Kerberos tickets, SSH public key auth, AFS tokens

Douglas E. Engert deengert at anl.gov
Fri Dec 18 14:06:39 EST 2009



Jeff Blaine wrote:
>> But this won't work with ssh public keys. If its winCVS
>> on Windows you are interested in, it too can support GSSAPI.
> 
> Doug, I'd like to hear about WinCVS + some SSH using
> GSSAPI if that's what you're referring to (using :gserver:
> isn't going to cut it as far as I can see, since there will
> be no tokens).


We use the :gserver: since the we did not need the forwarded tickets,
and it was easier, but we have in the past use PuTTY with GSSAPI,
and have used PuTTY with Eclipse.

Google for wincvs ext putty

The WinCVS page has:
http://www.tortoisecvs.org/faq.html#puttysessions

The secret is to have a PuTTY session predefined with all the SSH Auth
options including the GSSAPI and delegate GSSAPI options.

The which PuTTY has GSSAPI:

  Quest has one that uses SSPI. http://rc.quest.com/topics/putty/

  The PuTTY developers have SSPI in their SVN version:
  svn://svn.tartarus.org/sgt/putty.

  Secure-Endpoints has or had one that uses the MIT gssapi libs.

  http://v_t_m.sweb.cz/#putty has PuTTY mods to 5.8 can can use
  either SSPI of GSSAPI using MIT Kerberos libs.


> 
> Does anyone know of a Cygwin OpenSSH that supports GSS-API?
> 
> 

-- 

  Douglas E. Engert  <DEEngert at anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444



More information about the Kerberos mailing list