From owner-freebsd-questions@FreeBSD.ORG Sat Mar 19 20:22:45 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 125F516A4CE for ; Sat, 19 Mar 2005 20:22:45 +0000 (GMT) Received: from mail.seekingfire.com (caliban.seekingfire.com [24.72.10.209]) by mx1.FreeBSD.org (Postfix) with ESMTP id 628D443D5A for ; Sat, 19 Mar 2005 20:22:44 +0000 (GMT) (envelope-from tillman@seekingfire.com) Received: by mail.seekingfire.com (Postfix, from userid 500) id D8B5D853; Sat, 19 Mar 2005 14:22:43 -0600 (CST) Date: Sat, 19 Mar 2005 14:22:41 -0600 From: Tillman Hodgson To: freebsd-questions@freebsd.org Message-ID: <20050319202241.GQ4572@seekingfire.com> References: <200503191354.38712.kirk@strauser.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <200503191354.38712.kirk@strauser.com> X-Habeas-SWE-1: winter into spring X-Habeas-SWE-2: brightly anticipated X-Habeas-SWE-3: like Habeas SWE (tm) X-Habeas-SWE-4: Copyright 2002 Habeas (tm) X-Habeas-SWE-5: Sender Warranted Email (SWE) (tm). The sender of this X-Habeas-SWE-6: email in exchange for a license for this Habeas X-Habeas-SWE-7: warrant mark warrants that this is a Habeas Compliant X-Habeas-SWE-8: Message (HCM) and not spam. Please report use of this X-Habeas-SWE-9: mark in spam to . X-GPG-Key-ID: 828AFC7B X-GPG-Fingerprint: 5584 14BA C9EB 1524 0E68 F543 0F0A 7FBC 828A FC7B X-GPG-Key: http://www.seekingfire.com/personal/gpg_key.asc X-Urban-Legend: There is lots of hidden information in headers X-Tillman-rules: yes he does X-No-prize-winner: Nathanael User-Agent: Mutt/1.5.9i Subject: Re: ksu doesn't use my ticket X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 19 Mar 2005 20:22:45 -0000 On Sat, Mar 19, 2005 at 01:53:58PM -0600, Kirk Strauser wrote: > I have a working kdc on my LAN and use OpenSSH's "gssapi-with-mic" > authentication to connect to other machines. However, I can't > use /usr/bin/ksu to su to root without entering root's password, even if I > have a current, valid ticket and am listed in root's .k5login; The ksu from the mit-krb5 port works the way you expect it to. -T -- "You can have peace. Or you can have freedom. Don't ever count on having both at once." -- Robert Heinlein