Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Row, row, row your bits, gently down the stream...


devel / comp.protocols.kerberos / Is there a way to steer kinit to a specific kdc?

SubjectAuthor
o Is there a way to steer kinit to a specific kdc?Dan Mahoney (Gushi)

1
Is there a way to steer kinit to a specific kdc?

<mailman.54.1680670417.1964.kerberos@mit.edu>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=337&group=comp.protocols.kerberos#337

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: danm@prime.gushi.org (Dan Mahoney (Gushi))
Newsgroups: comp.protocols.kerberos
Subject: Is there a way to steer kinit to a specific kdc?
Date: Tue, 4 Apr 2023 21:52:58 -0700 (PDT)
Organization: TNet Consulting
Lines: 32
Message-ID: <mailman.54.1680670417.1964.kerberos@mit.edu>
References: <4c59d692-3d8a-553-20e8-388e7446f37@prime.gushi.org>
Mime-Version: 1.0
Content-Type: text/plain; format=flowed; charset=US-ASCII
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="11424"; mail-complaints-to="newsmaster@tnetconsulting.net"
To: kerberos@mit.edu
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=c2epv4X2xh7KB7iIA4jJFVwjRRYclktsmofMMq3dGrtR520UX13TzI20YRJCFk396sxd0lKrkBtOYnLpw2/0x3t0vuh7QeRrcJcfcnIGzNZJ4/KW0wLJjYhJfvQn3DKmZUEpeOX7mP5HBvI9Gm5DHWwZ2c8krHV3BZQpnx5gp+h4rp0zWMTxq+kafxA5qtfTALI4HvM/7/6TSwJlIQyO0Y4ahSai7PApX8x06A3M4fNMBxTJmDRceGpA7lFzqh3DKios166t9uXtCw7fTWb7DIBTceBQbYCoOu9puUKgMWsky7sZyscKmtkKetSz5mQZc69YufCqCFD68/Cv/crNog==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=kW5DeBwsCBoE6neuXkabbkkl6Cnmh3ozyE9gI2Of/GA=;
b=anrP/5Dsdx4A8L+mBOByTAoZWlHGxD22pWkEqeJBkQDE4Ae0KrY5bmzbHQm/eBtwCTi538Ep3yd2/sIiQ7okq38FgOVusuujQuTq/D6pey7SKwVoGJ0fWV7POJ3GF9dNvd/EzBJxW9U/o5nkJ/Q8hLakQEJogzDgm92UYxnvX6wJWlZ9ksNwkfoEyjUxONdZwkqne/GKrpNWiKplMqYLebI5gYrc/XMAgmhpUdjDcMCt4gDcP7Yc/wxXLWH++DELah4dvo3LSzmPIjPn7Y2GDCe8TnsxvkJW30Y+8pThB6SpunmxeE+pLULSJ1dvrK0zbsdPthcnulBnFmmjIa3E3w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
149.20.68.142) smtp.rcpttodomain=mit.edu smtp.mailfrom=prime.gushi.org;
dmarc=pass (p=none sp=none pct=100) action=none header.from=prime.gushi.org;
dkim=pass (signature was verified) header.d=gushi.org; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=kW5DeBwsCBoE6neuXkabbkkl6Cnmh3ozyE9gI2Of/GA=;
b=lXhc9JAP9qutu9itv1xk7qOEZSj78EP0A5DDFXDkbVkuDWD4Z2BNp4JMCGkXoDzj958pKlagHN9nCeYX6qePIZFuxzxGcF8EQ5RPZltSO0A+PvpfFh5QtSeDvrCnAUP0eMlpVYBAnjiN6aSyqdYtSmfNLUbRvN82dzUjgv8mREA=
Authentication-Results: spf=pass (sender IP is 149.20.68.142)
smtp.mailfrom=prime.gushi.org; dkim=pass (signature was verified)
header.d=gushi.org;dmarc=pass action=none header.from=prime.gushi.org;
Received-SPF: Pass (protection.outlook.com: domain of prime.gushi.org
designates 149.20.68.142 as permitted sender)
receiver=protection.outlook.com; client-ip=149.20.68.142;
helo=prime.gushi.org; pr=C
DKIM-Filter: OpenDKIM Filter v2.10.3 prime.gushi.org 3354qxGW027159
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gushi.org;
s=prime2014; t=1680670380;
bh=kW5DeBwsCBoE6neuXkabbkkl6Cnmh3ozyE9gI2Of/GA=;
h=Date:From:To:Subject;
z=Date:=20Tue,=204=20Apr=202023=2021:52:58=20-0700=20(PDT)|From:=20
"Dan=20Mahoney=20(Gushi)"=20<danm@prime.gushi.org>|To:=20kerberos@
mit.edu|Subject:=20Is=20there=20a=20way=20to=20steer=20kinit=20to=
20a=20specific=20kdc?;
b=Iknl/HxEoCS2314RQKtW7UMjvwIMVR7uou4v0iyKcnZRYq0LsoV93jTs8u2Z0AZWQ
e4JnPROtdIn0vhUvC0V5U9SiGQahFGheL3XHt4MQG+9BwpAtiguyLmhc0d52kYGaIR
wR2Hyjw3yVan9rmyJ0jKqa464Um0JihyzgRaZmEKb1PWsU/mRhTmfEIIv8cHo9EEn8
YHnVbXEhV0gEHDp4Gbjet5xXKISS9gwURSLY/KqcljC6Z/uWhlPWcYLMZI4b/XD+ir
JqpR5RhDJkNn8lJ+fg8mrMwcW42IFOIdIRQl4AwkyMBbJAmAyrXfejOAZkchNbcK0c
Xr8vDwbGgomUA==
X-OpenPGP-Key-ID: 0x624BB249
X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4
(prime.gushi.org [0.0.0.0]); Wed, 05 Apr 2023 04:53:08 +0000 (UTC)
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: BN8NAM11FT024:EE_|BL0PR01MB4275:EE_
X-MS-Office365-Filtering-Correlation-Id: fca5fa6c-c854-4b9d-a88a-08db3591a7a3
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: MGT56PFye59nZpBqbME+sQhAbr9wQwL/xD46raIlkOgvvPqNlgmQztuAmQ7YTGpkEFaFdjuE7nU94aEra3MAYPJuJpxcbtnWnI3Mas6MgRs5sGcmkpyrVFbpuhqNXZd/gbeu0YQt8miVPbT8s2v4yKIxU1IgVY2+h421+NU59nPsTCxsz5pGlNeCQRMrCkp5eEjwtpslfhCjuKf7oZF6E4uH/cP/hS/+8qb81Ho4xkFfPWtCSG0J9ZvryT091nLHHj1uApOGQ8TFSJnvKiPqqg36ym4pKQWAuJodUDirXGG5AP+oTdd5HTVcWvcbH8DNKqOH9ayeAlU1hQHOck3uBAUqIATp05GGwZHxZlVUlTCYTkZ/Ibj9zvliGdJNmb66pHGYKq/Y3YEP0S2hS0pk2z9ThEyYp2ABaOoxO2VvnD8VGZA0rAETW3rmtfV1/goKs30CULlHsLdPrrUZ4eYUF/SLIF0jhux9uodu6yS0aKdZbjApum+ppcdEUfu9lfsD1HjeFMieCLkUzJ3kqRDQCGmF4OQAmca7YJEWd/pDiraqhs2k5gP0zhzOd23rqCy+vaV58bEG2upYAGT+wiOHJhM7EkrNZME5QuMrgcIlAbySG+C95HwhO1nRqojzLBhkrLH1Z5IcCTRfnx+bh3n3vw==
X-Forefront-Antispam-Report: CIP:149.20.68.142; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:prime.gushi.org; PTR:prime.gushi.org; CAT:NONE;
SFS:(13230028)(4636009)(39860400002)(136003)(376002)(346002)(396003)(451199021)(34206002)(5660300002)(2906002)(336012)(966005)(86362001)(83380400001)(26005)(42186006)(498600001)(786003)(7636003)(316002)(426003)(45080400002)(4744005)(2616005)(8676002)(7596003)(356005)(68406010)(70586007)(84970400001)(43043002);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 05 Apr 2023 04:53:09.9139 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: fca5fa6c-c854-4b9d-a88a-08db3591a7a3
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: BN8NAM11FT024.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL0PR01MB4275
X-OriginatorOrg: mitprod.onmicrosoft.com
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <4c59d692-3d8a-553-20e8-388e7446f37@prime.gushi.org>
 by: Dan Mahoney (Gushi) - Wed, 5 Apr 2023 04:52 UTC

Hey there all.

I'm writing up a Nagios check to make sure our KDC's are answering, and
rather than just sending a tcp/udp probe to port 88, I want to actually
get a ticket, probably by using a keytab and an otherwise unprivileged
user.

I'm reading about one such plugin, here:
https://exchange.nagios.org/directory/Plugins/Security/check_kdc/details
and it looks *okay*. I'm not super invested in reinventing the wheel.
It's a fairly simple shell script.

It *looks* like, in order to check basically fakes this out with a
krb5.conf that only includes a single KDC (the one being tested).

Is that really the best way to go about it?

Can neither mit kinit nor the heimdal one supplied with BSD systems by
default, not just be forced to a single KDC?

-Dan

--

--------Dan Mahoney--------
Techie, Sysadmin, WebGeek
Gushi on efnet/undernet IRC
FB: fb.com/DanielMahoneyIV
LI: linkedin.com/in/gushi
Site: http://www.gushi.org
---------------------------


devel / comp.protocols.kerberos / Is there a way to steer kinit to a specific kdc?

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor