Kerberos Authentication not working with ssh through pam

From: Mark Faine (mfaine_at_knology.net)
Date: 10/26/05


Date: Wed, 26 Oct 2005 08:55:23 -0500

Suse Linux Enterprise 9 SP2
OpenSSH_3.8p1, SSH protocols 1.5/2.0, OpenSSL 0.9.7d 17 Mar 2004

-----

I've configured Kerberos Client and can successfully get a ticket with
kinit <username>

I've configured /etc/security/pam_unix2.conf with "use_krb5"

Yet I cannot get sshd to take my Kerberos authentication. When I enter
the password it immediately (very quickly, too quickly) rejects it. It
will take my unix login but it takes about 3-5 seconds to authenticate
which makes me believe it is at least trying my unix password on the
kerberos server.

Any assistance would be appreciated.

Thanks,
-Mark

----== Posted via Newsfeeds.Com - Unlimited-Uncensored-Secure Usenet News==----
http://www.newsfeeds.com The #1 Newsgroup Service in the World! 120,000+ Newsgroups
----= East and West-Coast Server Farms - Total Privacy via Encryption =----



Relevant Pages

  • Re: Kerberos interoperablity with import NT4 users and WRQ Reflections
    ... The WRQ Reflections program has a problem with the Kerberos authentication ... when you use it to access a Unix host. ... > in the userAccountControl field of the Active Directory. ...
    (microsoft.public.win2000.active_directory)
  • Re: kerberos 5.0 and apache 1.3.34
    ... My kerberos authentication i think is working now ... i say 'i think' because when i check my http header response this is ... I have apache 1.3.34 running on a ubuntu linux box. ...
    (comp.protocols.kerberos)
  • Re: Kerberos and Group membership
    ... Has anyone used Kerberos in Windows 2000\2003 server environment? ... "Active Directory" is basically a KDC and an LDAP server. ... doing Kerberos authentication to W2K or Windows 2003? ...
    (comp.protocols.kerberos)
  • Re: Windows authentication query
    ... trusts) cannot be authenticated by Kerberos due to the absence of a common ... > Kerberos Authentication works find with FQDN. ... a client on the internet would not be able to connect ... >: over an intranet). ...
    (microsoft.public.inetserver.iis.security)
  • RE: Activesync HTTP_500
    ... One of the main causes of the HTTP_500 error is if Kerberos authentication ... From a command prompt on the Exchange 2000 computer, ... WSS but its best not to have WSS installed on an Exchange Server. ...
    (microsoft.public.exchange.clients)