Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

"One lawyer can steal more than a hundred men with guns." -- The Godfather


devel / comp.protocols.kerberos / kfw-4.1: ms2mit in virtual setups?

SubjectAuthor
o kfw-4.1: ms2mit in virtual setups?John Devitofranceschi

1
kfw-4.1: ms2mit in virtual setups?

<mailman.0.1631913299.2760.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=141&group=comp.protocols.kerberos#141

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.pch.mit.edu!not-for-mail
From: foo...@gmail.com (John Devitofranceschi)
Newsgroups: comp.protocols.kerberos
Subject: kfw-4.1: ms2mit in virtual setups?
Date: Fri, 17 Sep 2021 17:14:15 -0400
Organization: TNet Consulting
Lines: 87
Message-ID: <mailman.0.1631913299.2760.kerberos@mit.edu>
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.13\))
Content-Type: multipart/signed;
boundary="Apple-Mail=_79A1C2DD-4312-4518-9C6B-5DAE53FA6BB9";
protocol="application/pkcs7-signature"; micalg=sha-256
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="pch.mit.edu:18.7.21.50";
logging-data="3798"; mail-complaints-to="newsmaster@tnetconsulting.net"
To: kerberos@mit.edu
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=fovvMJj85M7jm1d+BUEBG+1Z+Bx0XTh+dconH9W4NarW1tqPiIVehgjqaMzOgGfripJ1btBO2yr/cqTGctiIKzmEMA/yIrxD9/naB6HN0HSBTlBta8fremv2YJPdgl0GKjvvcZmE2eeCJtpyrkl5ogpi5l4ijUVOeAjBykz3y91TvUnvLIWVu+71ZrToD3FsCcP6xPZZLs533CHCbfXwhZx3YMyDMmZjhkeko8cGwjs4EK6EOjGnLNnkf4oe9ptoZtZ6DefNR1W8yT5cO9AvTEKme1Y7nVEUabTV9x8YWEvoYKmkZPma3SkK1xMYNdhIAwD7NTbY2PSi+sT6YZ1GxA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version;
bh=j6YNJv5zcRhNl11DqkQ9uRVrN1CeY+ExuqgfAJxQf+w=;
b=cDsUGQdXvv1aktCT8wWcti/IkcMWRxN/dehLo3hw//dE0HbO9TQ5wkRSJAgsMRZp/5DF7pS6uMy5W7TWBDRFap3SEUXzUEFnONf+eZ7XtYJI40nBzSC9DbbmRSOgAq/SFr3VoDkbn4cM8JbIPOf5aW+IzTTwYMCiYY+05SnuFMHSoT59K9ODzQ/7I7Goe1S3VKHXLH9nf8zDtNNtY+1GYOVhsGC0zzBqSiGrCtfi4KchinRmZvYUfNhy9gnwCYVN3hcrM6yoXqasuM2t9R3GqtLenZAjZwGHWWCldRTld2El5AFwLZj3CCocEkMOTNcZKL0nFaS0YVnY0idQUXp1jA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none;
dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=j6YNJv5zcRhNl11DqkQ9uRVrN1CeY+ExuqgfAJxQf+w=;
b=qZHTNyWT0198koS6Y+iwMpgqgx0v5c4drBcjNhj9kTZTr2QxFYdlTdVbM5mF9H4S8a4+rbxTyCsWq6chWZ0LNfZXTIxVaHyHKIjk/fLyIJnHgZVOdmPnxdt/GcHvQuv+dpjpQrPDuNYoBI/0QbpdG2AgENk0q32ZmxQ3sU4PvvQ=
Authentication-Results: spf=pass (sender IP is 209.85.222.176)
smtp.mailfrom=gmail.com; mit.edu; dkim=pass (signature was verified)
header.d=gmail.com; mit.edu;
dmarc=pass action=none header.from=gmail.com;
Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
209.85.222.176 as permitted sender) receiver=protection.outlook.com;
client-ip=209.85.222.176; helo=mail-qk1-f176.google.com;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112;
h=from:mime-version:subject:message-id:date:to;
bh=j6YNJv5zcRhNl11DqkQ9uRVrN1CeY+ExuqgfAJxQf+w=;
b=SE+dK3+5wq4TF00dhZcwex7R+Xp8aflg1M6yTuX/q73DAy4mcTUBSseXZqnc9/CccY
7JC8FVUqSsT8khogfE3HXMZITb19g5XChOTmtNdn2m6hEY1V63PkLlE5HU+mQif0T5Fp
UeUeBAsHQJvYQtmZ+4xWMVC3eoXI+XbqAkNyPWCAc4EtAs+L7muX2ElsKGOYPJkthqXN
SFVoxeuujTk0vmCPe61WTTHSG6uO1xmZN/XGPEUr50FgInrdj4qPD0689i0vsG1C2dgi
N6lgFpDbzZSyLtqABL1bc329RqjgG+ySJjbh87rrLzMetFCkKyEgTXIDp6dzkXNtw3h0
BbpQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20210112;
h=x-gm-message-state:from:mime-version:subject:message-id:date:to;
bh=j6YNJv5zcRhNl11DqkQ9uRVrN1CeY+ExuqgfAJxQf+w=;
b=Sbj7FO8GENQ5YtndiMBsTgOQep0q6g3nKWB8ZbX+Qx9535LCD9M6erFSfHny6PTtAi
+bM7a3lGqBLVtGZ7pBpPnp8n9eYDNDOhn7HPLmoP029763fhhoM5pD3Gxz389/b5C8mq
M1py1qFBueIjRkAFiT5qRoWojYewgn3b224iEOCxl1MxJYjdkomp5S/iFROFM1Cpdj+P
SXm/67yHgcES1e08pTUHN39bVE3JWfOFVbjGeVpAArqWQtqLj/Q0SWayAvIN6vqnccUQ
xK6SonIRkATuCB6wyiA+5Mf3m+2cUyGjyIH8YKmI+prsLGkz2pucKxjLnkqeJEDDecaY
rHtw==
X-Gm-Message-State: AOAM532C/nSXsxnYn4hIieVzjY80iU43abxSHzKCDceAiAkaCU6uHaXn
DPI7t6GTeruwLGoJm9uxglvBB0tMJCo=
X-Google-Smtp-Source: ABdhPJwSzmGWKz1G/5ooA98enualZogb4ZTD7CJ5QtBfoXZUGytF8PXfLVKK3am/jW5ZFLrbFShhvg==
X-Received: by 2002:a05:620a:254c:: with SMTP id
s12mr12677545qko.112.1631913258126;
Fri, 17 Sep 2021 14:14:18 -0700 (PDT)
X-Mailer: Apple Mail (2.3654.120.0.1.13)
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 729a17b9-9f64-4473-ee37-08d97a201d14
X-MS-TrafficTypeDiagnostic: DM6PR01MB5947:
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-Microsoft-Antispam-PRVS: <DM6PR01MB59473BC871E1D64B55FB6C78D2DD9@DM6PR01MB5947.prod.exchangelabs.com>
X-MS-Oob-TLC-OOBClassifiers: OLM:9508;
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: uNCLb/MWNpn+CG/GAB2QVR7FbFCA/0p/gEaSVW1mS5kZWRdKE0qyTtmW3jtVfitIek8EnIfEYSL4+KoBIQvZClPX9IszpfEloAiBExai/XaSdPTWtWcXBIC7FU+ORF/d5zBbk/EBSv6R0vKxsr4XnUr0p5Uk0GLPv8Al+DJBdkJyEcDe/anTA9niObjLpuOJTI3XxtWtfnFBa6ewsIBEdFrZ6jPzebf9k0PP5xH08znp4nZ+O8CDEZLcqrKaxH0IPGnn+t66oxc3Ob9Pi7NkLcYqAVigBOJrq6zar2BNZuDGAYcabcRqlVi64f1nEMDUmBbkrgLh42sIYeULtC2w2GfKxQAuEyFApU4liEmlL5hR7eiJuTRAal3avuspBtYTXpd4T4hBivRK9dsDAUkeJOD/6dyWft2LJ2/JioEzdeQ9Jw6Gwuxuqi5EbZuuMAn7XA2FKAoUN8I9JnqouuW/2dPBSTh9fURCvlWSC7JO84mNUXJfVjlDBuOgZCdZby8GVqcsmiq+vp1nmO85WVLLcF3ErTi9mPvWiPvhnAMRZ+8D26QBvVxjsLYc+/leckBClqSLkF5uxqohVY5MtYoiuTo8kCwgRG1myUioSQrIIUvgTDDHmHw1bQJSoYnasEJd
X-Forefront-Antispam-Report: CIP:209.85.222.176; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mail-qk1-f176.google.com;
PTR:mail-qk1-f176.google.com; CAT:NONE;
SFS:(4636009)(84050400002)(73392003)(956004)(36756003)(2906002)(356005)(7596003)(76482006)(2616005)(336012)(235185007)(26005)(426003)(34206002)(7636003)(316002)(86362001)(70586007)(68406010)(45080400002)(508600001)(5660300002)(55446002)(8676002)(33964004)(33656002)(82202003);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-Transport-Forked: True
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Sep 2021 21:14:19.5058 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 729a17b9-9f64-4473-ee37-08d97a201d14
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: CO1NAM11FT052.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR01MB5947
X-OriginatorOrg: mitprod.onmicrosoft.com
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.6
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
 by: John Devitofrancesch - Fri, 17 Sep 2021 21:14 UTC
Attachments: smime.p7s (application/pkcs7-signature)

So, we’re trying to get kfw-4.1 working in a development environment that’s using Microsoft App V to deliver applications in a virtual format.

In general things are working, but ms2mit is giving the "Initial tgt’s are not available from the MS LSA” error

I can see that “AllowTGTSessionKey” is set to ‘1’ in the virtual registry. Is that not sufficient? Any way around this?

Thanks in advance for any hints or pointers to hints.

jd

Attachments: smime.p7s (application/pkcs7-signature)
1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor