Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 3 Mar 2001 14:29:54 +0000 (GMT)
From:      Neil Hoggarth <njh@kernighan.demon.co.uk>
To:        <freebsd-questions@freebsd.org>
Subject:   OpenSSH in 4.2-RELEASE and Kerberos
Message-ID:  <Pine.BSF.4.33.0103031412420.301-100000@homebrew.localdomain>

next in thread | raw e-mail | index | archive | help

When making an ssh connection between two machines running FreeBSD
4.2-RELEASE on my internal LAN, using the OpenSSH incorporated into
FreeBSD, I find that both client and server generate DNS queries for
hostnames containing variations of "kerberos", "_kerberos" and
"krb5-realm". These are an annoyance, as they trigger my dial-on-demand
PPP link (and produce an associated delay while the link comes up and the
names fail to resolve).

I don't use any kerberos stuff, and haven't knowingly configured anything
relating to it.

The ssh and sshd man pages document various command line and config file
options for suppressing Kerberos authentication and ticket passing, but
the ssh and sshd binaries don't seem to recognise these.

Is there anyway I can supress kerberos activity in ssh/sshd, or configure
the kerberos libraries not to generate DNS query traffic?

Regards,

Neil Hoggarth.



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.33.0103031412420.301-100000>