OpenSSH, Telnet, Windows Authentication and double-hops



We're looking for a solution to create a secure single-signon
deployment on a Windows network. The chain of connections looks like
this:

Client: Telnets through SSH Tunnel to -->
Server1: that runs our application locally and connects to --->
Server2: that serves up the database using SQL Server

We're hitting an issue when we reach the SQL Server machine. Logging
in to SQL Server, the network has deprecated our logon down to 'NT
AUTHORITY\ANONYMOUS LOGON' . The database kicks us out.

We've learned that this is commonly refered to as the "double-hop"
issue and is well known with web development. There are mechanisms in
IIS to set up delegation and impersonation and caching etc, to get
past this.

We want to continue using public/private key authentication for the
SSH. We've tried the -A switch when starting up the SSH tunnel with
no avail.

Is there anything that SSH can offer us so that we can maintain the
authentication ticket over the second hop?

.



Relevant Pages

  • Re: Win2003 Shares not Visible
    ... One would think that Network Places on the server for the domain ... White Paper available on the Microsoft anonymous ftp server: ... Windows Network on any of the computers on the LAN. ... The tree on the domain controller server shows MS Windows Network ...
    (microsoft.public.windows.server.networking)
  • Re: browse with root-rights
    ... I use my server as a printserver. ... to my testing machine. ... If have a problem with browsing the Windows network under samba. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Cant log in (new user)
    ... Red Hat Group was closest) and just installed it on a Dell PowerEdge ... I, being kinda stupid about this, tried to set it up first run to connect ... Like how to set up this server to see my windows network for starters ...
    (alt.os.linux.redhat)
  • Re: ASP 500 error with IIS (Class not registered)
    ... search the newsgroup list - the same way you found this ... > I type "localhost" on my web host server. ... >> Did you check with the experts in the IIS and/or ASP newsgroups? ... >> this clearly had nothing to do with a Windows Network - especially ...
    (microsoft.public.windowsxp.network_web)
  • Browsing the network
    ... Windows Network under Network places. ... server for this current workgroup is not currently available. ... all on the Windows 2000 domain controllers. ...
    (microsoft.public.windows.server.active_directory)