To: | krb5-bugs@mit.edu |
RT-Send-CC: | rafael@mail.ufsm.br |
Subject: | Hierarchical cross-realm seems broken |
From: | Sam Hartman <hartmans@MIT.EDU> |
Date: | Sun, 27 Oct 2002 15:24:56 -0500 |
The behavior described here should work as I understand the code. I'm able to reproduce in a test setup as follows:
* FOO.SUCHDAMAGE.ORG shares a key with SUCHDAMAGE.ORG
* I get FOO.SUCHDAMAGE.ORG tickets and ask for tickets in the Athena realm.
* Since SUCHDAMAGE.ORG and ATHENA share tickets, and since the step
from foo.suchdamage.org to suchdamage.org is hierarchical, this
should be allowed.
However here is what I see:
hartmans@tir-na-nogth:bar-test(1414)> ./kinit hartmans
Password for hartmans@FOO.SUCHDAMAGE.ORG:
hartmans@tir-na-nogth:bar-test(1415)> ./kvno host/luminous.mit.edu@ATHENA.MIT.EDU
host/luminous.mit.edu@ATHENA.MIT.EDU: Invalid message type while getting credentials
hartmans@tir-na-nogth:bar-test(1416)> ./kvno host/luminous.mit.edu@ATHENA.MIT.EDU
host/luminous.mit.edu@ATHENA.MIT.EDU: KDC policy rejects request while getting credentials
hartmans@tir-na-nogth:bar-test(1417)>
So, I think this is broken.
Return-Path: <kerberos-admin@MIT.EDU>
Received: from solipsist-nation ([unix socket])
by solipsist-nation (Cyrus v2.1.5-Debian2.1.5-1) with LMTP; Fri, 25 Oct
2002 16:47:32 -0400
X-Sieve: CMU Sieve 2.2
Return-Path: <kerberos-admin@MIT.EDU>
Received: from pacific-carrier-annex.mit.edu (PACIFIC-CARRIER-ANNEX.MIT.EDU
[18.7.21.83])
by suchdamage.org (Postfix) with ESMTP id 853F41315E
for <hartmans@suchdamage.org>; Fri, 25 Oct 2002 16:47:32 -0400 (EDT)
Received: from pch.mit.edu (PCH.MIT.EDU [18.7.21.90])
by pacific-carrier-annex.mit.edu (8.9.2/8.9.2) with ESMTP id QAA26990;
Fri, 25 Oct 2002 16:47:26 -0400 (EDT)
Received: from pch.mit.edu (localhost [127.0.0.1])
by pch.mit.edu (8.9.3+Sun/8.9.3) with ESMTP id QAA04772;
Fri, 25 Oct 2002 16:47:05 -0400 (EDT)
Received: from pacific-carrier-annex.mit.edu (PACIFIC-CARRIER-ANNEX.MIT.EDU
[18.7.21.83])
by pch.mit.edu (8.9.3+Sun/8.9.3) with ESMTP id QAA04765
for <kerberos@PCH.mit.edu>; Fri, 25 Oct 2002 16:46:47 -0400 (EDT)
Received: from hostmail.ufsm.br (hostmail.ufsm.br [200.18.33.122])
by pacific-carrier-annex.mit.edu (8.9.2/8.9.2) with ESMTP id QAA26549
for <kerberos@mit.edu>; Fri, 25 Oct 2002 16:46:33 -0400 (EDT)
Received: from www-data by hostmail.ufsm.br with local (Exim 3.35 #1)
id 185BMM-0003F2-00
for kerberos@mit.edu; Fri, 25 Oct 2002 17:47:10 -0300
To: kerberos@mit.edu
Subject: Problem with Cross REALM authentication hierarchly
From: Rafael da Rosa Righi <rafael@mail.ufsm.br>
Message-Id: <E185BMM-0003F2-00@hostmail.ufsm.br>
Sender: kerberos-admin@MIT.EDU
Errors-To: kerberos-admin@MIT.EDU
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.0
Precedence: bulk
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Post: <mailto:kerberos@mit.edu>
List-Subscribe: <http://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <http://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
Date: Fri, 25 Oct 2002 17:47:10 -0300
X-Spam-Status: No, hits=0.6 required=5.0 tests=PORN_10,LINES_OF_YELLING
version=2.20
X-Spam-Level:
MIME-Version: 1.0
Hello all,
I tried to configure a cross realm auth. with 3 REALMS .
I am going to show my problem with examples:
First REALM: XXXX.BR
Second REALM: YYY.XXXX.BR
Third REALM: ZZZ.XXXX.BR
XXXX.BR
/ \
/ \
YYY.XXX.BR ZZZ.XXXX.BR
This is the same organization of DNS.
I constructed cross realm authentication between XXXX.BR and
YYY.XXXX.BR and this is OK. I constructed too, another cross realm
authentication between XXXX.BR and ZZZ.XXXX.BR and this is OK.
The problem is:
When I try an authentication between YYY.XXXX.BR and ZZZ.XXXX.BR I
recept a error. I configured the .k5login, krb5.keytab, the enctypes, the
enc-salt, key version.
