[24940] in Kerberos

home help back first fref pref prev next nref lref last post

Re: kerberos service (httpd using mod_auth_kerb) in DMZ

daemon@ATHENA.MIT.EDU (Achim Grolms)
Mon Nov 14 15:29:16 2005

From: Achim Grolms <kerberosml@grolmsnet.de>
To: kerberos@mit.edu
Date: Mon, 14 Nov 2005 21:28:29 +0100
In-Reply-To: <4378E8FC.1010105@lexum.umontreal.ca>
MIME-Version: 1.0
Content-Type: text/plain;
  charset="utf-8"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Message-Id: <200511142128.29981.kerberosml@grolmsnet.de>
Errors-To: kerberos-bounces@mit.edu

On Monday 14 November 2005 20:43, you wrote:
> Thanks for the reply,

> you can use http if you add tu http conf :  KrbServiceName  "http"

Yes, but you have to configure the Browser, too.
Internet Exploder *always* sends "HTTP".
That means "HTTP" is a de-facto standard if you
don't want to exclude IE-Browsers from HTTP-Authentication.

Have a look at 
<http://www.kerberosprotocols.org/index.php/Draft-brezak-spnego-http-03.txt>:

"When the Kerberos Version 5 GSSAPI mechanism [RFC-1964] is being 
used, the HTTP server will be using a principal name of the form of 
"HTTP/".

BTW: is there a HTTP-proxy between Client and kerberized HTTP-Server?

Achim
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post