Subject: Re: SSH and Kerberos
To: Daniel Cox <dcox@microbits.com.au>
From: Roland Dowdeswell <elric@imrryr.org>
List: tech-security
Date: 10/04/2002 08:08:45
On 1033710694 seconds since the Beginning of the UNIX epoch
"Daniel Cox" wrote:
>

>NetBSD 1.6 also works properly as a workstation, ie. I
>can run kinit and then ssh to other hosts without having to
>enter a password.
>BUT I cant connect to the NetBSD host with ssh from other
>hosts - ssh did not have kerberos support compiled in for 1.5.2,
>I thought I would try again with 1.6.

OpenSSH recently couldn't do krb5 auth while PriviledgeSeparation
was turned on, so you could try turning the Priv Sep off for a
while and see if that is the issue.  This has recently been recitified
in OpenSSH, but I don't think that it quite made it into 1.6.

--
    Roland Dowdeswell                      http://www.Imrryr.ORG/~elric/