Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  nodelist  faq  login

C'est magnifique, mais ce n'est pas l'Informatique. -- Bosquet [on seeing the IBM 4341]


computers / comp.protocols.kerberos / Re: Server settings from /etc/krb5.conf used despite KRB5_CONFIG set

SubjectAuthor
o Re: Server settings from /etc/krb5.conf used despite KRB5_CONFIG setJohn Devitofranceschi

1
Subject: Re: Server settings from /etc/krb5.conf used despite KRB5_CONFIG set
From: John Devitofrancesch
Newsgroups: comp.protocols.kerberos
Organization: TNet Consulting
Date: Sat, 14 May 2022 12:47 UTC
References: 1 2
Attachments: smime.p7s (application/pkcs7-signature)
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: john.dev...@gmail.com (John Devitofranceschi)
Newsgroups: comp.protocols.kerberos
Subject: Re: Server settings from /etc/krb5.conf used despite KRB5_CONFIG set
Date: Sat, 14 May 2022 08:47:32 -0400
Organization: TNet Consulting
Lines: 88
Message-ID: <mailman.66.1652540291.8148.kerberos@mit.edu>
References: <20220509190346.GA1253591@mikus.sk>
<1DAF1488-496C-4D0F-ABB3-DECBCF73CF7E@gmail.com>
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3696.80.82.1.1\))
Content-Type: multipart/signed;
boundary="Apple-Mail=_49E311CF-FA4C-4217-A886-757D5CA51DF8";
protocol="application/pkcs7-signature"; micalg=sha-256
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="7929"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: kerberos@mit.edu
To: Andrej Mikus <a-krb5user@mikus.sk>
Authentication-Results: mit.edu;
dmarc=fail (p=none dis=none) header.from=gmail.com
Authentication-Results: mit.edu; arc=fail
ARC-Seal: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1652532458; cv=fail;
b=K2JK1+rmlp/MltRyR86gpofVbRevtdpligtBMokVE822qPJht77RiDnCAL6iCeGZSMGngB6WvwYfwt8Ep3SWmquQuDVSiuFRjUr3ukvSNTO2uJnQ8jPOD0fzkUxQLHDq79sZGZM/TjZFzSad7JQdMTWKZXmjv5qNhhIYiizScXYQNElrseZcsBlCrZr/vQmTfGpVHNYi7jt4as3ZSbtTKxIfpG6SnDqtjF1dbF2oertd5SEsdN7I5hWP4iHB5RAP2dgL+RI+ua//05o2ytbwPZ72twh5dzmndhtowS7oUwem/MmX3oM9L0zS89HSbN2euOwjvemAn+7VP1kCemICNg==
ARC-Message-Signature: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1652532458;
c=relaxed/relaxed; bh=Rjy4lovR5bq/2KtMXymfBH2RV7nyoRFXvr1ItTw/maM=;
h=From:Message-ID:Content-Type:MIME-Version:Subject:Date;
b=ntAD5M1UHlpg6JNqRatXQJwGrizg6PMBBvleRsP4JbxDOiJYNd/1eyT4Q9Btlg2SKtNy8oiLgUpt5t0zFQlb72KT/X76DxaYt9+RYns9lKdQtDNb8VT2bPCbtMRaOEvf0iK6UTwz2JU0aqEfJFacKCSpsuDa5Nc4sgSD+juLAdH6IKmxd9IF70rrFoKYPR4sHXzanKfM20IPR76HWeTMLD4QTir3+xoKc4YbUsWG8esQuN8PC5NAbAxJ4C/0NTQe3P4dO4Hpzl750VLt4s4Z8nsjzt9IaJm1Hdxr915j7WeH38kJ+SDqF2Tzr3hKPaaBl+bCUeHVSrwEgpUnXAJf9A==
ARC-Authentication-Results: i=2; mit.edu; dkim=fail (1024-bit key)
header.d=mitprod.onmicrosoft.com header.i=@mitprod.onmicrosoft.com
header.b=FYUESdjF reason="signature verification failed";
dkim=fail (2048-bit key) header.d=gmail.com header.i=@gmail.com
header.b=KBZ9dqra reason="signature verification failed"; arc=fail
Authentication-Results: mit.edu;
dkim=fail reason="signature verification failed" (1024-bit key)
header.d=mitprod.onmicrosoft.com header.i=@mitprod.onmicrosoft.com
header.b=FYUESdjF;
dkim=fail reason="signature verification failed" (2048-bit key)
header.d=gmail.com header.i=@gmail.com header.b=KBZ9dqra
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=lZnJ3I/cM92gAghJc4L2w7P3QdUyB+1INoKuB1VENTkqQm5Qu8MgxGQiHdUWBagaexYPYUJLPkh1hQ9UVqjEAFisqTcppAmW1GZJ6/jz7QY1T1WmiRE2MM/ko0kK0RZQ8UwwPYJtgVK03c+kU8QW8TOyAqQudtSUAQ0nA7HM2Vo5bBQMp/ls/Md0chMf6+V1wvYyP1QbyCMyUe1OUJa4rfTLgHgtI+TTsjy1iPazYCwfmZBb4xYAbvjngovMhE3iJT5riufrGMY4xL7uZrgE8czR1C39hviV52djyCAEf30scLbBLhOiHnLK5lrqo1YO5skFUD1RThgy5OLDqJ2pig==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=5vcmHk+JXifm5uB2Dmy8D4PBjug0nOASIcOCjlJew5Q=;
b=WKNzJmmmKH7CzuHdhIgY+uRV8zQplzDORebpKc4qzzZLFNnfGUMCBLwXc0AHy9fCaxWe7K3+1acWDurfhTaF+y0WRK3+zTBEMY+yTntiIteCMCYr75+5juvA24segLsQAAkluy33atFaShqckcHLW9lUNiD7SsgBP2viOqzvv3TLlJr5qWWoMPZcHSWkeYLfcdKyx5M056gD5AQokuc5chtHeVbiC0MWkEo2TW98GP8PmOBCSGXjvQfDKQQ6cjyJGH//Z1+8zTNjsACIq2qAi8bMCLNMjHk0tvCzQ7M93HjG8JTPpzDbdshfvk3ZZ+yHtc1UxMMH0YF6hZaFtDxVIg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
209.85.160.172) smtp.rcpttodomain=mit.edu smtp.mailfrom=gmail.com; dmarc=pass
(p=none sp=quarantine pct=100) action=none header.from=gmail.com; dkim=pass
(signature was verified) header.d=gmail.com; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=5vcmHk+JXifm5uB2Dmy8D4PBjug0nOASIcOCjlJew5Q=;
b=FYUESdjFUATVJaiLDuj0epW42Pe54UQFUFj1TWfK3j0MACl3VPfR3i5KAK76pAsAoa3Fl4DjviFaSROo9CrWesMh/UFO6+Z+pvKchDcx6UlIKAnulEsWrnIPaQd29ASLikxKRh7MikU9apsunloKXCn2FY6UOVybDpXgfdPDZyE=
Authentication-Results: spf=pass (sender IP is 209.85.160.172)
smtp.mailfrom=gmail.com; dkim=pass (signature was verified)
header.d=gmail.com;dmarc=pass action=none header.from=gmail.com;
Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
209.85.160.172 as permitted sender) receiver=protection.outlook.com;
client-ip=209.85.160.172; helo=mail-qt1-f172.google.com;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112;
h=from:message-id:mime-version:subject:date:in-reply-to:cc:to
:references; bh=5vcmHk+JXifm5uB2Dmy8D4PBjug0nOASIcOCjlJew5Q=;
b=KBZ9dqrafUr6uaiPitJEIolMAOskV0NJOt+Bbq5yZa6YzmmWRFlkax4ePpJ+z/0n0/
W8gV0j/O3Gvw1LD/kT4287+Kpwj9450fQIIdCKlFbaXMIZoVwSLCEQ5/xsYVHiawt7To
KY+t/VzWhS9dzSXHxIfEkGUIAdM2oLxMa9wYybrtLx1sm7dpG1dQZj891NgNEkaxd+o3
45e3ZJDLRgbdLZ+h/8IQQDCWsSgPXLWGOrJel2d8T8fSIqyrjDZxg69RL9Gr2tFY7aXs
nVTHV0ikHHaEx7+Ky6BYWG8hcXBCh5sj6N7xoXkJqDKUxx4zvFQ1Jy4hVpPwwff79qZe
WdJw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20210112;
h=x-gm-message-state:from:message-id:mime-version:subject:date
:in-reply-to:cc:to:references;
bh=5vcmHk+JXifm5uB2Dmy8D4PBjug0nOASIcOCjlJew5Q=;
b=RwMbSo7SBn/pgJDBAXHCx9fUdsm2AQcSb8caTQhnW3EWWkgdbGDONyQLiSJgAsu4wq
A9a9Ypov7EMYkym0lXpIjv3cvHNeY8LfvyzlMxcJjoxky71CAwS3UIcnJBX9wQwQkhFR
IBfjFgP/cuIO2NL19w/S3G3NH/VVtrKP6Rzinije5TZiC3IIq6kfebHp+G2Cq5Ejcai6
7aUw5OurWdkUqsjCR/9rJwGHQ/Z7skYEj2vm2U/A4iJ9myjYEHDGJ+mq7AxZN+k8artl
KlOVG8fOTnaTREepwKHmt0d+AzKPj0sTM4HlSHNvUWKO/cjjwowrtLSLvuVErFr13phU
rmCg==
X-Gm-Message-State: AOAM533wxfMe69dpy7dKeJhKG+wtpUc1nw+kb/RoolHqvglO67H38VVu
/2t+fgeFDbQxo5S7DgAYtSCtEyJ+pwY=
X-Google-Smtp-Source: ABdhPJznnU1OzpDzTAltfQ0NrbecEaSRBQGdmCkK8e3ldHx6clLbhTlqrdLugwOgeDpY74fTwBfMdw==
X-Received: by 2002:a05:622a:38b:b0:2f3:dcce:a7a3 with SMTP id
j11-20020a05622a038b00b002f3dccea7a3mr8465351qtx.439.1652532454382;
Sat, 14 May 2022 05:47:34 -0700 (PDT)
In-Reply-To: <20220509190346.GA1253591@mikus.sk>
X-Mailer: Apple Mail (2.3696.80.82.1.1)
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 4aa810fa-2944-48cc-ec1c-08da35a7eb39
X-MS-TrafficTypeDiagnostic: PH0PR01MB6183:EE_
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-Microsoft-Antispam-PRVS: <PH0PR01MB6183EFAC133D982D2C9A13E8FFCD9@PH0PR01MB6183.prod.exchangelabs.com>
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: K2NfI9kiABuOgo/m/aVXonuKoVVGF/a1Uf6cNWAyWTR5Q4oFCyknvdFjcQcV+t/iuKKfR6szhAlbaKuOHLsE8HMe5ELxs1couoOMzwV6CLa0Fhw/TIgG8AV1l7Wfwen41fUFFEH49MXU79ZF3NpTQksDFUo7j4hLHa03mEANbdjSQEcA8L9W+gIChqjUnz1iTMOgWbF1QE3NI3dAsJtMpyETvYkRlP/2CQoPUNy1HpAGPyl7S2BlT30vMjo4S9HNTnEVuClaAJ9Wqx5JMlvzE3hhunCRggJWIFCBy1ejBopsDvjcHJg4cf+mFhnm9Q4zwsI6dJ6fWZzsFDvnld6SXApFB9BnnjUllM+ugCpL4qDj544BipfHtPyyQhOdeRd95GG0YI0Q0gJu+1SKFr4WlJ8cwDxE5UEA3ZmknWO+5c2oRGM+LYohEg6VKqdWjHI7vl2MoZ6Z+HZP4i3pIqeNwU9ojgwMCdbDczI+0/TpZAJpR0J6YELQ4uUKsAVIyM63qOWyUflfQdHa2Ai8LGIhY8eR1giLA4yjkbg0WlMIc2YPf8GoO6c+4Mwhn8VdPw09lIIVJXCs9cUMuMTJex5nXlsXmKBrETsaFgmQeb1d0H4=
X-Forefront-Antispam-Report: CIP:209.85.160.172; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mail-qt1-f172.google.com; PTR:mail-qt1-f172.google.com;
CAT:NONE;
SFS:(13230001)(4636009)(84050400002)(2616005)(956004)(26005)(73392003)(86362001)(316002)(44832011)(33656002)(426003)(82202003)(70586007)(336012)(55446002)(5660300002)(8676002)(2906002)(4326008)(6862004)(235185007)(356005)(786003)(68406010)(36756003)(7596003)(7636003)(508600001)(53546011)(76482006);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 May 2022 12:47:34.8442 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 4aa810fa-2944-48cc-ec1c-08da35a7eb39
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: BN8NAM11FT059.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR01MB6183
X-OriginatorOrg: mitprod.onmicrosoft.com
X-Mailman-Approved-At: Sat, 14 May 2022 10:58:10 -0400
X-Content-Filtered-By: Mailman/MimeDel 2.1.34
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <1DAF1488-496C-4D0F-ABB3-DECBCF73CF7E@gmail.com>
X-Mailman-Original-References: <20220509190346.GA1253591@mikus.sk>
View all headers


On May 9, 2022, at 3:03 PM, Andrej Mikus <a-krb5user@mikus.sk> wrote:
I am pointing KRB5_CONFIG to a file with correct KDC address/name, but
kinit always refers to the IP specified in /etc/krb5.conf.

It is my understanding that setting environment variable overrides any
use of files in /etc, also the test scripts in the code distribution
suggest this.

Is there an sssd_krb5_locator_plugin getting in the way?

Check under /usr/lib/krb5/plugins/libkrb5.

jd


Attachments: smime.p7s (application/pkcs7-signature)
1
rocksolid light 0.7.2
clearneti2ptor