OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: GSSAPI Authentication

From: Andreas Winkelmann (mlawinkelmann.de)
Date: Fri Jan 02 2004 - 03:12:56 CST


Am Freitag, 2. Januar 2004 07:13 schrieb ms419freezone.co.uk:

> Aha! I didn't understand what "chroot'ed" meant ... Now I gather that,
> because "smtpd" DOES run "chroot'ed", it looks for
> "/var/spool/postfix/etc/krb5.keytab", which doesn't exist.
>
> SO, my options appear to be, 1) not running "smtpd" "chroot'ed", or 2)
> creating "/var/spool/postfix/etc/krb5.keytab". I've tried to discover
> how the files in "/var/spool/postfix" are maintained ... What must I do
> to ensure "/var/spool/postfix/etc/krb5.keytab" is kept current with
> "/etc/krb5.keytab"?

I would prefer 1) ;-) But my Kerberos-Knowledge is not really good. It is only
updated/changed after you run manually "ktutil"? So after this copy the new
version from /etc to the jail.

--
        Andreas