Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

The solution of this problem is trivial and is left as an exercise for the reader.


devel / comp.protocols.kerberos / Re: Help with replication

SubjectAuthor
o Re: Help with replicationRuss Allbery

1
Re: Help with replication

<mailman.90.1658172881.8148.kerberos@mit.edu>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=289&group=comp.protocols.kerberos#289

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: eagle@eyrie.org (Russ Allbery)
Newsgroups: comp.protocols.kerberos
Subject: Re: Help with replication
Date: Mon, 18 Jul 2022 12:34:16 -0700
Organization: The Eyrie
Lines: 23
Message-ID: <mailman.90.1658172881.8148.kerberos@mit.edu>
References: <b2a9fcb0ebfe2b7b37dc5f24d4626236@ca-zephyr.org>
<6755037f-8e8e-7886-44a8-31a83124c787@mit.edu>
<2096c771ad96df84cd2b8113011d7ea9@ca-zephyr.org>
<202207180403.26I43CgF030277@hedwig.cmf.nrl.navy.mil>
<2ec4e1247f558f3b27bd74b6f931a0d9@ca-zephyr.org>
<871quikyfb.fsf@hope.eyrie.org>
Mime-Version: 1.0
Content-Type: text/plain
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="21677"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux)
Cc: Ken Hornstein <kenh@cmf.nrl.navy.mil>, <kerberos@mit.edu>
To: Bill MacAllister <bill@ca-zephyr.org>
Authentication-Results: mit.edu;
dmarc=none (p=none dis=none) header.from=eyrie.org
Authentication-Results: mit.edu; arc=pass
ARC-Seal: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1658172880; cv=pass;
b=dqAy/sKnyMibB2nYMdIJb2f3en8ntJoD8LDH5fYe2fOYFeFfAL4AWQY4tB3X6GMNO9tpijj+mJMIg9CYdNxQiVoUJrWJCauRt8+fYLlh6205j/gCAjNCQCvLCXqCD9CclnW5t1KW4cUbldrIOEu02HxuGtegT8/XcaRyxPDfaUYY3uAJU1c50ZuBaf31e3irwTi4eNZNLFkeahqv0Y2TSO2TwOHomLoH9Md7zbTM+uUe4jNmphEPQvQW8avA/OEK/3bPX4tFTekPjg+0oolohga1fWKG2YxrMZS5KWZ5xbfK0Q9Xr3tU4yZKZbNVqgle+YJdFz2vhw2vv/xSNtYVoQ==
ARC-Message-Signature: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1658172880;
c=relaxed/relaxed; bh=Qxsk7JOYOCEyBQFLELX1VF1hIjmnqTAvaprxff5rS4E=;
h=From:Subject:Date:Message-ID:MIME-Version:Content-Type;
b=dWDMBiLht3FW8SGZEc4T1xBKqd4xIBlN6Ri1RJ1gD3epZDrsMpiR/NelxJRQfdz+SdeC6TKoz2PWu6fA4ddEhaH1HBuVC/X5bzeXT+HzemZwQ04F67lFakMJN3iZ8uknXVxUaMZBXbu7jDEuwli0J6hycY/J7RyHFNOUszFKBa8KZ1gKxou9m6RyGXlfy6kpAgWzSL25YuusKZyeckHPK3A/tJjUCoRnpi/QmtwKNKhEpXwBVxBC9q2KnXSVsEKoIsIaVRVTOqaK3b7td6Qk8SBBRcYh6XBs4DuGmKy/dyKKy6VBr7tazblikV4yKzvv9fk/O04PREYFIAGi3NtbXA==
ARC-Authentication-Results: i=2; mit.edu; dkim=pass (1024-bit key)
header.d=mitprod.onmicrosoft.com header.i=@mitprod.onmicrosoft.com
header.b=UyaO3BpF; arc=pass
Authentication-Results: mit.edu;
dkim=pass (1024-bit key) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.b=UyaO3BpF
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=HgghLY4QG3fNowHn1UNLBeHvj5YOfFFR+MlguZixhItK+G7HqMdsBgNaPVISAvQAzslcSC2o5o4OduuipQtNyxOx1SQPD55FV0IhVFCnEu0WA+uWJe41lGVVZyQx/jdCYfBralHYJrPFM4PpD8/As3fA1M0oDUG64T+oqfn5bsmW+OjExsVSTySVO2N4picaitGItNo3xVs4Dd/cWJfqhffIg8E+3JXODIT4s8id48JfmaB8nH6SRaeMWkbDRw5MagWqapH6woeD0GfuOnlE1zQrzUROadloYZ1pma9pRRKLxOso1ARD8eL9o9y/WlFQbrONrYmdV1yC13AvDXSvJQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=Qxsk7JOYOCEyBQFLELX1VF1hIjmnqTAvaprxff5rS4E=;
b=TPRhmI9lxCfXRMXjLyLGfSqjnrrm7CyOlXtCdifB+40Qw7wkIaYUxk0/cuCLQrA9eNl0ibnU7h4MigBzZ11O0Gt2nUU1+DTCH0Z1oR7BkjNTlmtL8LecI53uurHp3xVVfgRvfUcHI8ocaziAkXkYyz05N180xK0D2yBqHPjkYMOhnCMJN2KqOqbRE23E7RvS27uBmDN616hatpWwQJnJ/FrL20MUtHjN/eRiMcH29OzAuJxnF+C0I9/b51/MiUWJBEqDp4zSJ4Li9q5cGyykX4xXflm0FTPy4nxPE08p/G8Wv0PLWFu7hPTgLvJr2hJ0V30Qv9dqhRL/uVJ6orJZmg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
166.84.7.159) smtp.rcpttodomain=mit.edu smtp.mailfrom=eyrie.org;
dmarc=bestguesspass action=none header.from=eyrie.org; dkim=none (message not
signed); arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=Qxsk7JOYOCEyBQFLELX1VF1hIjmnqTAvaprxff5rS4E=;
b=UyaO3BpFzFV2IgO36DaBotVYUTA11qrElpRh9nWnwp04fTFUS3BSl3fbCgDfbX4oFcd/A6oXyNhgULYEk8nWMWd93rKe0H0BaZs7Y1yVEofU6Lkc0Yo9R9w87pLQi2Ll6P2+6RJPh6MU8wjYEY3nHBlUdcZhlAJ7rc3PmwlbvvU=
Authentication-Results: spf=pass (sender IP is 166.84.7.159)
smtp.mailfrom=eyrie.org; dkim=none (message not signed)
header.d=none;dmarc=bestguesspass action=none header.from=eyrie.org;
Received-SPF: Pass (protection.outlook.com: domain of eyrie.org designates
166.84.7.159 as permitted sender) receiver=protection.outlook.com;
client-ip=166.84.7.159; helo=haven.eyrie.org; pr=C
In-Reply-To: <2ec4e1247f558f3b27bd74b6f931a0d9@ca-zephyr.org> (Bill
MacAllister's message of "Mon, 18 Jul 2022 10:47:09 -0700")
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: f333ce41-6111-4824-8704-08da68f48244
X-MS-TrafficTypeDiagnostic: DM6PR01MB4617:EE_
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 6BC9AatpyBdV1c9r+w+AHdxkZpMORIj55zguakYiQSded4pbVOvEEJo6RoZZEYu2y3YQETXSxRBac+UrzNYM3P0obI8aL1Q7gOPxmTbjA+0EfSTAvsXG2Jj5k2FG/GU7TK1Ed1Xt6xFQbnev3+Dh7XPG+bCXQ2cOTl+Bt3TCG7Bxfb7TvXx+FT/yDqN2yIqOq9prTR+R0rC8nLQbyUDz50HpZfVJ7sQFJ5lHX9+yWE2MiaRUBzuNN2xD+Db4m2d+5W/Vux1uEx6TaOawO6YtSigftT6awihjAZkzGyBqt+oZlNricS7fff5t1xE4wRUHLRA4zNaX7FaIPNtjPZDf9wrQ2DB6KeQRsNDUrxpkX6m/nYBsUEjFV4CTwMIMkVN427ryoKSG+2zpLEDvPMDhliSnWn5FOWR6vB78rFD7bo9tIeYQAG2yx7qDGZ9BqJd/gLaL4xKDfmUzSBzwjJavVkM7BNIk2xCix4kAsnW/93O0hves+OeJmc5U2uTtFKS1EuflY1n44ApXOu6WNf+Sqj/Bq3NLdxtOtLqRfuvpC7vN1Yhxn4BXViZBRcmcORbmLjBfSG+U1r2Ml4VAoYT+p3omCI80IXztFXZFOfJKQ6atN8AbUEFaBAm7Rt9mecQEAEOcibXHjUR5MofzVBIOSC/R3sT+45SdY6rnnLeEAeOqzoj4yFxL0XUgfDyJLHIiWVtPNrLPkrXdz+cbDt1Xd7726E9+imdHvpgIg1xInYNZKufiCSBHb7w27236lx13
X-Forefront-Antispam-Report: CIP:166.84.7.159; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:haven.eyrie.org; PTR:haven.eyrie.org; CAT:NONE;
SFS:(13230016)(4636009)(346002)(136003)(376002)(396003)(39860400002)(356005)(316002)(7596003)(42186006)(786003)(7636003)(83380400001)(426003)(336012)(2906002)(498600001)(5660300002)(7116003)(70586007)(68406010)(8676002)(4326008)(6266002)(26005)(6862004)(86362001)(36916002)(3480700007);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 18 Jul 2022 19:34:19.1778 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: f333ce41-6111-4824-8704-08da68f48244
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: DM6NAM11FT015.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR01MB4617
X-OriginatorOrg: mitprod.onmicrosoft.com
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <871quikyfb.fsf@hope.eyrie.org>
X-Mailman-Original-References: <b2a9fcb0ebfe2b7b37dc5f24d4626236@ca-zephyr.org>
<6755037f-8e8e-7886-44a8-31a83124c787@mit.edu>
<2096c771ad96df84cd2b8113011d7ea9@ca-zephyr.org>
<202207180403.26I43CgF030277@hedwig.cmf.nrl.navy.mil>
<2ec4e1247f558f3b27bd74b6f931a0d9@ca-zephyr.org>
 by: Russ Allbery - Mon, 18 Jul 2022 19:34 UTC

Bill MacAllister <bill@ca-zephyr.org> writes:

> The KDC logs revealed that indeed the principal did not exist. I had
> updated the krb5.conf to use a cname for the admin principal and kpropd
> is using the entry in the krb5.conf without canonicalization. I changed
> the krb5.conf file to use host names that matched the principals that I
> had created. That along with making sure kadm5.acl and kpropd.acl had
> the appropriate entries solved my problem. Thanks for the pointer.
> (Who would have thought to look in the logs? Certainly now me.)

Is this the thing where kpropd always uses exactly the hostname you have
listed and doesn't do any DNS canonicalization? If so, I've run into that
before and I think I just put keys for all of the principals that could be
formed from all the possible replica names in the keytab file for the
replicas and my recollection is that worked, although it's been a few
years.

> I guess one what would be to create principals for the cnames.

Right, yeah, that. Similar to what we had to do with LDAP servers.

--
Russ Allbery (eagle@eyrie.org) <https://www.eyrie.org/~eagle/>


devel / comp.protocols.kerberos / Re: Help with replication

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor