MIT extracted keytab not compatible with Heimdal kinit client...

Dyer, Rodney rmdyer at uncc.edu
Mon Oct 17 15:36:18 EDT 2011


Hi again,

Sorry for the confusion.  We now have it working by a re-arrangement of the Heimdal client "kinit" arguments.  So it does work.  My error.

It appears however that the -v option does not work:
      krb5_get_kdc_cred: VALIDATE VALID TICKET

MIT KDC:  1.6.1
Heimdal client version: 1-5-100-930

Rodney


From: Dyer, Rodney
Sent: Monday, October 17, 2011 3:03 PM
To: kerberos at mit.edu
Subject: MIT extracted keytab not compatible with Heimdal kinit client...

Hi,

We are running a Linux / MIT kdc and have extracted a user keytab.  It appears that this keytab format is not compatible with a Heimdal client "kinit".  Is there a way to "convert" a MIT keytab format to what is needed for use by Heimdal?  Or the question should really be what is the correct way of dealing with a Heimdal client service script that needs automated "authentication" when our KDCs are all MIT based?

Thanks,

Rodney


Rodney M. Dyer
Operations and Systems (Specialist)
Mosaic Computing Group
William States Lee College of Engineering
University of North Carolina at Charlotte
Email: rmdyer_at_uncc.edu
Web: http://www.coe.uncc.edu/~rmdyer
Office:  Cameron Hall, Room 232





More information about the Kerberos mailing list