[24791] in Kerberos

home help back first fref pref prev next nref lref last post

Re: failed to authenticate using mod_auth_kerb for Apache

daemon@ATHENA.MIT.EDU (Siarhei Baidun)
Tue Oct 4 03:53:59 2005

Message-ID: <a665a890510040053y1ec46d97ne58f8b774af4118d@mail.gmail.com>
Date: Tue, 4 Oct 2005 09:53:01 +0200
From: Siarhei Baidun <siarheibaidun@gmail.com>
To: Markus Moeller <huaraz@moeller.plus.com>
In-Reply-To: <dhrvd0$amg$1@sea.gmane.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Disposition: inline
cc: kerberos@mit.edu
Reply-To: Siarhei Baidun <siarheibaidun@gmail.com>
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit

On 10/3/05, Markus Moeller <huaraz@moeller.plus.com> wrote:

> Can you describe what you have done ? When you always get a NTLM token it
> normally means that there is no key for this service in your kdc. Check
> that you don't use CNAMEs. Use kerbtray on your Windows machine to see
> which tickets are available for IE.

 Hi Markus,
You are right - I do not have the key for my web server in my KDC.
I have read Achim's manual and have discovered that I missed that point -
creation of service realm for my web server.
In my case it is HTTP/gvepl100.internal.epo.org@INTERNAL.EPO.ORG
With "klist.exe tickets" command I see the following tickets in cache on my
workstation (Win2000):

Server: krbtgt/INTERNAL.EPO.ORG@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/4/2005 22:28:03
Renew Time: 10/11/2005 9:28:03


Server: krbtgt/INTERNAL.EPO.ORG@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/4/2005 18:55:26
Renew Time: 10/11/2005 5:55:26


Server: ldap/GVW001.internal.epo.org/internal.epo.org@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/4/2005 18:55:26
Renew Time: 10/11/2005 5:55:26


Server: LDAP/GVW001.internal.epo.org@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/4/2005 18:55:26
Renew Time: 10/11/2005 5:55:26


Server: HOST/gvw001.internal.epo.org@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/4/2005 18:55:26
Renew Time: 10/11/2005 5:55:26


Server: ldap/GVW002.internal.epo.org/internal.epo.org@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/4/2005 18:55:26
Renew Time: 10/11/2005 5:55:26


Server: LDAP/GVW002.internal.epo.org@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/4/2005 18:55:26
Renew Time: 10/11/2005 5:55:26


Server: HOST/GVW010@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/3/2005 23:44:21
Renew Time: 10/10/2005 10:44:21


Server: HOST/GVW011@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/3/2005 23:44:21
Renew Time: 10/10/2005 10:44:21


Server: HOST/GVW001@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/3/2005 23:44:21
Renew Time: 10/10/2005 10:44:21


Server: HOST/GVW002@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/3/2005 23:44:21
Renew Time: 10/10/2005 10:44:21


Server: host/sb82058a.internal.epo.org@INTERNAL.EPO.ORG
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
End Time: 10/3/2005 23:44:21
Renew Time: 10/10/2005 10:44:21
 I guess I should have had a ticket for
HTTP/gvepl100.internal.epo.org@INTERNAL.EPO.ORG as well
 --
Thanks,
Siarhei Baidun
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post