[27882] in Kerberos

home help back first fref pref prev next nref lref last post

gssapi auth, and multihomed multinamed hosts

daemon@ATHENA.MIT.EDU (Edward Irvine)
Wed Jun 6 05:38:05 2007

Mime-Version: 1.0 (Apple Message framework v752.3)
To: kerberos@mit.edu
Message-Id: <289E8CBB-BEE7-4F87-BDF9-69D80C519EF8@tpg.com.au>
From: Edward Irvine <eirvine@tpg.com.au>
Date: Wed, 6 Jun 2007 19:36:38 +1000
Content-Type: multipart/mixed; boundary="===============0334054417=="
Errors-To: kerberos-bounces@mit.edu


--===============0334054417==
Content-Type: multipart/signed; micalg=sha1; boundary=Apple-Mail-1-951935611;
	protocol="application/pkcs7-signature"


--Apple-Mail-1-951935611
Content-Transfer-Encoding: 7bit
Content-Type: text/plain;
	charset=US-ASCII;
	delsp=yes;
	format=flowed

Hi Folks,

I have a Solaris 10 server with two ip addresses: "fixed.example.com"  
and "float.example.com". The latter is an IP address that the server  
sometimes assumes as part of its role in a high-availability cluster.

I have compiled my own openssh+gssapi version of sshd, and have got  
ssh single-sign-on working fine (both windows secureCRT, a patched  
version of Putty, and also the unix openssh clients) . So far so good.

It is now time to get gssapi auth to working with the  
"float.example.com" address.

Can I expect to just add the keytab for "float.example.com" into /etc/ 
krb5.keytab and expect everything to be OK?

Thanks
Eddie




--Apple-Mail-1-951935611--

--===============0334054417==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============0334054417==--

home help back first fref pref prev next nref lref last post