krb5+Ubuntu (maverick, jaunty (LTS))+ssh

Thomas Schweikle tps at vr-web.de
Sat Nov 20 16:45:31 EST 2010


Am 20.11.2010 09:58, schrieb Brian Candler:
> On Fri, Nov 19, 2010 at 02:03:09PM +0100, Thomas Schweikle wrote:
>> I can log in from maverick to maverick machines. No problem.
>> kerberos does what it is expected to do.
>> 
>> I can't log in from any jaunty (10.04.1 LTS) machine to any other
>> machine using kerberos. I am handled a session key, but
>> authenticating against any of the jaunty-machines fails. ssh falls
>> back to password authentication.
> 
> Sorry to state the obvious, but have you set
> 
> Host *
> ...
>     GSSAPIAuthentication yes
> 
> in /etc/ssh/ssh_config ?

I've set it and it was automatically set by installing the packages.

> What does ssh -v <host> show when you try to connect?

Something about no GSSAPI environment. I'll post the whole thing
Tomorrow --- I'll need access to the systems.

>> The kerberos server on jaunty seems to work as expected, but the
>> client and GSSAPI seems badly broken.
> 
> 10.04.1 LTS isn't Jaunty, it's Lucid. "cat /etc/lsb-release" to see what you
> have.

Uhhhgg! Yes it's right. Mkixed up the names. My fault!

> I have a Lucid client which can quite happily kinit to Active Directory, and
> ssh to RedHat machines using its Kerberos ticket.

That's what is curious: kinit works on these machines! I'll get my
tgt, but connections do not work. Only 10.10 to 10.10 does what is
expected. 10.10 to 10.04.1 does not as 10.04.1 to 10.10 or 10.04.1.

-- 
Thomas



More information about the Kerberos mailing list