How do I configure GSSAPI->Kerberos V to work with openssh-3.9p1-8 on RHEL4U4?

Posted on 2007-10-17
Last Modified: 2013-11-15

RHEL4U4 - fresh installation
openssh-3.9p1-8 RPMs for openssh
Fully operational KDC
Correctly configured host and user principals for hostA and hostB

Problem: kerberos login not attempted via GSSAPI and sshd on hostB when logging in as usera from hostA with current TGT and correct CC.

Should this just work, or am I banging my head on a wall again?
We have no AFS, which most of the info on Google seems to refer to.

Many thanks.
Question by:engerd
    LVL 30

    Accepted Solution


    First of all please make suere that HostA /etc/ssh/sshd_config has hthese options enabled (i.e., not commented out):

    GSSAPIAuthentication yes
    GSSAPICleanupCredentials yes

    If not modify and save, exit and restart sshd service.

    Then edit /etc/ssh/ssh_config and make sure that:
    GSSAPIAuthentication yes

    is there. If not modify.

    Then start kde on your local host:
    kinit user@realm
    if you get "kinit(v5): Cannot find KDC for requested realm while getting initial credentials" then it means that you have a problem with  kerberos. lease reconfigure it.

    If it is ok then you can
    ssh host

    and it should succeed.


    Author Comment

    Hi KeremE,
    This is all configured correctly.  I noticed a short time ago, that a specific user *can* ssh without a password with a suitable TGT in their CC.  This does not work for root.

    So ... I  believe the problem is in the LDAP UID lookup rather than kerberos.  root account doesn't work either, which is also mystifying.

    Thanks for yur help in any case.
    LVL 30

    Expert Comment

    by:Kerem ERSOY
    I am sure you've checked that but just to make sure. Did you enable root login in your sshd_config of ServerA ?

    Author Comment

    We've been using ssh a lot longer than Kerberos ;-)   I've just got root to work - missing the root@REALM principal - doh!  We don't put root into LDAP via inetorgperson or otherwise!

    Thanks again for your help.  I'll throw the points to you in any case.
    LVL 30

    Expert Comment

    by:Kerem ERSOY
    BTW what is your kinit name ? Is it also root@realm ? Or you are using a realm other than root that has no access to root credentials?
    if so please include it to rot realm
    LVL 30

    Expert Comment

    by:Kerem ERSOY
    oops you've already put it in ther :) Sorry I did not see your comment. Thansk anyway :)

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    I use more than 1 computer in my office for various reasons. Multiple keyboards and mice take up more than just extra space, they make working a little more complicated. Using one mouse and keyboard for all of my computers makes life easier. This co…
    This article describes how to use the timestamp of existing data in a database to allow Tableau to calculate the prior work day instead of relying on case statements or if statements to calculate the days of the week.
    This video will demonstrate how to find the puppet warp tool from the edit menu and where to put the points to edit.
    Viewers will learn how to use the Hootsuite Dashboard.

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now