[27504] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Solaris 10 sshd + GSSAPI - usernames limited to 8 or 9 chars?

daemon@ATHENA.MIT.EDU (Sam Hartman)
Tue Feb 27 17:48:29 2007

From: Sam Hartman <hartmans@mit.edu>
To: Edward Irvine at home <eirvine@tpg.com.au>
Date: Tue, 27 Feb 2007 17:47:54 -0500
In-Reply-To: <45E3D885.8030408@tpg.com.au> (Edward Irvine at home's message of
	"Tue, 27 Feb 2007 18:06:45 +1100")
Message-ID: <tslzm6zi5et.fsf@cz.mit.edu>
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

>>>>> "Edward" == Edward Irvine at home <eirvine@tpg.com.au> writes:

    Edward> Hi,
    Edward> We are using the stock solaris 10 sshd daemon and a W2K3 KDC.

    Edward> Everything works fine except for one of our users who has a ten
    Edward> character username. The user with a long username fails to login from
    Edward> a number of clients, such as another solaris 10 computer, and a
    Edward> SecureCRT terminal emulator on windows.

    Edward> When we switch sshd from stock solaris to an OpenSSH version that I've compiled and linked with MIT-Kerberos 1.5, the client can log in.

    Edward> Has anyone seen anything like this? If anyone is interested I can post output from debug sessions.


Sounds like solaris is limiting the length of usernames in
krb5_kuserok (called internally from their gssapi library).  That's
fixed in MIT Kerberos 1.5.

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post