Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

It has just been discovered that research causes cancer in rats.


devel / comp.protocols.kerberos / KDC timeout for MIT Kerberos?

SubjectAuthor
o KDC timeout for MIT Kerberos?Russ Allbery

1
KDC timeout for MIT Kerberos?

<mailman.30.1644429002.8148.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=220&group=comp.protocols.kerberos#220

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: eag...@eyrie.org (Russ Allbery)
Newsgroups: comp.protocols.kerberos
Subject: KDC timeout for MIT Kerberos?
Date: Wed, 09 Feb 2022 09:49:32 -0800
Organization: The Eyrie
Lines: 15
Message-ID: <mailman.30.1644429002.8148.kerberos@mit.edu>
References: <87sfsskk0j.fsf@hope.eyrie.org>
Mime-Version: 1.0
Content-Type: text/plain
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="29395"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux)
To: <kerberos@mit.edu>
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=G67IE1LqNFRAqWpJGRf5ufJoe6NkKFhPJbkQXvKxNgMOvVCXVqqtdc73kQ1CRZEhB4Hdq4bWikmUWc1y6dIeFMyhf9Ncj/dvroxnoTrhg1sa0QGdgA4QOupv0BpJqkg1AEKr8Sc7PXbBBVOiK4Mw63jvdfhKgRDNHOFTGARAqDHzTRzoty/ptCZJ9DTNzw9Cxv21aGSha5DHmT4y8znhkkxqpfBewJ01qdKcviXvsSWww7zZLaY2iga/w1zEU90X0sbDUem89IlRwRpxZV12nXxW3qeJCfRvmr2BissfKjRi9Aup6ckm7C7mPvY/2F0r4iRUH70GzmOMi3Kl8JJtlw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=24aNfZGop3jAroSfvdd9AFnq3JWLAQjHsUJ0/Bo0Wd0=;
b=f003KnlUKccCJO71yp7mfWE53h2Y1JTN3/vi/1hJ4hKxOW615mwvG4pwyHOId02yF68eA/IFYrhC62BbP14jQPde8J1iN3of+TDIM1vSlk7sdAyTl8Z27jiTuJrxgkjofkxHzZb8bi3lPHzFNBe3pIWRLnOXrHcEkYJMwhpqb8lOtBdU66mQe+zimpEk6uaOL17Qi000HvdDv8drUllOBsovgQn4KllFymGVgBp3ZVEqkgr7EueG08dw83MkfQM2UQoPeQ0H1iICE7YhEhVpcB8cczE5SOIDEXkXkRgpRhwJRZvyWlj4vaPXe/VOP5q4yoxUFSNebDC6qgbgSOkc5Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
166.84.7.159) smtp.rcpttodomain=mit.edu smtp.mailfrom=eyrie.org;
dmarc=bestguesspass action=none header.from=eyrie.org; dkim=none (message not
signed); arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=24aNfZGop3jAroSfvdd9AFnq3JWLAQjHsUJ0/Bo0Wd0=;
b=bZ2iO396QVWhKmXsE/IViWFY0q1XVQLCIAr7cpXO4X/alcg2v4FeVSQEOxYXNCmXGmPuHAgconPc6ERVb2ocJcDOHy0SxRrudx6XEmrBCQb7oFA7LK6xRV7RagGEl6OBZDF845376nFa5/0W7KbVNH1dAK4kw4x91ChDxvwJ9wQ=
Authentication-Results: spf=pass (sender IP is 166.84.7.159)
smtp.mailfrom=eyrie.org; dkim=none (message not signed)
header.d=none;dmarc=bestguesspass action=none header.from=eyrie.org;
Received-SPF: Pass (protection.outlook.com: domain of eyrie.org designates
166.84.7.159 as permitted sender) receiver=protection.outlook.com;
client-ip=166.84.7.159; helo=haven.eyrie.org;
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: fde57596-5fc0-498c-9ee7-08d9ebf488a2
X-MS-TrafficTypeDiagnostic: DM6PR01MB3724:EE_
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-Microsoft-Antispam-PRVS: <DM6PR01MB372421C810DF8720765FFA4CA62E9@DM6PR01MB3724.prod.exchangelabs.com>
X-MS-Oob-TLC-OOBClassifiers: OLM:9508;
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: MoIzclPiZev7BtImE0G5VpyhmEDstqsj87smGew5OMp83ElDZ04fZM2939XaOh9DGndbPmoVFY9YO1cj39VHsl9nj4y1CPM5JRa3js7aZu1WjdVVVc90pn5JmyOKMInrlRcY3hGuEZVNEEiPJBEN/7OqVXXL6WTxmoEtZJMhaQ74M0O2vSiqQaQNi4mt9bRW5fq35g7e7IvpYZQnLRqge8lz6sceqh4MYgivrXylqeul2PyciSk98g7sAIzWoTTcY+ScDH6PyeETw9rGaJRBRD7hv3ZW7y8xJ7Lt9mSI3o6RxVvyGcxKQuew1EaipFD0gvBijZ4NqHK+zEbLBtaBKKcIObGaSkC9Wnpu3H0THG8jdCw22lFc76HjlDb+E1Hi/z8WTvvbGYlD/2mcioWkziyxleevv9v8XTOO74qLzzXKw6VUJXkJEi6hij2pqLyCFPX5eDHe33qYOooYTQWSub6MbxG0KZPL8nUahxDf6FM+Qj3RlkeyX4WtDjlwGiPaLbLSTN0/dt4dcjAGz9zMiuXIU6VKb8qTnBf6Eo89AJblh5mePU1jQvq75tmX9sQ2SNPxrpNiQgYG18OnmGfZKCYVsff067ZWkT3wxQTqoopd9rwdW29CwPqhuunut5NLrBxmacDUqoG9BH0YfmPI8tkOUYNNp9qxUn4AqWg1Op136EhlwK29fcKpEvEz6Nk6Kz1/Q3Q79yUZxTqfnPMxrQ==
X-Forefront-Antispam-Report: CIP:166.84.7.159; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:haven.eyrie.org; PTR:haven.eyrie.org; CAT:NONE;
SFS:(13230001)(4636009)(356005)(966005)(6266002)(42186006)(7636003)(4744005)(66574015)(8676002)(34206002)(70586007)(68406010)(316002)(786003)(26005)(426003)(7596003)(83380400001)(336012)(36916002)(5660300002)(2906002)(508600001)(86362001);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Feb 2022 17:49:34.5917 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: fde57596-5fc0-498c-9ee7-08d9ebf488a2
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: BN8NAM11FT020.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR01MB3724
X-OriginatorOrg: mitprod.onmicrosoft.com
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <87sfsskk0j.fsf@hope.eyrie.org>
 by: Russ Allbery - Wed, 9 Feb 2022 17:49 UTC

A user of my Kerberos PAM module asked whether there was a way to adjust
the timeout when talking to the KDC. The use case is a laptop that may
have a dodgy VPN and thus think it's on the Internet but not be able to
reach the KDC.

https://github.com/rra/pam-krb5/issues/22

My understanding is that Heimdal supports the kdc_timeout configuration
option in krb5.conf, but I don't see an equivalent for MIT Kerberos. Is
there any way for the application or for the user to control how long it
takes for the library to decide that it's not going to get a reply from
the KDC and fail the krb5_get_init_creds_password attempt?

--
Russ Allbery (eagle@eyrie.org) <https://www.eyrie.org/~eagle/>

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor