[27504] in Kerberos
Re: Solaris 10 sshd + GSSAPI - usernames limited to 8 or 9 chars?
daemon@ATHENA.MIT.EDU (Sam Hartman)
Tue Feb 27 17:48:29 2007
From: Sam Hartman <hartmans@mit.edu>
To: Edward Irvine at home <eirvine@tpg.com.au>
Date: Tue, 27 Feb 2007 17:47:54 -0500
In-Reply-To: <45E3D885.8030408@tpg.com.au> (Edward Irvine at home's message of
"Tue, 27 Feb 2007 18:06:45 +1100")
Message-ID: <tslzm6zi5et.fsf@cz.mit.edu>
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
>>>>> "Edward" == Edward Irvine at home <eirvine@tpg.com.au> writes:
Edward> Hi,
Edward> We are using the stock solaris 10 sshd daemon and a W2K3 KDC.
Edward> Everything works fine except for one of our users who has a ten
Edward> character username. The user with a long username fails to login from
Edward> a number of clients, such as another solaris 10 computer, and a
Edward> SecureCRT terminal emulator on windows.
Edward> When we switch sshd from stock solaris to an OpenSSH version that I've compiled and linked with MIT-Kerberos 1.5, the client can log in.
Edward> Has anyone seen anything like this? If anyone is interested I can post output from debug sessions.
Sounds like solaris is limiting the length of usernames in
krb5_kuserok (called internally from their gssapi library). That's
fixed in MIT Kerberos 1.5.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos