Re: Realm in Username



On 2007-03-20 08:34:00 +0100, "Miguel Sanders" <miguelsanders@xxxxxxxxxx> said:

Dear

When using a Kerberized version of telnet, I can provide the realm (so
user@REALM) of the user when logging in. However when using SSH, this
doesn't seem to work. Is there any way to overcome this? I am running
AIX.

Is the dns domain coincident with the realm name? Is the ssh server fully kerberos aware and having the proper keytab file? Last, can you post the output for

$ ssh -vvv -l username server

and --- if you can --- the corresponding sshd debug output and configuration for both server and client? There is little information here, sorry.

--
Sensei <senseiwa at Apple's mac dot com>

Three things are certain
Death, taxes, and lost data
Guess which has occurred. (Computer's Haiku)

.



Relevant Pages

  • Re: Authenticating Windows 2003 users to a central LDAP
    ... We have two KDC servers with realm nyu.edu. ... of those kerberos servers. ... Thus a user account in the AD will be associated with a Kerberos ... We are running a Windows 2003 R2 server whose domain ...
    (comp.protocols.kerberos)
  • Re: No username prompt SSHD
    ... $ ssh -l login serveur ... (if omitted login is client side login) ... I have sshd set up on my server, and all I want is just username/password ... # Kerberos options ...
    (SSH)
  • Re: No username prompt SSHD
    ... No it is the server side because when you just to do a " ssh server". ... # HostKey for protocol version 1 ... # Kerberos options ...
    (SSH)
  • Re: Kerberos + SSH question
    ... Nod> I've currently got a Heimdal KDC setup for testing. ... Nod> testing network, I can succesfully get tickets via kinit, and ssh ... Nod> (using SecureCRT with Kerberos support) but only when I use kinit ... Nod> ssh server on the machine I'm accessing to carry out the kerberos ...
    (comp.protocols.kerberos)
  • SSH version 2 "Server refused our key" error
    ... I really need help on how to configure correctly in order to use SSH ... "Server refused our key" error. ... # To disable tunneled clear text passwords, ... # Kerberos TGT Passing does only work with the AFS kaserver ...
    (SSH)