LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 04-13-2011, 03:38 AM   #1
Felipe
Member
 
Registered: Oct 2006
Posts: 302

Rep: Reputation: 32
ssh, kerberos and DNS


Hallo:

I use CentOS 5.5 joined to Active Directory Win2003 (ADS).

I use ADS to authenticate users.

Works fine:
- Share folders.
- ssh with user/pass from ADS.

But have a problem with SSO.

When a user of ADS starts a session, a kerberos ticket is created. So he can use that ticket to start sessions on another computer with that username.

As I've added system to ADS, only direct name/IP has been added.

If I've started a session with a user of ADS called userda1 then I can start a new session with:

ssh server.domain

The problem is that this works if I do a new connection with current host, but not to another computer.

What I've checked is that it's due to a problem of DNS.

If I add the IP of target host to /etc/hosts, then it works fine. else, it doesn't work.

Another option is to register reverse IP in DNS, but that can give me problems with another services (due to I use the IP with different names).

Can any tell me how can I say to ssh client not to check reverse IP.

Tried modifying /etc/ssh_config with:
CheckHostIP no

But still I receive a message with:

Next authentication method: gssapi-with-mic
debug3: Trying to reverse map address 10.18.127.134.
debug1: Unspecified GSS failure. Minor code may provide more information
Server not found in Kerberos database

and I'm asked for user/pass.


Thanks

Last edited by Felipe; 04-13-2011 at 03:40 AM.
 
Old 04-18-2011, 09:31 AM   #2
tshikose
Member
 
Registered: Apr 2010
Location: Kinshasa, Democratic Republic of Congo
Distribution: RHEL, Fedora, CentOS
Posts: 525

Rep: Reputation: 95
Hi Felipe,

What are the DNS settings on your CentOS 5.5 server?
My suggestion would be to have it points to the same DNS server as the one used by the Windows machines in the Windows 2000 AD.
Post back the content of

/etc/resolv.conf:
search your_windows_2000_domain
nameserver the_ip_address_of_your_windows_2000_domain_first_dns_server
nameserver the_ip_address_of_your_windows_2000_domain_second_dns_server

Regards,

Tshimanga.
 
Old 04-18-2011, 02:56 PM   #3
Felipe
Member
 
Registered: Oct 2006
Posts: 302

Original Poster
Rep: Reputation: 32
As I've told you, mi resolv.conf has as dns servers the domain controllers of Active Directory (ADS).
It works fine and it solves direct and reverse ip/name of computers.
But for Kerberos purposes, I have to add the reverse IP of my computer to DNS of ADS. Windows computers are added to ADS only with name/IP, not reverse, and kerberos works fine.
In Linux servers I've to add direct/reverse IP to DNS to work kerberos. So I suppose I'm doing something wrong and I suppose that will be a way to do kerberos work without adding reverse IP to DNS.
As my servers have more names (depending of the services it serves), some of them can give me problems if I add reverse IP, as some of them check direct and reverse and will see they are not the same. So won't work.
Not sure if I've explained it well, but the only I look for is to "do kerberos work without adding reverse IP to DNS".

Any suggestion?

Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh and kerberos error: Server not found in Kerberos database Felipe Linux - Server 1 01-17-2011 03:12 AM
SSH w/ Kerberos ibaniski Linux - Security 0 11-11-2010 08:44 AM
Kerberos and SSH ceph Linux - Server 0 08-03-2009 11:28 AM
Kerberos and SSH l0rddarkf0rce Linux - Server 0 10-26-2008 04:50 PM
SSH and Kerberos l0rddarkf0rce Ubuntu 0 10-26-2008 02:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration