[24941] in Kerberos

home help back first fref pref prev next nref lref last post

Re: kerberos service (httpd using mod_auth_kerb) in DMZ

daemon@ATHENA.MIT.EDU (FM)
Mon Nov 14 15:45:27 2005

Message-ID: <4378F73A.5090801@lexum.umontreal.ca>
Date: Mon, 14 Nov 2005 15:44:42 -0500
From: FM <dist-list@lexum.umontreal.ca>
MIME-Version: 1.0
To: Achim Grolms <kerberosml@grolmsnet.de>,
        Mailing List Kerberos <kerberos@mit.edu>
In-Reply-To: <200511142128.29981.kerberosml@grolmsnet.de>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Thank you, I'll use HTTP as service name
there a PXI firewall but for now all ports are open from the server to 
kerberos server and there is non nat.
Do I also need a princ host/... ? For now I just have the HTTP/


Achim Grolms wrote:

>On Monday 14 November 2005 20:43, you wrote:
>  
>
>>Thanks for the reply,
>>    
>>
>
>  
>
>>you can use http if you add tu http conf :  KrbServiceName  "http"
>>    
>>
>
>Yes, but you have to configure the Browser, too.
>Internet Exploder *always* sends "HTTP".
>That means "HTTP" is a de-facto standard if you
>don't want to exclude IE-Browsers from HTTP-Authentication.
>
>Have a look at 
><http://www.kerberosprotocols.org/index.php/Draft-brezak-spnego-http-03.txt>:
>
>"When the Kerberos Version 5 GSSAPI mechanism [RFC-1964] is being 
>used, the HTTP server will be using a principal name of the form of 
>"HTTP/".
>
>BTW: is there a HTTP-proxy between Client and kerberized HTTP-Server?
>
>Achim
>________________________________________________
>Kerberos mailing list           Kerberos@mit.edu
>https://mailman.mit.edu/mailman/listinfo/kerberos
>  
>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post