[24943] in Kerberos
Re: kerberos service (httpd using mod_auth_kerb) in DMZ
daemon@ATHENA.MIT.EDU (Achim Grolms)
Mon Nov 14 16:22:57 2005
From: Achim Grolms <kerberosml@grolmsnet.de>
To: kerberos@mit.edu
Date: Mon, 14 Nov 2005 22:21:33 +0100
In-Reply-To: <4378F73A.5090801@lexum.umontreal.ca>
MIME-Version: 1.0
Content-Type: text/plain;
charset="utf-8"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Message-Id: <200511142221.33648.kerberosml@grolmsnet.de>
Errors-To: kerberos-bounces@mit.edu
On Monday 14 November 2005 21:44, FM wrote:
> Thank you, I'll use HTTP as service name
> there a PXI firewall but for now all ports are open from the server to
> kerberos server and there is non nat.
OK, I asked for HTTP-protocol-level proxies.
> Do I also need a princ host/... ? For now I just have the HTTP/
You only need the HTTP/ principal.
Have you used
kvno + klist -e
"To verify if keytype, kvno and principalname match
each other on clientside and in keytabfile."
as described in my first email?
Have you added the
.dmz.lexum.pri KERBEROS.DOMAIN
entry as described in my first email?
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos