Operating System - HP-UX
1824037 Members
3549 Online
109667 Solutions
New Discussion юеВ

HP-UX PAM-Kerberos and Windows 2003 DC

 
Brian Frost
Occasional Advisor

HP-UX PAM-Kerberos and Windows 2003 DC

Has anyone had success with doing Kerberos authentication to a Windows 2003 (not Windows 2000) AD Domain Controller? According to some research that I've already done on the net, Kerberos needs to be based of MIT Kerberos 1.3, which uses TCP as well as UDP for authentication.

I've found one article that suggests the following modification in the registry:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kdc
MaxDatagramReplySize 4000 (decimal) reg_dword

I am planning on testing this.

Is there a time table for the Kerberos client to updated to the MIT-Kerberos 1.3.1 standard, since this also is suppose to fix the issue.
2 REPLIES 2
Doug Lamoureux_2
Valued Contributor

Re: HP-UX PAM-Kerberos and Windows 2003 DC

Yes it is possible to use PAM Kerberos with Win2k3. There are 2 known issues, one you mention above where the HP Kerberos client does not support TCP (the only time I see this being a problem is when a user is a member of a large number of groups).

The other problem is with the supported encryption types on the HP-UX Kerberos client. By default Win2K3 disable support for DES-CBC-CRC when requested by the client (which is what the HP Kerberos client supports). The have since released a hot fix (registry hack also reguired) to allow this functionality:

http://support.microsoft.com/default.aspx?scid=kb;en-us;833708

This was supposed to be fixed in SP2, but I have not verified this.

HP is investigating MIT 1.3.x, no timeframe/commitments at this point.
Steven E. Protter
Exalted Contributor

Re: HP-UX PAM-Kerberos and Windows 2003 DC

Do note that Windows 2003 server went a little overboard and would only authenticate using the latest (v5) Kerobos software.

You actually have to get a hotfix from Microsoft to get 2003 server to use older versions of Kerobos.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com