home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!dtix!darwin.sura.net!zaphod.mps.ohio-state.edu!sdd.hp.com!think.com!spdcc!dyer
- From: dyer@spdcc.com (Steve Dyer)
- Newsgroups: comp.protocols.kerberos
- Subject: Re: Kerberos' rlogin, and Thanks.
- Keywords: rlogin, setuid
- Message-ID: <1992Sep10.173849.7056@spdcc.com>
- Date: 10 Sep 92 17:38:49 GMT
- References: <1992Sep10.160402.16410@syl.dl.nec.com>
- Organization: S.P. Dyer Computer Consulting, Cambridge MA
- Lines: 22
-
- In article <1992Sep10.160402.16410@syl.dl.nec.com> yuan@syl.dl.nec.com (Ruixi Yuan) writes:
- >The kerberos' rlogin program is running now.
- >
- >However, there is a warning message:
- >
- > Warning: No Kerberos tickets obtained.
- >
- >displayed after the rlogin. Does this mean the rlogin session is not
- >authenticated?
-
- It means you don't have a Kerberos TGT which you can use on the host you
- logged into. You'd have to get a new one using "kinit" (unfortunately
- exposing your password over the net). In version 4, the ticket contains
- the single IP address from which it may be used, and therefore, tickets
- can't be forwarded to other hosts to be used there. In version 5, there
- is the capability to allow a list of addresses from which a ticket may be
- used or (if my memory serves me) an indication that the ticket may be used
- without regard to the host from which it's used.
-
- --
- Steve Dyer
- dyer@ursa-major.spdcc.com aka {ima,harvard,rayssd,linus,m2c}!spdcc!dyer
-