
    (comp.security.ssh)
  • RE: Event ID 40960 and 40961
    ... Thank you for posting to Microsoft newsgroup. ... if a XP/2003 machine is pointed directly at a DNS server that doesn't ... support Kerberos, secure dynamic updates will generate 40960/40961 events. ... XP/2003 machine is pointed to a 2000/2003 DNS server, ...
    (microsoft.public.windows.server.migration)
  • Re: [FATAL] Kerberos does not have a ticket for <any of my servers>
    ... was too large for Kerberos to read. ... | print server was not working, ... | My Exchange server is failing the Kerberos Test too... ... |> | The kerberos client received a KRB_AP_ERR_MODIFIED error from the ...
    (microsoft.public.win2000.active_directory)
  • Re: UserName and Kerberos tokens at the same time
    ... > What makes me feeling a bit strange is that the WSE 3.0 Kerberos demo also ... Are you logon the computer as a domain user when running the ... I have tried it on a Windows 2003 server as well and there I get the ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Java GSS/Kerberos issue - Autheticating server
    ... as used in a Kerberos principal. ... Figure 2 provides a sample login configuration entry for a server ... Argonne National Laboratory ...
    (comp.protocols.kerberos)