Mac OS X 10.5 automatic ticket creation tips?

View: New views
2 Messages — Rating Filter:   Alert me  

Mac OS X 10.5 automatic ticket creation tips?

by Grindley, Karl :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message


Greetings,

I'm struggling with what should be a simple problem.  I have a number of Macs and users that are authenticating into a kerberos realm.  Authentication within the realm works without issue and Initial ticket creation on login.  I'm using Russ Albury's krenew package to keep credentials renewed until the user gets a new ticket.  Everything works great until the maximum renewable lifetime has expired, the user must manually kinit to get a new ticket.  This is slightly annoying.

However, on linux based systems using PAM, new tickets are requested from the KDC, extending the maximum renewal lifetime every time the user unlocks the console via screen saver.  Is there a simple way to do this on the mac (specifically in leopard?)  Does anyone have any good suggestions or tips?

Thanks,
Karl
________________________________________________
Kerberos mailing list           Kerberos@...
https://mailman.mit.edu/mailman/listinfo/kerberos

Re: Mac OS X 10.5 automatic ticket creation tips?

by Edward Murrell-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi,

>From my notes for 10.4 for doing this a few years ago (at a company that
I no longer work for, so my memory may be fuzzy and/or out of date) you
need to run through the instructions here;
http://support.apple.com/kb/TA20987?viewlocale=en_US
AND you need modify the pam files in /etc/pam.d/

Hope that helps some. :/

Edward

On Fri, 2008-11-21 at 08:06 -0500, Grindley, Karl wrote:

> Greetings,
>
> I'm struggling with what should be a simple problem.  I have a number of Macs and users that are authenticating into a kerberos realm.  Authentication within the realm works without issue and Initial ticket creation on login.  I'm using Russ Albury's krenew package to keep credentials renewed until the user gets a new ticket.  Everything works great until the maximum renewable lifetime has expired, the user must manually kinit to get a new ticket.  This is slightly annoying.
>
> However, on linux based systems using PAM, new tickets are requested from the KDC, extending the maximum renewal lifetime every time the user unlocks the console via screen saver.  Is there a simple way to do this on the mac (specifically in leopard?)  Does anyone have any good suggestions or tips?
>
> Thanks,
> Karl
> ________________________________________________
> Kerberos mailing list           Kerberos@...
> https://mailman.mit.edu/mailman/listinfo/kerberos

________________________________________________
Kerberos mailing list           Kerberos@...
https://mailman.mit.edu/mailman/listinfo/kerberos
LightInTheBox - Buy quality products at wholesale price!