************************************************************************************
KDC register: (Before I get TGT ticket for rafaelr@YYY.XXXX.BR)
Oct 25 17:05:53 r.ufm.br krb5kdc[30473](info): TGS_REQ (3 etypes {16 3 1})
200.xx.xx.xx ( 88): ISSUE: authtime 1035572747, etypes {rep=16 tkt=16
ses=16}, rafaelr@YYY.XXXX.BR for krbtgt /ZZZ.XXXX.BR@XXXX.BR
Oct 25 17:05:53 r.ufsm.br krb5kdc[30473](info): bad realm transit path from
'rafaelr@YYY.XXXX.BR to 'host/rmachine.AT.ZZZ.XXXX.BR@ZZZ.XXXX.BR via
'XXXX.BR'
Oct 25 17:05:53 re.ufm.br krb5kdc[30473](info): TGS_REQ (3 etypes {16 3 1})
200.xx.xx.xx(88): BAD_TRANSIT: authtime 1035572747, rafaelr@YYY.XXXX.BR for
host/ machine.AT.ZZZ.XXXX.BR@ZZZ.XXXX.BR KDC policy rejects request
****************************************************************************************
Thank you for help.
Rafael Righi. Brazil
Received: from solipsist-nation ([unix socket])
by solipsist-nation (Cyrus v2.1.5-Debian2.1.5-1) with LMTP; Fri, 25 Oct
2002 16:47:32 -0400
X-Sieve: CMU Sieve 2.2
Return-Path: <kerberos-admin@MIT.EDU>
Received: from pacific-carrier-annex.mit.edu (PACIFIC-CARRIER-ANNEX.MIT.EDU
[18.7.21.83])
by suchdamage.org (Postfix) with ESMTP id 853F41315E
for <hartmans@suchdamage.org>; Fri, 25 Oct 2002 16:47:32 -0400 (EDT)
Received: from pch.mit.edu (PCH.MIT.EDU [18.7.21.90])
by pacific-carrier-annex.mit.edu (8.9.2/8.9.2) with ESMTP id QAA26990;
Fri, 25 Oct 2002 16:47:26 -0400 (EDT)
Received: from pch.mit.edu (localhost [127.0.0.1])
by pch.mit.edu (8.9.3+Sun/8.9.3) with ESMTP id QAA04772;
Fri, 25 Oct 2002 16:47:05 -0400 (EDT)
Received: from pacific-carrier-annex.mit.edu (PACIFIC-CARRIER-ANNEX.MIT.EDU
[18.7.21.83])
by pch.mit.edu (8.9.3+Sun/8.9.3) with ESMTP id QAA04765
for <kerberos@PCH.mit.edu>; Fri, 25 Oct 2002 16:46:47 -0400 (EDT)
Received: from hostmail.ufsm.br (hostmail.ufsm.br [200.18.33.122])
by pacific-carrier-annex.mit.edu (8.9.2/8.9.2) with ESMTP id QAA26549
for <kerberos@mit.edu>; Fri, 25 Oct 2002 16:46:33 -0400 (EDT)
Received: from www-data by hostmail.ufsm.br with local (Exim 3.35 #1)
id 185BMM-0003F2-00
for kerberos@mit.edu; Fri, 25 Oct 2002 17:47:10 -0300
To: kerberos@mit.edu
Subject: Problem with Cross REALM authentication hierarchly
From: Rafael da Rosa Righi <rafael@mail.ufsm.br>
Message-Id: <E185BMM-0003F2-00@hostmail.ufsm.br>
Sender: kerberos-admin@MIT.EDU
Errors-To: kerberos-admin@MIT.EDU
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.0
Precedence: bulk
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Post: <mailto:kerberos@mit.edu>
List-Subscribe: <http://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <http://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
Date: Fri, 25 Oct 2002 17:47:10 -0300
X-Spam-Status: No, hits=0.6 required=5.0 tests=PORN_10,LINES_OF_YELLING
version=2.20
X-Spam-Level:
MIME-Version: 1.0
Hello all,
I tried to configure a cross realm auth. with 3 REALMS .
I am going to show my problem with examples:
First REALM: XXXX.BR
Second REALM: YYY.XXXX.BR
Third REALM: ZZZ.XXXX.BR
XXXX.BR
/ \
/ \
YYY.XXX.BR ZZZ.XXXX.BR
This is the same organization of DNS.
I constructed cross realm authentication between XXXX.BR and
YYY.XXXX.BR and this is OK. I constructed too, another cross realm
authentication between XXXX.BR and ZZZ.XXXX.BR and this is OK.
The problem is:
When I try an authentication between YYY.XXXX.BR and ZZZ.XXXX.BR I
recept a error. I configured the .k5login, krb5.keytab, the enctypes, the
enc-salt, key version.
************************************************************************************
KDC register: (Before I get TGT ticket for rafaelr@YYY.XXXX.BR)
Oct 25 17:05:53 r.ufm.br krb5kdc[30473](info): TGS_REQ (3 etypes {16 3 1})
200.xx.xx.xx ( 88): ISSUE: authtime 1035572747, etypes {rep=16 tkt=16
ses=16}, rafaelr@YYY.XXXX.BR for krbtgt /ZZZ.XXXX.BR@XXXX.BR
Oct 25 17:05:53 r.ufsm.br krb5kdc[30473](info): bad realm transit path from
'rafaelr@YYY.XXXX.BR to 'host/rmachine.AT.ZZZ.XXXX.BR@ZZZ.XXXX.BR via
'XXXX.BR'
Oct 25 17:05:53 re.ufm.br krb5kdc[30473](info): TGS_REQ (3 etypes {16 3 1})
200.xx.xx.xx(88): BAD_TRANSIT: authtime 1035572747, rafaelr@YYY.XXXX.BR for
host/ machine.AT.ZZZ.XXXX.BR@ZZZ.XXXX.BR KDC policy rejects request
****************************************************************************************
Thank you for help.
Rafael Righi. Brazil
Show quoted text
________________________________________________
Kerberos mailing list Kerberos@mit.edu
http://mailman.mit.edu/mailman/listinfo/kerberos
Kerberos mailing list Kerberos@mit.edu
http://mailman.mit.edu/mailman/listinfo/kerberos