Click here to get back home

Delegation using GSSAPI in Microsoft Kerberose based realm

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Delegation using GSSAPI in Microsoft Kerberose based realm ambekar@gmail.com 11-26-2005
Posted by ambekar@gmail.com on November 26, 2005, 7:17 am
Please log in for more thread options
Hello,
I am having Microsoft W2K server based kerberos realm. I have
configured my UNIX machines to this realm. I am able to run most of the
MIT kerberos utilities (klist, kinit, ...). I've written sample
application and sample service (service principal is created in AD as
per interoperability guide from Microsoft). I am able to do kerberos
authentication in this setup. I am using GSSAPI (gss_init_sec_context
on client side and gss_accept_sec_context on service). My final
objective is to make server application impersonate the client. For
this I've created a forwardable and proxyable TGT for the user of
client application. In client application, I am passing
GSS_C_DELEG_FLAG to gss_initi_sec_context. Although,
gss_init_sec_context does not throw any error, the return flag
(indicating the flags used for initialization of security context) does
not contain this flag. As a result, I am not getting any delegated
creds in gss_accept_sec_context. I am using Red Hat Linux and MIT
kerberos. Tickets are obtained using MIT kerberos kinit utility.
Has any one faced similar problem. Is there any known interoperability
issue?
Thanks in advance,
Ashwin


Posted by ambekar@gmail.com on November 27, 2005, 9:56 pm
Please log in for more thread options
Issuse was
1) I was not using address less ticketskkkkk
2) I was using krb5-devel-1.2.7-19, which doesn't seem to work. With
latest release, init_sec_context seems to be working properly.

-Ashwin


Similar ThreadsPosted
Windows 2008 AD cross realm trust with MIT Kerberos realm August 1, 2008, 10:31 am
kerberos realm trust: how to find the realm for a service? August 4, 2005, 7:50 pm
SPNEGO / SSPI / SSO / GSSAPI Questions September 12, 2006, 11:11 am
trusting a non-Windows Kerberos Realm March 27, 2008, 11:28 am
EFS and Delegation June 8, 2005, 10:30 am
OU delegation July 26, 2007, 12:08 pm
Delegation problem January 22, 2006, 1:43 pm
Kerberos delegation December 7, 2006, 12:53 pm
Kerberos/ASP/Delegation/W2K3 July 19, 2005, 2:24 pm
RODC 2008 account and delegation April 17, 2008, 3:50 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap