From owner-freebsd-security@FreeBSD.ORG Mon Dec 1 21:18:07 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AD21216A4CE; Mon, 1 Dec 2003 21:18:07 -0800 (PST) Received: from mandy.mts.ru (mandy.mts.ru [81.211.47.3]) by mx1.FreeBSD.org (Postfix) with ESMTP id 86D9743FD7; Mon, 1 Dec 2003 21:18:05 -0800 (PST) (envelope-from tiamat@komi.mts.ru) Received: from maeko.inside.mts.ru (maeko [192.168.10.3]) by mandy.mts.ru with SMTP id hB25Hxb07106; Tue, 2 Dec 2003 08:18:04 +0300 (MSK) Received: from stella.komi.mts.ru ([10.50.1.1]) by maeko.inside.mts.ru (NAVGW 2.5.2.12) with SMTP id M2003120208175804917 ; Tue, 02 Dec 2003 08:17:58 +0300 Received: from nbdav (nb-dav.komi.mts.ru [10.50.1.185]) (user=tiamat mech=NTLM bits=0) by stella.komi.mts.ru (MTS Komi/Smtp) with ESMTP id hB25HwFm006960; Tue, 2 Dec 2003 08:17:58 +0300 (MSK) (envelope-from tiamat@komi.mts.ru) Message-ID: <006501c3b893$a2214ae0$b901320a@komi.mts.ru> From: =?koi8-r?B?5MXK1MXSIOHMxcvTwc7E0iD3wczF0snF18ne?= To: "Mark Murray" References: <200312010859.hB18x2Dw094198@grimreaper.grondar.org> Date: Tue, 2 Dec 2003 08:17:51 +0300 Organization: =?koi8-r?B?5snMycHMIO/h7yAi7c/CyczYztnFIPTFzMXzydPUxc3ZIiDXIMcu8w==?= =?koi8-r?B?2cvU2dfLwdLFLCDy6y4=?= MIME-Version: 1.0 Content-Type: text/plain; charset="koi8-r" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1158 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 cc: freebsd-security@freebsd.org Subject: Re: Kerberized applications in FreeBSD 5.x X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 02 Dec 2003 05:18:07 -0000 > > In FreeBSD 5.x only telnet/telnetd works 'out of box' with kerberos. > > Why ftp/ftpd, ssh/sshd and cvs do not support kerberos ? > You need to turn it obn by hand in /etc/pam.d/*. Its not on by default, > because that would cause nasty delays in PAM. No. I meant support at the protocol level. Thanks!