From sacadmin Fri Jul  6 15:05:59 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l66M5xHi009643
	for <psarc-record@sac.eng.sun.com>; Fri, 6 Jul 2007 15:05:59 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l66M41R2020178
	for <@sunmail2sca.sfbay.sun.com:PSARC-record@sun.com>; Fri, 6 Jul 2007 15:04:07 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKS00F1T2MUEZ00@brm-avmta-1.central.sun.com> for PSARC-record@sun.com
 (ORCPT PSARC-record@sun.com); Fri, 06 Jul 2007 16:04:06 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKS00C3C2MQIL30@brm-avmta-1.central.sun.com> for
 PSARC-record@sun.com (ORCPT PSARC-record@sun.com); Fri,
 06 Jul 2007 16:04:03 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id l66M42qH008001	for
 <PSARC-record@sun.com>; Fri, 06 Jul 2007 15:04:02 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0JKS00M012KTBF00@fe-sfbay-10.sun.com>
 (original mail from John.Plocher@Sun.COM)
 for PSARC-record@sun.com (ORCPT PSARC-record@sun.com); Fri,
 06 Jul 2007 15:04:02 -0700 (PDT)
Received: from [192.168.168.4] ([66.166.204.98])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0JKS008XU2MP1190@fe-sfbay-10.sun.com> for
 PSARC-record@sun.com (ORCPT PSARC-record@sun.com); Fri,
 06 Jul 2007 15:04:02 -0700 (PDT)
Date: Fri, 06 Jul 2007 15:04:01 -0700
From: John Plocher <John.Plocher@sun.com>
Subject: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]]
Sender: John.Plocher@sun.com
To: PSARC-record@sun.com
Message-id: <468EBC51.4090902@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
User-Agent: Thunderbird 1.5.0.12 (Macintosh/20070509)
Status: RO
Content-Length: 15222



-------- Original Message --------
Subject: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
Date: Fri, 06 Jul 2007 08:32:46 -0700 (PDT)
From: Wyllys Ingersoll <wyllys@borg.SFBay.Sun.COM>
To: PSARC-ext@sun.com


Template Version: @(#)sac_nextcase 1.63 06/14/07 SMI
This information is Copyright 2007 Sun Microsystems
1. Introduction
     1.1. Project/Component Working Name:
	 kclient version 2
     1.2. Name of Document Author/Supplier:
	 Author:  Shawn Emery
     1.3  Date of This Document:
	06 July, 2007
4. Technical Description
ABSTRACT
--------

This project will add much needed features to the CLI used to
configure a Kerberos client, kclient(1M).  The features that will
be added will allow for the following configurations:

1) Add a Kerberos client to a MS Active Directory (AD) server

2) Add a Kerberos client to a non-Solaris and non-AD Key Distribution Center
    (KDC).  This includes support for servers such as MIT, Heimdal, and
    Shishi.

3) Add a Kerberos client that has no Kerberos administraion privileges.
    These types of clients include:
	a) Client is dynamic.  For example a VPN or DHCP client.
	b) Client is not dynamic, but the local administrator does not currently
	have service keys available for the machine.  It is expected that a
	later time that these keys will be installed on the machine.
	c) Client is not dynamic, but does not want to provide services using
	Kerberos.

4) Add a Kerberos client that is part of a cluster node.

PROPOSAL
--------

We propose:

Additions to the kclient(1M) set of options:

-D domain_list: where domain_list is a list of domains or host names that will
	be mapped to the Kerberos realm specified
-K: configure a client that does not have host/service keys
-h logical_host_name: where logical_host_name is the logical host name of the
	cluster
-m master_kdc: where master_kdc is the master KDC host name
-s pam_service: where pam_service is the service name to be configured for
	Kerberos authentication in the pam.conf(4) file
-t: configure a simple broadcast/multicast NTP client
-T kdc_vendor: specify the KDC of the client to be of kdc_vendor.  Supported
vendors are currently:
	ms_ad: Microsoft Active Directory
	mit: MIT KDC server
	heimdal: Heimdal KDC server
	shishi: Shishi KDC server

Changes to existing options, yet providing backwards compatibility:

-k kdc_list: where kdc_list is a list of KDC host names, if -m is not used then
	the first KDC in the list is assummed to be the master (to preserve old
	behavior).  Note KDC host names are used verbatim

In addition we propose to add the following profile tag-values, respectively:

MSAD: MS AD server configuration (1 or 0, 1 indicating a MS AD client)
RMAP: domain or host names separated by commas (e.g.
	"example.com,host.example.com")
NOKEY: no keys (1 or 0, 1 indicating client w/o service keys)
KDCVENDOR: specifies which vendor the KDC is.  Currently supported values are
	"ms_ad", "mit", "heimdal", and "shishi".
LHN: logical host name of cluster (value set to the cluster's logical host name)
MAS: master KDC host name
PAM: PAM service names separated by commas (e.g. "sshd-kbdint,dtlogin")
NTP: NTP client (1 or 0, 1 indicating a NTP client)

Changes to existing tag-values, but providing backwards compatibility:

KDC: now a list of KDC host names separated by commas (e.g. "kdc1,kdc2").  If
	MASTER is not defined the first KDC in the list is assummed to be the
	master.  Note KDC host names are used verbatim

to support non-interactive Kerberos client configurations.  See the man page
for more information.

The major differences between the options is the ability to create a keytab
file and which change password protocol is supported by the servers.  Here
is a matrix that indicates which is used by the clients for the various types
of servers:

		MIT<1.4	Heimdal	Shishi	AD	Solaris	No keys		MIT1.4+
-------------------------------------------------------------------------------
option (-t)	mit	heimdal	shishi	ms_ad	none	-K		none
-------------------------------------------------------------------------------
keytab					X	X			X
-------------------------------------------------------------------------------
no keytab	X	X	X			X
-------------------------------------------------------------------------------
RPC change pw					X	X		X
-------------------------------------------------------------------------------
non-RPC chpw	X	X	X	X
-------------------------------------------------------------------------------

DOCUMENTATION
-------------

Updates to the kclient(1M) man page and the Security Service's System
Administrative Guide document will be made.

kclient(1M) update as follows:
NAME
      kclient - set up a machine as a Kerberos client

SYNOPSIS
-     /usr/sbin/kclient [-n] [-R realm] [-k  kdc]  [-a  adminuser]
-     [-c filepath] [-d dnsarg] [-f fqdn_list] [-p profile]
+     /usr/sbin/kclient [ -K ] [ -R realm ] [ -a adminuser ]
+     [ -c filepath ] [ -d dnsarg ] [ -f fqdn_list ] [ -h logical_host_name ]
+     [ -k kdc_list ] [ -m master_kdc ] [ -n ] [ -p profile ]
+     [ -s pam_service ] [ -t ] [ -T kdc_vendor ]

DESCRIPTION
      You can use the kclient utility to:

        o  Configure a machine as a Kerberos client for  a  speci-
...
        o  Optionally  setup  a  machine  to  do   server   and/or
           host/domain  name-to-realm  mapping lookups by means of
           DNS.
+
+      o  Optionally configure a Kerberos client to a MS Active Directory
+	  server.  This will generate a keytab file with the Kerberos client's
+	  service keys populated.
+
+      o  Optionally setup a Kerberos client that has no service keys.
+	  This is useful when the client does not require service keys, because
+	  the client does not wish to host a service that uses Kerberos for
+	  security.
+
+      o  Optionally configure a Kerberos client that is part of a cluster.
+	  This option requires the logical host name of the cluster so that
+	  the proper service keys are created and populated in the clients
+	  keytab file.
+
+      o  Optionally setup a Kerberos client to join an environment that
+	  consists of Kerberos servers that are non-Solaris and non MS Active
+	  Directory servers.
+
+      o  Optionally configure pam.conf(4) to use Kerberos authentication for
+	  specified services.
+
+      o  Optionally configure the client as a simple NTP broadcast/multicast
+	  client.
+
+      o  Optionally specify custom domain/host name to realm name mappings.
+
+      o  Optionally setup the Kerberos client to use multiple KDC servers.

      The kclient utility needs to be run on  the  client  machine
      with  root permission and can be run either interactively or
      non-interactively.  In the non-interactive  mode,  the  user
      feeds  in  the  required  inputs  by  means  of  a  profile,
      command-line  options,  or  a  combination  of  profile  and
      command-line  options.  The  user is prompted for "required"
-    parameter values (realm, kdc, and adminuser), if found miss-
+    parameter values (realm and kdc), if found miss-
      ing  in  the  non-interactive  run.  The interactive mode is
      invoked when the utility is  run  without  any  command-line
      arguments.

      Both the interactive and non-interactive  forms  of  kclient
-    always  add  the  host/fqdn entry to the local host's keytab
-    file. They also require the user to enter the  password  for
+    may  add  the  host/fqdn entry to the local host's keytab
+    file. They also may require the user to enter the  password  for
      the  administrative  user  requested, to obtain the Kerberos
      Ticket Granting Ticket (TGT) for adminuser.  The  host/fqdn,
-    nfs/fqdn,  and  root/fqdn  principals  are  added to the KDC
-    database (if not already present) before their  addition  to
+    nfs/fqdn, and root/fqdn principals may be added to the KDC
+    database (if not already present) before their possible addition to
      the local host's keytab.
...
      -n

          Set up the machine for  kerberized  NFS.  This  involves
-        making  changes  to  nfssec.conf(4)  and addition of the
-        nfs/fqdn and root/fqdn entries to the local host's  key-
-        tab file.
+        making changes to krb5* security flavors in nfssec.conf(4).
+	 This option will also add nfs/fqdn and root/fqdn entries to
+	 the local host's keytab file if the -K option has not been specified.
+
      -R [ realm]

          Specifies the Kerberos realm.

-    -k [ kdc]
-
-        Specifies the machine to be used  as  the  Kerberos  Key
-        Distribution Center (KDC).
+    -k kdc_list
+
+	 The -k option specifies the KDC host names for the Kerberos client.
+	 kdc_list is a comma separated list of KDCs.  If the -m option is not
+	 used then it is assummed that the first (or only) host in kdc_list
+	 is the master KDC host name.  Note that the list specified is used
+	 verbatim.  This is helpful when specifying non-fully qualified KDC
+	 host names that can be canonicalized by DNS.

      -a [ adminuser ]

          Specifies the Kerberos administrative user.

+    -T kdc_vendor
+	 Configure the Kerberos client to be one a third party server.
+	 Valid kdc_vendor currently supported are:
+
+		"ms_ad": Microsoft Active Directory
+		"mit": MIT KDC server
+		"heimdal": Heimdal KDC server
+		"shishi": Shishi KDC server
+
+	 Knowing the administrative password will be required in
+	 order to join the client to the server if the ms_ad option is
+	 specified.
+
      -c [ filepath ]

          Specifies the pathname to the krb5.conf(4) master  file,
          to  be copied over to the local host. The path specified
          normally points to a master copy on a  remote  host  and
...
          host/domain  name-to-realm  mapping  by  means  of  DNS.
          dns_fallback is a superset and does DNS lookups for both
          the servers and the host/domain name-to-realm mapping. A
          lookup option of none specifies that DNS is not be  used
          for any kind of mapping lookup.
+
+    -D domain_list
+
+	 Specifies the host and/or domain names to be mapped to the Kerberos
+	 client's default realm name.  domain_list is a comma separated list,
+	 for example "example.com,host1.example.com".  If the -D option is not
+	 used then the client's domain is only used for this mapping.  For
+	 example, if the client is host1.eng.example.com then the domain that is
+	 mapped to the EXAMPLE.COM realm is example.com.
+
+    -K
+
+        Configure the Kerberos client without service keys, which are usually
+	 stored in /etc/krb5/krb5.keytab.  This is useful in the following
+	 scenarios:
+
+		* The client IP address is dynamically assigned and therefore
+		does not host Kerberized services.
+		* Client has a static IP address, but does not want to host
+		any Kerberized services.
+		* Client has a static IP address, but the local administrator
+		does not currently have service keys available for the
+		machine.  It is	expected that in a later time, these keys
+		will be installed on the machine.

      -f [ fqdn_list]

          This  option   creates   a   service   principal   entry
          (host/nfs/root)  associated  with  each  of  the  listed
          fqdn's, if required, and subsequently adds  the  entries
...
          qualified DNS domain names.

          This option is especially useful in Kerberos realms hav-
          ing  systems  offering kerberized services, but situated
          in multiple different DNS domains.
+
+    -h  logical_host_name
+
+	 Specifies that the Kerberos client is a node in a cluster.  The
+	 logical_host_name is the logical host name given to the cluster.
+	 The resulting /etc/krb5/krb5.conf and /etc/krb5/krb5.keytab files
+	 must be manually copied over to the other members of the cluster.
+
+    -m master_kdc
+
+	 This option specified the master KDC to be used by the Kerberos client.
+	 master_kdc is the host name of the master KDC for the client.
+	 If the -m option is not used then it assummed that the first KDC host
+	 name listed with the -k option is the master KDC.
+
      -p [ profile]

          Specifies the profile to be used to enable  the  reading
          in  of  the  values  of  all the parameters required for
          setup of the machine as a Kerberos client.
...
          The profile should have entries in the format:

          PARAM <value>

          Valid PARAM entries are: REALM,  KDC,  ADMIN,  FILEPATH,
-        NFS,   DNSLOOKUP,  and  FQDN.   These  profile  entries
-        correspond to the -R [realm], -k [kdc], -a  [adminuser],
-        -c  [filepath],  -n,  -d  [dnsarg],  and  -f [fqdn_list]
-        command-line  options,  respectively.  Any  other  PARAM
-        entry is considered invalid and is ignored.
+        NFS, DNSLOOKUP, FQDN, NOKEY, NOSOL, LHN, KDCVENDOR, RMAP, MAS, PAM,
+	 and NTP.
+
+	 These profile entries correspond to the -R [realm], -k [kdc_list],
+	 -a [adminuser], -c [filepath], -n, -d [dnsarg], -f [fqdn_list],
+	 -K, -h [logical_host_name], -T [kdc_vendor], -D [domain_list],
+	 -m [master_kdc], -s [pam_service], and -t command-line options,
+	 respectively.  Any other PARAM entry is considered invalid and is
+	 ignored.

          The NFS profile entry can have a value of 0 (do nothing)
          or  1  (operation is requested). Any other value is con-
          sidered invalid and is ignored.
...
+    -s pam_service
+
+	 This specifies the PAM service names that are specified in pam_service
+	 to authenticate through Kerberos foremost.  Using this option updates
+	 pam.conf(4) to include pam_krb5(5) to existing authentication stacks
+	 for the specified service(s) in pam_service.  An example of a possible
+	 pam_service is "dtlogin,sshd-kbdint".
+
+    -t
+
+	 Configures the client to be a NTP broadcast/multicast client if it
+	 has not already been configured to be one.
+
...
      ADMIN clntconfig
      FILEPATH /net/example1.com/export/krb5.conf
      NFS 0
      DNSLOOKUP none

+    Example 3: Setting Up a Kerberos Client That Has a Dynamic IP Address
+
+    In this example a Kerberos client is a DHCP client that has a dynamic IP
+    address.  This client does not wish to host any Kerberized services and
+    therefore does not require a keytab (/etc/krb5/krb5.keytab) file.
+
+    For this type of client the administrator would issue the following command
+    to configure this machine to be a Kerberos client of the `ABC.COM` realm
+    with the KDC server `kdc1.example.com`:
+
+    # /usr/sbin/kclient -K -R EXAMPLE.COM -k kdc1.example.com
+
FILES
      /etc/krb5/kadm5.acl

          Kerberos access control list (ACL) file.


INTERFACE STABILITY AND RELEASE BINDINGS
----------------------------------------

These new options for kclient have the same stability and binding values as
the original case for kclient, PSARC/2003/148:

Interface	Stability	Release Binding

kclient(1M)	Evolving	micro/patch

Note that the new interface taxonomy would consider this Uncommitted.

6. Resources and Schedule
     6.4. Steering Committee requested information
    	6.4.1. Consolidation C-team Name:
		ON
     6.5. ARC review type: FastTrack
     6.6. ARC Exposure: open


From carlsonj@phorcys.east.sun.com Sun Jul  8 11:13:47 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l68IDknP008199
	for <psarc-ext@sac.sfbay.sun.com>; Sun, 8 Jul 2007 11:13:47 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l68IBp7E003473
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Sun, 8 Jul 2007 19:11:52 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKV00003H7RYM00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Sun, 08 Jul 2007 11:11:51 -0700 (PDT)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKV00KWTH7QI4B0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Sun,
 08 Jul 2007 11:11:51 -0700 (PDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.1+Sun/8.14.1) with ESMTP id l68IBn4b026932; Sun,
 08 Jul 2007 14:11:49 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.1+Sun/8.14.1/Submit) id l68IBnW1026929; Sun,
 08 Jul 2007 14:11:49 -0400 (EDT)
Date: Sun, 08 Jul 2007 14:11:49 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
To: Wyllys Ingersoll <wyllys@borg.SFBay.Sun.COM>
Cc: PSARC-ext@sun.com
Message-id: <18065.10469.405649.972650@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
Status: RO
Content-Length: 890

Wyllys Ingersoll writes:
> -t: configure a simple broadcast/multicast NTP client

Why is this part of kclient?  Though having a tool to administer NTP
clients would probably be helpful (and having it tied into something
like DHCP and thus automatic would be much more helpful still), it
seems out of place here.

> -T kdc_vendor: specify the KDC of the client to be of kdc_vendor.  Supported
> vendors are currently:
> 	ms_ad: Microsoft Active Directory
> 	mit: MIT KDC server
> 	heimdal: Heimdal KDC server
> 	shishi: Shishi KDC server

Why does the user have to specify this?  Is there no way for the
client implementation to detect the proper KDC variant to use?

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 1 Network Drive         71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From roland.mainz@nrubsig.org Sun Jul  8 16:14:04 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l68NE2Pp011564
	for <psarc-ext@sac.sfbay.Sun.COM>; Sun, 8 Jul 2007 16:14:03 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l68NC22O017366;
	Mon, 9 Jul 2007 07:12:06 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKV00M03V44KL00@nwk-avmta-2.sfbay.sun.com>; Sun,
 08 Jul 2007 16:12:04 -0700 (PDT)
Received: from sca-ea-mail-1.sun.com ([192.18.43.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKV008UTV44TP50@nwk-avmta-2.sfbay.sun.com>; Sun,
 08 Jul 2007 16:12:04 -0700 (PDT)
Received: from relay22.sun.com
 (relay22.sun.com [192.12.251.34] (may be forged))	by sca-ea-mail-1.sun.com
 (8.13.7+Sun/8.12.9) with ESMTP id l68NC3Ms009433; Sun,
 08 Jul 2007 23:12:04 +0000 (GMT)
Received: from mms22es.sun.com ([150.143.232.34] [150.143.232.34])
 by relay22.sun.com with ESMTP id BT-MMP-272684; Sun,
 08 Jul 2007 23:12:03 +0000 (Z)
Received: from mms23bas.mms.us.syntegra.com
 (mms23bas.mms.us.syntegra.com [192.12.251.50]) by mms22es.sun.com with ESMTP
 id BT-MMP-89413; Sun, 08 Jul 2007 23:12:03 +0000 (Z)
Received: from mail-in-05.arcor-online.net ([151.189.21.45] [151.189.21.45])
 by relay23.sun.com with ESMTP id BT-MMP-3886340; Sun,
 08 Jul 2007 23:12:03 +0000 (Z)
Received: from mail-in-01-z2.arcor-online.net
 (mail-in-01-z2.arcor-online.net [151.189.8.13])	by mail-in-05.arcor-online.net
 (Postfix) with ESMTP id 8DB3C1838F4; Mon, 09 Jul 2007 01:12:02 +0200 (CEST)
Received: from mail-in-09.arcor-online.net
 (mail-in-09.arcor-online.net [151.189.21.49])
	by mail-in-01-z2.arcor-online.net (Postfix) with ESMTP id 7C44413EC9E; Mon,
 09 Jul 2007 01:12:02 +0200 (CEST)
Received: from jupiterb48.nrubsig.org
 (dslb-084-058-199-101.pools.arcor-ip.net [84.58.199.101])
	by mail-in-09.arcor-online.net (Postfix) with ESMTP id 62C9434A6A7; Mon,
 09 Jul 2007 01:12:02 +0200 (CEST)
Received: from nrubsig.org (localhost [127.0.0.1])	by jupiterb48.nrubsig.org
 (8.13.8+Sun/8.13.8) with ESMTP id l68NBxmX001882; Mon,
 09 Jul 2007 01:12:00 +0200 (CEST)
Date: Mon, 09 Jul 2007 01:11:59 +0200
From: Roland Mainz <roland.mainz@nrubsig.org>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
Sender: gisburn@jupiterb48.nrubsig.org
To: James Carlson <james.d.carlson@sun.com>
Cc: Wyllys Ingersoll <wyllys@borg.SFBay.Sun.COM>, PSARC-ext@sun.com
Message-id: <46916F3F.C4C1E34F@nrubsig.org>
MIME-version: 1.0
X-Mailer: Mozilla 4.76 [en] (X11; U; SunOS 5.11 sun4u)
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-Accept-Language: en
X-PMX-Version: 5.2.0.264296
X-Virus-Scanned: ClamAV 0.90.3/3610/Sun Jul  8 13:24:35 2007 on
 mail-in-09.arcor-online.net
X-Virus-Status: Clean
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL>
Status: RO
Content-Length: 1441

James Carlson wrote:
> Wyllys Ingersoll writes:
> > -t: configure a simple broadcast/multicast NTP client
> 
> Why is this part of kclient?  Though having a tool to administer NTP
> clients would probably be helpful (and having it tied into something
> like DHCP and thus automatic would be much more helpful still), it
> seems out of place here.

Ugh... since when it is recommended to mix untrusted services like DHCP
with Kerberos5 ?

> > -T kdc_vendor: specify the KDC of the client to be of kdc_vendor.  Supported
> > vendors are currently:
> >       ms_ad: Microsoft Active Directory
> >       mit: MIT KDC server
> >       heimdal: Heimdal KDC server
> >       shishi: Shishi KDC server
> 
> Why does the user have to specify this?  Is there no way for the
> client implementation to detect the proper KDC variant to use?

Erm, AFAIK this will end like the HTTP's "User-Agent:" - you cannot rely
on the value since the submitter may change it intentionally in some
cases to emulate other clients (for example Mozilla/FireFox allows to
set the "User-Agent:" string to any value and other browsers like
Konqueror have a sophosticated feature to set a specific User-Agent
value per domain or URL).
IMO it would be nice to keep such an option around...

----

Bye,
Roland

-- 
  __ .  . __
 (o.\ \/ /.o) roland.mainz@nrubsig.org
  \__\/\/__/  MPEG specialist, C&&JAVA&&Sun&&Unix programmer
  /O /==\ O\  TEL +49 641 7950090
 (;O/ \/ \O;)

From richlowe@richlowe.net Sun Jul  8 17:02:45 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6902imJ012175
	for <psarc-ext@sac.sfbay.Sun.COM>; Sun, 8 Jul 2007 17:02:44 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l6900k4b026094;
	Mon, 9 Jul 2007 08:00:47 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKV00405XDAE300@nwk-avmta-2.sfbay.sun.com>; Sun,
 08 Jul 2007 17:00:46 -0700 (PDT)
Received: from sca-ea-mail-1.sun.com ([192.18.43.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKV008ZYXD9TQ80@nwk-avmta-2.sfbay.sun.com>; Sun,
 08 Jul 2007 17:00:45 -0700 (PDT)
Received: from relay41i.sun.com ([192.5.209.70])
	by sca-ea-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id l6900jYH015538;
 Mon, 09 Jul 2007 00:00:45 +0000 (GMT)
Received: from mms49es.sun.com ([160.41.221.233] [160.41.221.233])
 by relay41i.sun.com with ESMTP id BT-MMP-237342; Mon,
 09 Jul 2007 00:00:45 +0000 (Z)
Received: from relay43i.sun.com ([192.5.209.74] [192.5.209.74])
 by mms49es.sun.com with ESMTP id BT-MMP-812078; Mon,
 09 Jul 2007 00:00:45 +0000 (Z)
Received: from rwcrmhc13.comcast.net ([204.127.192.83] [204.127.192.83])
 by relay4i.sun.com with ESMTP id BT-MMP-1941498; Mon,
 09 Jul 2007 00:00:45 +0000 (Z)
Received: from [192.168.1.20]
 (c-71-203-214-110.hsd1.tn.comcast.net[71.203.214.110])
 by comcast.net (rwcrmhc13) with ESMTP id <20070709000026m130050uoue>; Mon,
 09 Jul 2007 00:00:44 +0000
Date: Sun, 08 Jul 2007 20:00:19 -0400
From: Richard Lowe <richlowe@richlowe.net>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <18065.10469.405649.972650@gargle.gargle.HOWL>
To: James Carlson <james.d.carlson@sun.com>
Cc: PSARC-ext@sun.com
Message-id: <46917A93.8090309@richlowe.net>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.0 (X11/20070605)
Status: RO
Content-Length: 580

James Carlson wrote:
> Wyllys Ingersoll writes:

[trimming Wyllys from the Cc, since borg.sfbay appears to lack an MX]

>> -t: configure a simple broadcast/multicast NTP client
> 
> Why is this part of kclient?  Though having a tool to administer NTP
> clients would probably be helpful (and having it tied into something
> like DHCP and thus automatic would be much more helpful still), it
> seems out of place here.

I'd assume due to kerberos's sensitivity to time skew, though I agree I'm 
not sure they're tied together to the degree kclient should configure both.

-- Rich


From Shawn.Emery@sun.com Sun Jul  8 22:26:05 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l695Q4OT015687
	for <psarc-ext@sac.sfbay.Sun.COM>; Sun, 8 Jul 2007 22:26:04 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l695O5ic004281
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 9 Jul 2007 13:24:09 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW00L0BCC7HM00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Sun, 08 Jul 2007 23:24:07 -0600 (MDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW00KX4CC6JQ10@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Sun,
 08 Jul 2007 23:24:06 -0600 (MDT)
Received: from fe-amer-03.sun.com ([192.18.108.177])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l695O63X023473	for
 <PSARC-ext@sun.com>; Mon, 09 Jul 2007 05:24:06 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JKW00101B6DUC00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Sun,
 08 Jul 2007 23:24:06 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.32.192])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JKW00H7UCBZ6M20@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Sun, 08 Jul 2007 23:24:06 -0600 (MDT)
Date: Sun, 08 Jul 2007 23:21:47 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <18065.10469.405649.972650@gargle.gargle.HOWL>
Sender: Shawn.Emery@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: PSARC-ext@sun.com
Message-id: <4691C5EB.9010406@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 1262

James Carlson wrote:
> Wyllys Ingersoll writes:
>   
>> -t: configure a simple broadcast/multicast NTP client
>>     
>
> Why is this part of kclient?  Though having a tool to administer NTP
> clients would probably be helpful (and having it tied into something
> like DHCP and thus automatic would be much more helpful still), it
> seems out of place here.
>   

As Roland, et. al., have mentioned, the Kerberos client could fail to 
authenticate given clock skew with KDCs.  So there is a dependency and 
the administrator may not have control over the network's DHCP servers.

>> -T kdc_vendor: specify the KDC of the client to be of kdc_vendor.  Supported
>> vendors are currently:
>> 	ms_ad: Microsoft Active Directory
>> 	mit: MIT KDC server
>> 	heimdal: Heimdal KDC server
>> 	shishi: Shishi KDC server
>>     
>
> Why does the user have to specify this?  Is there no way for the
> client implementation to detect the proper KDC variant to use?
>   

There is no standard to detect the version of the administrative 
interface.  As Roland mentions having an option would provide a more 
deterministic way using the right interface.  For example, one protocol 
may work with a number of vendors, but another protocol may work more 
affectively.

Shawn.
--

From roland.mainz@nrubsig.org Sun Jul  8 22:49:56 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l695ntin015749
	for <psarc-ext@sac.sfbay.Sun.COM>; Sun, 8 Jul 2007 22:49:56 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l695lrmX009445;
	Mon, 9 Jul 2007 13:47:56 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW00403DFURE00@nwk-avmta-1.sfbay.Sun.COM>; Sun,
 08 Jul 2007 22:47:54 -0700 (PDT)
Received: from sca-ea-mail-1.sun.com ([192.18.43.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW003MUDFURQ20@nwk-avmta-1.sfbay.Sun.COM>; Sun,
 08 Jul 2007 22:47:54 -0700 (PDT)
Received: from relay22.sun.com
 (relay22.sun.com [192.12.251.34] (may be forged))	by sca-ea-mail-1.sun.com
 (8.13.7+Sun/8.12.9) with ESMTP id l695ls26014716; Mon,
 09 Jul 2007 05:47:54 +0000 (GMT)
Received: from mms24es.sun.com ([150.143.232.74] [150.143.232.74])
 by relay22.sun.com with ESMTP id BT-MMP-295556; Mon,
 09 Jul 2007 05:47:53 +0000 (Z)
Received: from mms25bas.mms.us.syntegra.com
 (mms25bas.mms.us.syntegra.com [192.12.251.90]) by mms24es.sun.com with ESMTP
 id BT-MMP-500551; Mon, 09 Jul 2007 05:47:53 +0000 (Z)
Received: from mail-in-06.arcor-online.net ([151.189.21.46] [151.189.21.46])
 by relay21.sun.com with ESMTP id BT-MMP-6235991; Mon,
 09 Jul 2007 05:47:53 +0000 (Z)
Received: from mail-in-04-z2.arcor-online.net
 (mail-in-04-z2.arcor-online.net [151.189.8.16])	by mail-in-06.arcor-online.net
 (Postfix) with ESMTP id 9E6BE31EEDD; Mon, 09 Jul 2007 07:47:52 +0200 (CEST)
Received: from mail-in-08.arcor-online.net
 (mail-in-08.arcor-online.net [151.189.21.48])
	by mail-in-04-z2.arcor-online.net (Postfix) with ESMTP id 8A82CAD91E; Mon,
 09 Jul 2007 07:47:52 +0200 (CEST)
Received: from jupiterb48.nrubsig.org
 (dslb-084-058-199-101.pools.arcor-ip.net [84.58.199.101])
	by mail-in-08.arcor-online.net (Postfix) with ESMTP id 38C842BAEFD; Mon,
 09 Jul 2007 07:47:52 +0200 (CEST)
Received: from nrubsig.org (localhost [127.0.0.1])	by jupiterb48.nrubsig.org
 (8.13.8+Sun/8.13.8) with ESMTP id l695loW4002006; Mon,
 09 Jul 2007 07:47:51 +0200 (CEST)
Date: Mon, 09 Jul 2007 07:47:50 +0200
From: Roland Mainz <roland.mainz@nrubsig.org>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
Sender: gisburn@jupiterb48.nrubsig.org
To: "Shawn M. Emery" <Shawn.Emery@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>, PSARC-ext@sun.com
Message-id: <4691CC06.B7ECCF36@nrubsig.org>
MIME-version: 1.0
X-Mailer: Mozilla 4.76 [en] (X11; U; SunOS 5.11 sun4u)
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-Accept-Language: en
X-PMX-Version: 5.2.0.264296
X-Virus-Scanned: ClamAV 0.90.3/3613/Mon Jul  9 03:16:11 2007 on
 mail-in-08.arcor-online.net
X-Virus-Status: Clean
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <4691C5EB.9010406@sun.com>
Status: RO
Content-Length: 1706

"Shawn M. Emery" wrote:
> James Carlson wrote:
> > Wyllys Ingersoll writes:
> >
> >> -t: configure a simple broadcast/multicast NTP client
> >>
> >
> > Why is this part of kclient?  Though having a tool to administer NTP
> > clients would probably be helpful (and having it tied into something
> > like DHCP and thus automatic would be much more helpful still), it
> > seems out of place here.
> 
> As Roland, et. al., have mentioned, the Kerberos client could fail to
> authenticate given clock skew with KDCs.  So there is a dependency and
> the administrator may not have control over the network's DHCP servers.

Erm, slightly offtopic: Killing or taking over is one of the "classical"
DOS attacks against networks which use Kerberos5 or NIS+ for
authentification. The Kerberos5 (or NIS+) servers/replicas are usually
heavily protected (firewall, seperate room, armed guard, komodo dragons
etc.) but the machines which run the NTP server are usually not that
well protected. Take down the NTP server and fill the network with your
own NTP packets and the whole network becomes unuseable (because no
machine/user/service can get auth tickets anymore).

Or short: The NTP service is _important_ for authentification services
like Kerberos5 or NIS+ and using "untrusted" services like DHCP to
distribute the information for these servers is DANGEROUS. IMO no tool
(including "kclient"/"kserver") should include options which configure a
"trusted" service (like Kerberos5) with an "untrusted" service like DHCP
as basis.

----

Bye,
Roland

-- 
  __ .  . __
 (o.\ \/ /.o) roland.mainz@nrubsig.org
  \__\/\/__/  MPEG specialist, C&&JAVA&&Sun&&Unix programmer
  /O /==\ O\  TEL +49 641 7950090
 (;O/ \/ \O;)

From Michael.Hunter@sun.com Mon Jul  9 00:07:26 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6977PHf017685
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 00:07:25 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6975Rjg020793
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 9 Jul 2007 00:05:30 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW0051SH141Z00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Jul 2007 01:05:28 -0600 (MDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW00KLOH0YJOD0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 01:05:22 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id l6975MRj029414	for
 <PSARC-ext@sun.com>; Mon, 09 Jul 2007 00:05:22 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0JKW00H01GYEUR00@fe-sfbay-09.sun.com>
 (original mail from Michael.Hunter@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 00:05:22 -0700 (PDT)
Received: from sun.com ([10.7.251.174])
 by fe-sfbay-09.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0JKW00H39H0X5WC0@fe-sfbay-09.sun.com>; Mon,
 09 Jul 2007 00:05:22 -0700 (PDT)
Date: Mon, 09 Jul 2007 00:05:21 -0700
From: Michael Hunter <Michael.Hunter@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <46916F3F.C4C1E34F@nrubsig.org>
Sender: Michael.Hunter@sun.com
To: Roland Mainz <roland.mainz@nrubsig.org>
Cc: James Carlson <James.D.Carlson@sun.com>,
        Wyllys Ingersoll <wyllys@borg.SFBay.Sun.COM>, PSARC-ext@sun.com
Message-id: <20070709000521.00001925@localhost>
Organization: SMI
MIME-version: 1.0
X-Mailer: Claws Mail 2.9.2-csw (GTK+ 2.10.11; i386-pc-solaris2.8)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <46916F3F.C4C1E34F@nrubsig.org>
Status: RO
Content-Length: 947

On Mon, 09 Jul 2007 01:11:59 +0200
Roland Mainz <roland.mainz@nrubsig.org> wrote:

> James Carlson wrote:
> > Wyllys Ingersoll writes:
> > > -t: configure a simple broadcast/multicast NTP client
> > 
> > Why is this part of kclient?  Though having a tool to administer NTP
> > clients would probably be helpful (and having it tied into something
> > like DHCP and thus automatic would be much more helpful still), it
> > seems out of place here.
> 
> Ugh... since when it is recommended to mix untrusted services like DHCP
> with Kerberos5 ?
[...]

This says to configure a client which uses broadcast/multicast for
NTP.  How is the attack vector of breaching DHCP different from
breaching broadcast/multicast NTP?

How would you expect different NTP administrative mechanisms to
arbitrate control of the NTP configuration?  time-admin(1) is one such
thing which currently exists.  NWAM will want to also be able to do
this in the future.

			mph

From Shawn.Emery@sun.com Mon Jul  9 00:21:17 2007
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l697LHUb017930
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 00:21:17 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l697JMfi026329
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 9 Jul 2007 00:19:23 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW00303HOBV600@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Jul 2007 00:19:23 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW00H22HOA9FD0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 00:19:23 -0700 (PDT)
Received: from fe-amer-03.sun.com ([192.18.108.177])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l697JMeN006016	for
 <PSARC-ext@sun.com>; Mon, 09 Jul 2007 07:19:22 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JKW00D01HL2CS00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 01:19:22 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.33.24])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JKW00H9JHO96M40@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Jul 2007 01:19:22 -0600 (MDT)
Date: Mon, 09 Jul 2007 01:17:08 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <20070709000521.00001925@localhost>
Sender: Shawn.Emery@sun.com
To: Michael Hunter <Michael.Hunter@sun.com>
Cc: Roland Mainz <roland.mainz@nrubsig.org>,
        James Carlson <James.D.Carlson@sun.com>, PSARC-ext@sun.com
Message-id: <4691E0F4.5020604@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <46916F3F.C4C1E34F@nrubsig.org>
 <20070709000521.00001925@localhost>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 1219

Michael Hunter wrote:
> On Mon, 09 Jul 2007 01:11:59 +0200
> Roland Mainz <roland.mainz@nrubsig.org> wrote:
>
>   
>> James Carlson wrote:
>>     
>>> Wyllys Ingersoll writes:
>>>       
>>>> -t: configure a simple broadcast/multicast NTP client
>>>>         
>>> Why is this part of kclient?  Though having a tool to administer NTP
>>> clients would probably be helpful (and having it tied into something
>>> like DHCP and thus automatic would be much more helpful still), it
>>> seems out of place here.
>>>       
>> Ugh... since when it is recommended to mix untrusted services like DHCP
>> with Kerberos5 ?
>>     
> [...]
>
> This says to configure a client which uses broadcast/multicast for
> NTP.  How is the attack vector of breaching DHCP different from
> breaching broadcast/multicast NTP?
>
> How would you expect different NTP administrative mechanisms to
> arbitrate control of the NTP configuration?  time-admin(1) is one such
> thing which currently exists.  NWAM will want to also be able to do
> this in the future.
>   

Perhaps -t could have an argument that contains a list of NTP servers.  
If a list is not provided then it reverts to configuring the client for 
broadcast/multicast.

Shawn.
--

From roland.mainz@nrubsig.org Mon Jul  9 00:32:10 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l697W9wB018133
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 00:32:09 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l697U8JR002367;
	Mon, 9 Jul 2007 08:30:12 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW00513I6A0300@nwk-avmta-2.sfbay.sun.com>; Mon,
 09 Jul 2007 00:30:10 -0700 (PDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW00H64I659FE0@nwk-avmta-2.sfbay.sun.com>; Mon,
 09 Jul 2007 00:30:05 -0700 (PDT)
Received: from relay23.sun.com
 (relay23.sun.com [192.12.251.54] (may be forged))	by brmea-mail-3.sun.com
 (8.13.6+Sun/8.12.9) with ESMTP id l697U4uf023124; Mon,
 09 Jul 2007 07:30:04 +0000 (GMT)
Received: from mms23es.sun.com ([150.143.232.54] [150.143.232.54])
 by relay23.sun.com with ESMTP id BT-MMP-303215; Mon,
 09 Jul 2007 07:30:04 +0000 (Z)
Received: from relay22.sun.com (relay22.sun.com [192.12.251.34])
 by mms23es.sun.com with ESMTP id BT-MMP-721608; Mon,
 09 Jul 2007 07:30:04 +0000 (Z)
Received: from mail-in-15.arcor-online.net ([151.189.21.55] [151.189.21.55])
 by relay22.sun.com with ESMTP id BT-MMP-4438991; Mon,
 09 Jul 2007 07:30:03 +0000 (Z)
Received: from mail-in-04-z2.arcor-online.net
 (mail-in-04-z2.arcor-online.net [151.189.8.16])	by mail-in-15.arcor-online.net
 (Postfix) with ESMTP id 1C464A4350; Mon, 09 Jul 2007 09:30:03 +0200 (CEST)
Received: from mail-in-08.arcor-online.net
 (mail-in-08.arcor-online.net [151.189.21.48])
	by mail-in-04-z2.arcor-online.net (Postfix) with ESMTP id ECD94ADB1B; Mon,
 09 Jul 2007 09:30:02 +0200 (CEST)
Received: from jupiterb48.nrubsig.org
 (dslb-084-058-199-101.pools.arcor-ip.net [84.58.199.101])
	by mail-in-08.arcor-online.net (Postfix) with ESMTP id 533CE2BAEFA; Mon,
 09 Jul 2007 09:30:02 +0200 (CEST)
Received: from nrubsig.org (localhost [127.0.0.1])	by jupiterb48.nrubsig.org
 (8.13.8+Sun/8.13.8) with ESMTP id l697U0Vh002055; Mon,
 09 Jul 2007 09:30:01 +0200 (CEST)
Date: Mon, 09 Jul 2007 09:30:00 +0200
From: Roland Mainz <roland.mainz@nrubsig.org>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
Sender: gisburn@jupiterb48.nrubsig.org
To: Michael Hunter <Michael.Hunter@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>,
        Wyllys Ingersoll <wyllys@borg.SFBay.Sun.COM>, PSARC-ext@sun.com
Message-id: <4691E3F8.F7CD939E@nrubsig.org>
MIME-version: 1.0
X-Mailer: Mozilla 4.76 [en] (X11; U; SunOS 5.11 sun4u)
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-Accept-Language: en
X-PMX-Version: 5.2.0.264296
X-Virus-Scanned: ClamAV 0.90.3/3613/Mon Jul  9 03:16:11 2007 on
 mail-in-08.arcor-online.net
X-Virus-Status: Clean
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <46916F3F.C4C1E34F@nrubsig.org>
 <20070709000521.00001925@localhost>
Status: RO
Content-Length: 2123

Michael Hunter wrote:
> On Mon, 09 Jul 2007 01:11:59 +0200
> Roland Mainz <roland.mainz@nrubsig.org> wrote:
> > James Carlson wrote:
> > > Wyllys Ingersoll writes:
> > > > -t: configure a simple broadcast/multicast NTP client
> > >
> > > Why is this part of kclient?  Though having a tool to administer NTP
> > > clients would probably be helpful (and having it tied into something
> > > like DHCP and thus automatic would be much more helpful still), it
> > > seems out of place here.
> >
> > Ugh... since when it is recommended to mix untrusted services like DHCP
> > with Kerberos5 ?
> [...]
> 
> This says to configure a client which uses broadcast/multicast for
> NTP.

Urgh...

> How is the attack vector of breaching DHCP different from
> breaching broadcast/multicast NTP?

It isn't much different except that people may spend more time in
securing the DHCP server (assuming they use DHCP... for example we avoid
it for the core servers and most of the other stuff unless it's really
not important if the students or someone else take the affected
computers down with their "games"...) then spending time in securing the
NTP server (e.g. they don't expect a DOS attack using this path).
However broadcast/multicast is IMO the wrong method unless you both
"own" the network (e.g. you have 100% control who adds machines (usually
"open" environments like universities don't have full control)) and
deploy NTP authentification (we used a different solution - we use fixed
IP addresses for the core server machines which provide
Kerberos5/NIS+/LDAP/NTP/SMTP/etc. services, configured all manageable
switches to make sure the IP address matches the EthernetID of the
server and use NTP auth. for those clients who support it. It's not
perfect but surived the last years in our environment...).

> How would you expect different NTP administrative mechanisms to
> arbitrate control of the NTP configuration? 

Erm... what do you mean ?

----

Bye,
Roland

-- 
  __ .  . __
 (o.\ \/ /.o) roland.mainz@nrubsig.org
  \__\/\/__/  MPEG specialist, C&&JAVA&&Sun&&Unix programmer
  /O /==\ O\  TEL +49 641 7950090
 (;O/ \/ \O;)

From roland.mainz@nrubsig.org Mon Jul  9 00:37:41 2007
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l697bf7a018160
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 00:37:41 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l697ZkkF029032;
	Mon, 9 Jul 2007 00:35:46 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW00F01IFMOQ00@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 09 Jul 2007 00:35:46 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW005IMIFLXB50@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 09 Jul 2007 00:35:45 -0700 (PDT)
Received: from relay43i.sun.com ([192.5.209.74])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l697Zi3t006999; Mon,
 09 Jul 2007 07:35:45 +0000 (GMT)
Received: from mms48es.sun.com ([160.41.221.231] [160.41.221.231])
 by relay43i.sun.com with ESMTP id BT-MMP-262151; Mon,
 09 Jul 2007 07:35:44 +0000 (Z)
Received: from relay42i.sun.com ([192.5.209.72] [192.5.209.72])
 by mms48es.sun.com with ESMTP id BT-MMP-1146665; Mon,
 09 Jul 2007 07:35:44 +0000 (Z)
Received: from mail-in-11.arcor-online.net ([151.189.21.51] [151.189.21.51])
 by relay4i.sun.com with ESMTP id BT-MMP-2129679; Mon,
 09 Jul 2007 07:35:44 +0000 (Z)
Received: from mail-in-09-z2.arcor-online.net
 (mail-in-09-z2.arcor-online.net [151.189.8.21])	by mail-in-11.arcor-online.net
 (Postfix) with ESMTP id 534D012A3B; Mon, 09 Jul 2007 09:35:43 +0200 (CEST)
Received: from mail-in-01.arcor-online.net
 (mail-in-01.arcor-online.net [151.189.21.41])
	by mail-in-09-z2.arcor-online.net (Postfix) with ESMTP id 3DB032918B9; Mon,
 09 Jul 2007 09:35:43 +0200 (CEST)
Received: from jupiterb48.nrubsig.org
 (dslb-084-058-199-101.pools.arcor-ip.net [84.58.199.101])
	by mail-in-01.arcor-online.net (Postfix) with ESMTP id 0D6D519B32C; Mon,
 09 Jul 2007 09:35:43 +0200 (CEST)
Received: from nrubsig.org (localhost [127.0.0.1])	by jupiterb48.nrubsig.org
 (8.13.8+Sun/8.13.8) with ESMTP id l697Zf8O002061; Mon,
 09 Jul 2007 09:35:42 +0200 (CEST)
Date: Mon, 09 Jul 2007 09:35:41 +0200
From: Roland Mainz <roland.mainz@nrubsig.org>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
Sender: gisburn@jupiterb48.nrubsig.org
To: "Shawn M. Emery" <Shawn.Emery@sun.com>
Cc: Michael Hunter <Michael.Hunter@sun.com>,
        James Carlson <James.D.Carlson@sun.com>, PSARC-ext@sun.com
Message-id: <4691E54D.702F254D@nrubsig.org>
MIME-version: 1.0
X-Mailer: Mozilla 4.76 [en] (X11; U; SunOS 5.11 sun4u)
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-Accept-Language: en
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <46916F3F.C4C1E34F@nrubsig.org>
 <20070709000521.00001925@localhost> <4691E0F4.5020604@sun.com>
Status: RO
Content-Length: 1882

"Shawn M. Emery" wrote:
> Michael Hunter wrote:
> > On Mon, 09 Jul 2007 01:11:59 +0200
> > Roland Mainz <roland.mainz@nrubsig.org> wrote:
> >
> >> James Carlson wrote:
> >>
> >>> Wyllys Ingersoll writes:
> >>>
> >>>> -t: configure a simple broadcast/multicast NTP client
> >>>>
> >>> Why is this part of kclient?  Though having a tool to administer NTP
> >>> clients would probably be helpful (and having it tied into something
> >>> like DHCP and thus automatic would be much more helpful still), it
> >>> seems out of place here.
> >>>
> >> Ugh... since when it is recommended to mix untrusted services like DHCP
> >> with Kerberos5 ?
> >>
> > [...]
> >
> > This says to configure a client which uses broadcast/multicast for
> > NTP.  How is the attack vector of breaching DHCP different from
> > breaching broadcast/multicast NTP?
> >
> > How would you expect different NTP administrative mechanisms to
> > arbitrate control of the NTP configuration?  time-admin(1) is one such
> > thing which currently exists.  NWAM will want to also be able to do
> > this in the future.
> 
> Perhaps -t could have an argument that contains a list of NTP servers.
> If a list is not provided then it reverts to configuring the client for
> broadcast/multicast.

... or "kclient" could check whether the "ntp" client service is running
(and working) on the current machine and refuse to work if there is no
ntp service active (unless a specific option (like --no-ntp-needed) is
provided (this may be required for systems (like Solaris running as a
VMware or XEN guest OS) where other mechanisms do the time
syncronisation work)) ... that may be much easier and keep both items
(NTP vs. Kerberos5) seperate...

----

Bye,
Roland

-- 
  __ .  . __
 (o.\ \/ /.o) roland.mainz@nrubsig.org
  \__\/\/__/  MPEG specialist, C&&JAVA&&Sun&&Unix programmer
  /O /==\ O\  TEL +49 641 7950090
 (;O/ \/ \O;)

From Michael.Hunter@sun.com Mon Jul  9 01:03:21 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6983LTi018823
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 01:03:21 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6981R6F000696
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 9 Jul 2007 01:01:27 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW00I0DJME9000@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Jul 2007 01:01:26 -0700 (PDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW0052IJMDXM60@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 01:01:25 -0700 (PDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id l6981PZt007105	for
 <PSARC-ext@sun.com>; Mon, 09 Jul 2007 01:01:25 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0JKW00D01JJSOU00@fe-sfbay-10.sun.com>
 (original mail from Michael.Hunter@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 01:01:25 -0700 (PDT)
Received: from sun.com ([10.7.251.174])
 by fe-sfbay-10.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0JKW008RMJMCW420@fe-sfbay-10.sun.com>; Mon,
 09 Jul 2007 01:01:25 -0700 (PDT)
Date: Mon, 09 Jul 2007 01:01:24 -0700
From: Michael Hunter <Michael.Hunter@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <4691E3F8.F7CD939E@nrubsig.org>
Sender: Michael.Hunter@sun.com
To: Roland Mainz <roland.mainz@nrubsig.org>
Cc: James Carlson <James.D.Carlson@sun.com>,
        Wyllys Ingersoll <wyllys@borg.SFBay.Sun.COM>, PSARC-ext@sun.com
Message-id: <20070709010124.00006e77@localhost>
Organization: SMI
MIME-version: 1.0
X-Mailer: Claws Mail 2.9.2-csw (GTK+ 2.10.11; i386-pc-solaris2.8)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <46916F3F.C4C1E34F@nrubsig.org>
 <20070709000521.00001925@localhost> <4691E3F8.F7CD939E@nrubsig.org>
Status: RO
Content-Length: 1037

On Mon, 09 Jul 2007 09:30:00 +0200
Roland Mainz <roland.mainz@nrubsig.org> wrote:

> Michael Hunter wrote:
> > On Mon, 09 Jul 2007 01:11:59 +0200
> > Roland Mainz <roland.mainz@nrubsig.org> wrote:
> > > James Carlson wrote:
> > > > Wyllys Ingersoll writes:
> > > > > -t: configure a simple broadcast/multicast NTP client
[...]
> > How would you expect different NTP administrative mechanisms to
> > arbitrate control of the NTP configuration? 
> 
> Erm... what do you mean ?
[...]

When there are multiple paths to configure a service who wins?  The GUI
is used to configure NTP, then kclient is used to also configure it at
a different time, and finally something picks up a value from DHCP that
its been told to use to configure NTP with. Something stops working or
worse yet security assumptions are silently overriden.  If there is
just one admin this is just painful and you can almost blame it on user
error. If there are two or more its maddening and its entirely our
fault for having created the mess in the first place.

			mph

From Michael.Hunter@sun.com Mon Jul  9 01:07:52 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6987qlm018862
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 01:07:52 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6985tnD001530
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 9 Jul 2007 01:05:58 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW0080FJTYL500@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Jul 2007 01:05:58 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW006KBJTWA010@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 01:05:56 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id l6985u5A000366	for
 <PSARC-ext@sun.com>; Mon, 09 Jul 2007 01:05:56 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0JKW00C01JSO7R00@fe-sfbay-09.sun.com>
 (original mail from Michael.Hunter@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 01:05:56 -0700 (PDT)
Received: from sun.com ([10.7.251.174])
 by fe-sfbay-09.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb
 28 2007)) with ESMTPSA id <0JKW001N8JTVOU50@fe-sfbay-09.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 01:05:56 -0700 (PDT)
Date: Mon, 09 Jul 2007 01:05:55 -0700
From: Michael Hunter <Michael.Hunter@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <4691E54D.702F254D@nrubsig.org>
Sender: Michael.Hunter@sun.com
To: Roland Mainz <roland.mainz@nrubsig.org>
Cc: "Shawn M. Emery" <Shawn.Emery@sun.com>, PSARC-ext@sun.com,
        James Carlson <James.D.Carlson@sun.com>
Message-id: <20070709010555.000055a4@localhost>
Organization: SMI
MIME-version: 1.0
X-Mailer: Claws Mail 2.9.2-csw (GTK+ 2.10.11; i386-pc-solaris2.8)
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <46916F3F.C4C1E34F@nrubsig.org>
 <20070709000521.00001925@localhost> <4691E0F4.5020604@sun.com>
 <4691E54D.702F254D@nrubsig.org>
Status: RO
Content-Length: 956

On Mon, 09 Jul 2007 09:35:41 +0200
Roland Mainz <roland.mainz@nrubsig.org> wrote:

[...]
> ... or "kclient" could check whether the "ntp" client service is running
> (and working) on the current machine and refuse to work if there is no
> ntp service active (unless a specific option (like --no-ntp-needed) is
> provided (this may be required for systems (like Solaris running as a
> VMware or XEN guest OS) where other mechanisms do the time
> syncronisation work)) ... that may be much easier and keep both items
> (NTP vs. Kerberos5) seperate...
[...]

But this seems in conflict with the security concern.

And define "working".  Has it found a server?  Did it find the right
server?  Did it converge?  How long ago did it talk to the server?  If
any of these are true now but are no longer true in the future is that
going to break some important assumption that kclient need to
revalidate?  If so how are you going to discover that situation?

		mph

From Darren.Moffat@sun.com Mon Jul  9 02:10:10 2007
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l699AAEA019845
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 02:10:10 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6997QD7041909
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 9 Jul 2007 03:07:26 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKW00C0LMPQCM00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Jul 2007 03:08:14 -0600 (MDT)
Received: from gmp-ea-fw-1.sun.com ([129.156.42.5])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKW00AAJMPLS710@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 03:08:12 -0600 (MDT)
Received: from d1-emea-10.sun.com (d1-emea-10.sun.com [192.18.2.120])
	by gmp-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l69989gA000443	for
 <PSARC-ext@sun.com>; Mon, 09 Jul 2007 09:08:09 +0000 (GMT)
Received: from conversion-daemon.d1-emea-10.sun.com by d1-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JKW00401MOHYH00@d1-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Jul 2007 10:08:09 +0100 (BST)
Received: from [129.156.173.21] by d1-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JKW00MR2MPKEP00@d1-emea-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Jul 2007 10:08:09 +0100 (BST)
Date: Mon, 09 Jul 2007 10:08:08 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <4691CC06.B7ECCF36@nrubsig.org>
Sender: Darren.Moffat@sun.com
To: Roland Mainz <roland.mainz@nrubsig.org>
Cc: "Shawn M. Emery" <Shawn.Emery@sun.com>,
        James Carlson <James.D.Carlson@sun.com>, PSARC-ext@sun.com
Message-id: <4691FAF8.9090905@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <4691C5EB.9010406@sun.com>
 <4691CC06.B7ECCF36@nrubsig.org>
User-Agent: Thunderbird 2.0.0.0 (X11/20070605)
Status: RO
Content-Length: 591

Roland Mainz wrote:
> Or short: The NTP service is _important_ for authentification services
> like Kerberos5 or NIS+ and using "untrusted" services like DHCP to
> distribute the information for these servers is DANGEROUS. IMO no tool
> (including "kclient"/"kserver") should include options which configure a
> "trusted" service (like Kerberos5) with an "untrusted" service like DHCP
> as basis.

kclient already does because it allows you to use DNS to lookup REALM 
and KDC information.

But IMO that is offtopic here, the original issue was around kclient and 
NTP.

-- 
Darren J Moffat

From Nicolas.Williams@sun.com Mon Jul  9 08:45:01 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l69Fj1Iw026481
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 08:45:01 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l69Fh5FX027137;
	Mon, 9 Jul 2007 08:43:05 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKX006034ZT9C00@nwk-avmta-2.sfbay.sun.com>; Mon,
 09 Jul 2007 08:43:05 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKX00LL94ZTPPE0@nwk-avmta-2.sfbay.sun.com>; Mon,
 09 Jul 2007 08:43:05 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id l69FftVI014179;
 Mon, 09 Jul 2007 10:41:55 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id l69FftCP014178; Mon,
 09 Jul 2007 10:41:55 -0500 (CDT)
Date: Mon, 09 Jul 2007 10:41:54 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <20070709010555.000055a4@localhost>
To: Michael Hunter <Michael.Hunter@sun.com>
Cc: Roland Mainz <roland.mainz@nrubsig.org>,
        "Shawn M. Emery" <Shawn.Emery@sun.com>, PSARC-ext@sun.com,
        James Carlson <James.D.Carlson@sun.com>
Message-id: <20070709154154.GA13207@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <46916F3F.C4C1E34F@nrubsig.org>
 <20070709000521.00001925@localhost> <4691E0F4.5020604@sun.com>
 <4691E54D.702F254D@nrubsig.org> <20070709010555.000055a4@localhost>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 703

On Mon, Jul 09, 2007 at 01:05:55AM -0700, Michael Hunter wrote:
> On Mon, 09 Jul 2007 09:35:41 +0200
> Roland Mainz <roland.mainz@nrubsig.org> wrote:
> 
> [...]
> > ... or "kclient" could check whether the "ntp" client service is running
> [...]
> 
> But this seems in conflict with the security concern.
> 
> And define "working".  Has it found a server?  Did it find the right
> [...]

And it's unfriendly.  Kerberos V requires synchronized time.

It would technically be possible for systems with host principals and
keys to use the Kerberos V KDC protocols securly to obtain a timestamp
from the KDC with 1 second resolution.  But we do not have a tool that
implements this at this point.

Nico
-- 

From Nicolas.Williams@sun.com Mon Jul  9 08:56:06 2007
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l69Fu6mr027167
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Jul 2007 08:56:06 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l69FrImF057653;
	Mon, 9 Jul 2007 09:53:21 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKX007135IA9W00@nwk-avmta-2.sfbay.sun.com>; Mon,
 09 Jul 2007 08:54:10 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKX00L8R5I9PZE0@nwk-avmta-2.sfbay.sun.com>; Mon,
 09 Jul 2007 08:54:09 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id l69Fqwpc014191;
 Mon, 09 Jul 2007 10:52:58 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id l69FqwBn014190; Mon,
 09 Jul 2007 10:52:58 -0500 (CDT)
Date: Mon, 09 Jul 2007 10:52:58 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: kclient version 2 [PSARC/2007/401 FastTrack timeout 07/13/2007]
In-reply-to: <46916F3F.C4C1E34F@nrubsig.org>
To: Roland Mainz <roland.mainz@nrubsig.org>
Cc: James Carlson <James.D.Carlson@sun.com>,
        Wyllys Ingersoll <wyllys@borg.SFBay.Sun.COM>, PSARC-ext@sun.com
Message-id: <20070709155257.GB13207@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.2.0.264296
References: <200707061532.l66FWkH7017376@borg.SFBay.Sun.COM>
 <18065.10469.405649.972650@gargle.gargle.HOWL> <46916F3F.C4C1E34F@nrubsig.org>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1977

On Mon, Jul 09, 2007 at 01:11:59AM +0200, Roland Mainz wrote:
> James Carlson wrote:
> > > -T kdc_vendor: specify the KDC of the client to be of kdc_vendor.  Supported
> > > vendors are currently:
> > >       ms_ad: Microsoft Active Directory
> > >       mit: MIT KDC server
> > >       heimdal: Heimdal KDC server
> > >       shishi: Shishi KDC server
> > 
> > Why does the user have to specify this?  Is there no way for the
> > client implementation to detect the proper KDC variant to use?
> 
> Erm, AFAIK this will end like the HTTP's "User-Agent:" - you cannot rely
> on the value since the submitter may change it intentionally in some
> cases to emulate other clients (for example Mozilla/FireFox allows to
> set the "User-Agent:" string to any value and other browsers like
> Konqueror have a sophosticated feature to set a specific User-Agent
> value per domain or URL).
> IMO it would be nice to keep such an option around...

The Kerberos V protocol is effectively a standard (Proposed Standard in
IETF parlance), and interoperable.

However there is no standard password changing protocol for Kerberos V,
and there is an abundance of non-interoperable protocols for that:

 - MIT kpasswd v1
 - RFC3244 (what MS AD implements), an extension of MIT kpasswd v1)
 - kadmin with AUTH_GSSAPI
 - kadmin with RPCSEC_GSS
 - Heimdal's kadmin

The client needs to know which password changing protocol to try.

The client could probe to find out.  For the three protocols that
Solaris 10 supports this should be feasible without much difficulty or
pain for the user.  But even if the i-team could implement auto-
detection of this, avoiding auto-detection means avoiding potential
downgrade attacks.

IOW, I can see a future case adding auto-detection support for this sort
of thing as a default, but I'm not sure that we'll not want to provide
an option to tie things down.

OTOH, I am mildly concerned that kclient probably doesn't record the -T
option anywhere.

Nico
-- 

From gww@eng.sun.com Tue Jul 10 16:33:15 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6ANXE4g000772
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 10 Jul 2007 16:33:15 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6ANVBWL009928
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 11 Jul 2007 00:31:19 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKZ00001LC58L00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 10 Jul 2007 16:31:17 -0700 (PDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKZ003GJLC4F380@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 10 Jul 2007 16:31:16 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6ANVGCc013617; Tue, 10 Jul 2007 16:31:16 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6ANYX7Y016409; Tue,
 10 Jul 2007 16:34:33 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6ANYXsk016408; Tue,
 10 Jul 2007 16:34:33 -0700 (PDT)
Date: Tue, 10 Jul 2007 16:34:33 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
To: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <200707102334.l6ANYXsk016408@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 319

> -s pam_service: where pam_service is the service name to be configured for
> 	Kerberos authentication in the pam.conf(4) file

	What becomes of the account and password module type stacks?
	I understand that session is a pam_krb5(5) no-op, but for
	completeness what becomes of the session module type stack?

Gary..

From Shawn.Emery@sun.com Tue Jul 10 21:19:55 2007
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6B4JtCp005434
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 10 Jul 2007 21:19:55 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6B4H9XZ046405
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 10 Jul 2007 22:17:09 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JKZ00603YM0GY00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 10 Jul 2007 22:18:00 -0600 (MDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JKZ001QPYLWA830@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 10 Jul 2007 22:18:00 -0600 (MDT)
Received: from fe-amer-03.sun.com ([192.18.108.177])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6B4HuKF015708	for
 <PSARC-ext@sun.com>; Wed, 11 Jul 2007 04:17:56 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JKZ00501Y2V0A00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 10 Jul 2007 22:17:56 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.32.111])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JKZ00HXTYLQ6MH6@mail-amer.sun.com>; Tue,
 10 Jul 2007 22:17:56 -0600 (MDT)
Date: Tue, 10 Jul 2007 22:15:36 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
In-reply-to: <200707102334.l6ANYXsk016408@marduk.eng.sun.com>
Sender: Shawn.Emery@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <46945968.5070203@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707102334.l6ANYXsk016408@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 497

Gary Winiger wrote:
>> -s pam_service: where pam_service is the service name to be configured for
>> 	Kerberos authentication in the pam.conf(4) file
>>     
>
> 	What becomes of the account and password module type stacks?
>   
Those are left untouched as the configurations that I've seen for these 
can range quite a bit.
> 	I understand that session is a pam_krb5(5) no-op, but for
> 	completeness what becomes of the session module type stack?
>   
This is left untouched as well.

Shawn.
--

From gww@eng.sun.com Wed Jul 11 07:43:03 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6BEh3N4016643
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Jul 2007 07:43:03 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6BEf55F008589
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Wed, 11 Jul 2007 07:41:07 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL000403RGIOD00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 11 Jul 2007 07:41:06 -0700 (PDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL00010VRGIUJ90@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 11 Jul 2007 07:41:06 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6BEf5Vl019767; Wed, 11 Jul 2007 07:41:05 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6BEiNtG016983; Wed,
 11 Jul 2007 07:44:23 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6BEiNm6016982; Wed,
 11 Jul 2007 07:44:23 -0700 (PDT)
Date: Wed, 11 Jul 2007 07:44:23 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
To: gww@eng.sun.com, Shawn.Emery@sun.com
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <200707111444.l6BEiNm6016982@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 1159

> Gary Winiger wrote:
> >> -s pam_service: where pam_service is the service name to be configured for
> >> 	Kerberos authentication in the pam.conf(4) file
> >>     
> >
> > 	What becomes of the account and password module type stacks?
> >   
> Those are left untouched as the configurations that I've seen for these 
> can range quite a bit.
> > 	I understand that session is a pam_krb5(5) no-op, but for
> > 	completeness what becomes of the session module type stack?
> >   
> This is left untouched as well.

	Now I am confused.  The default delivered pam.conf(4) doesn't
	deliver account management, password or session entries for
	pam_krb5(5).  Are you saying these stacks are unnecessary and
	the pam_krb5(5) man page is incorrect?
	As I read kclient, I would have expected all I needed to correctly
	configure a service would have been -s <service>.
	If that's not the case, then it seems to me that either the
	pam_krb5(5) man page needs correction, or kclient needs to do more
	work, or the kclient man page needs to say -s only does part of the
	job and the admin must use $EDITOR to do the rest as described on
	the pam_krb5(5) man page.

Gary..

From Shawn.Emery@sun.com Thu Jul 12 08:59:27 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6CFxQww007436
	for <psarc-ext@sac.sfbay.Sun.COM>; Thu, 12 Jul 2007 08:59:27 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l6CFvJHY008393
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 12 Jul 2007 23:57:28 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL200901PNR4200@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Thu, 12 Jul 2007 08:57:27 -0700 (PDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL20055SPNQ9650@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Thu,
 12 Jul 2007 08:57:26 -0700 (PDT)
Received: from fe-amer-06.sun.com ([192.18.108.180])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6CFvQvP026437	for
 <PSARC-ext@Sun.COM>; Thu, 12 Jul 2007 15:57:26 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JL200M01PDXC400@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 12 Jul 2007 09:57:26 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.36.156])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JL2001G5PNOQFQ6@mail-amer.sun.com>; Thu,
 12 Jul 2007 09:57:26 -0600 (MDT)
Date: Thu, 12 Jul 2007 09:55:08 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
In-reply-to: <200707111444.l6BEiNm6016982@marduk.eng.sun.com>
Sender: Shawn.Emery@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <46964EDC.5020705@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707111444.l6BEiNm6016982@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 1810

Gary Winiger wrote:
>> Gary Winiger wrote:
>>     
>>>> -s pam_service: where pam_service is the service name to be configured for
>>>> 	Kerberos authentication in the pam.conf(4) file
>>>>     
>>>>         
>>> 	What becomes of the account and password module type stacks?
>>>   
>>>       
>> Those are left untouched as the configurations that I've seen for these 
>> can range quite a bit.
>>     
>>> 	I understand that session is a pam_krb5(5) no-op, but for
>>> 	completeness what becomes of the session module type stack?
>>>   
>>>       
>> This is left untouched as well.
>>     
>
> 	Now I am confused.  The default delivered pam.conf(4) doesn't
> 	deliver account management, password or session entries for
> 	pam_krb5(5).  Are you saying these stacks are unnecessary and
> 	the pam_krb5(5) man page is incorrect?
>   

The man page describes various permutations of these stacks.  Which one 
is incorrect?  That is difficult to know.  Should we provide another 
interface that we can specify the control flag and hope that they know 
which account authorities will be updated during change password?

> 	As I read kclient, I would have expected all I needed to correctly
> 	configure a service would have been -s <service>.
> 	If that's not the case, then it seems to me that either the
> 	pam_krb5(5) man page needs correction, or kclient needs to do more
> 	work, or the kclient man page needs to say -s only does part of the
> 	job and the admin must use $EDITOR to do the rest as described on
> 	the pam_krb5(5) man page.
>   

The point was to cover a broad range of environments w/o having to know 
about control flags and their affects.  But if this is not sufficient we 
need to either increase the complexity of the interface or make more 
assumptions of their environment.

Shawn.
--

From gww@eng.sun.com Thu Jul 12 12:50:28 2007
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6CJoSBN017661
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 12 Jul 2007 12:50:28 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6CJmTrm000518
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Thu, 12 Jul 2007 12:48:30 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL3009070CT6K00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Thu, 12 Jul 2007 12:48:29 -0700 (PDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL3004LP0CSOB50@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 12 Jul 2007 12:48:28 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6CJmR33017975; Thu, 12 Jul 2007 12:48:27 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6CJpkKE019886; Thu,
 12 Jul 2007 12:51:46 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6CJpkQZ019885; Thu,
 12 Jul 2007 12:51:46 -0700 (PDT)
Date: Thu, 12 Jul 2007 12:51:46 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
To: gww@eng.sun.com, Shawn.Emery@Sun.COM
Cc: PSARC-ext@Sun.COM, wyllys@borg.sfbay.sun.com
Message-id: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 2338


> >> This is left untouched as well.
> >>     
> >
> > 	Now I am confused.  The default delivered pam.conf(4) doesn't
> > 	deliver account management, password or session entries for
> > 	pam_krb5(5).  Are you saying these stacks are unnecessary and
> > 	the pam_krb5(5) man page is incorrect?
> >   
> 
> The man page describes various permutations of these stacks.  Which one 
> is incorrect?  That is difficult to know.  Should we provide another 
> interface that we can specify the control flag and hope that they know 
> which account authorities will be updated during change password?

	Let's try again.  I initially asked about the stacks other than
	the auth stack and how that related to the -s option.  I understood
	you to say that nothing was done with them: "This is left untouched
	as well."  So I tried to ask how the other stacks were intended
	to be populated in the pam.conf file.  If they were unnecessary,
	then why were they shown in pam_krb5(5) and why does the default
	pam.conf(4) state:
# Support for Kerberos V5 authentication and example configurations can
# be found in the pam_krb5(5) man page under the "EXAMPLES" section.

	So, I'm confused about what this project is doing or recommending
	relative to the -s option.

> > 	As I read kclient, I would have expected all I needed to correctly
> > 	configure a service would have been -s <service>.
> > 	If that's not the case, then it seems to me that either the
> > 	pam_krb5(5) man page needs correction, or kclient needs to do more
> > 	work, or the kclient man page needs to say -s only does part of the
> > 	job and the admin must use $EDITOR to do the rest as described on
> > 	the pam_krb5(5) man page.
> 
> The point was to cover a broad range of environments w/o having to know 
> about control flags and their affects.  But if this is not sufficient we 
> need to either increase the complexity of the interface or make more 
> assumptions of their environment.

	From the project spec and the various man pages and the default
	pam.conf, I don't know what is sufficient.  If adding a single
	line to the auth stack of a service will do it or not.
	What if that service is not in the existing pam.conf file, does
	it take the default service stack and replicate it adding pam_krb5?
	
	I'm having trouble understanding the efficacy of -s.

Gary..

From Shawn.Emery@sun.com Thu Jul 12 16:37:04 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6CNb3n9026762
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 12 Jul 2007 16:37:04 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6CNYvnH015540
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 13 Jul 2007 00:35:05 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL30050ZAUG5J00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Thu, 12 Jul 2007 16:35:04 -0700 (PDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL300LPUAUF6F60@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Thu,
 12 Jul 2007 16:35:03 -0700 (PDT)
Received: from fe-amer-06.sun.com ([192.18.108.180])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6CNZ37b025392	for
 <PSARC-ext@Sun.COM>; Thu, 12 Jul 2007 23:35:03 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JL3009018XNRP00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 12 Jul 2007 17:35:03 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.33.151])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JL3001A9AU3QDQ6@mail-amer.sun.com>; Thu,
 12 Jul 2007 17:35:03 -0600 (MDT)
Date: Thu, 12 Jul 2007 17:32:34 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
In-reply-to: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
Sender: Shawn.Emery@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <4696BA12.1040303@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 2997

Gary Winiger wrote:
>>>> This is left untouched as well.
>>>>     
>>>>         
>>> 	Now I am confused.  The default delivered pam.conf(4) doesn't
>>> 	deliver account management, password or session entries for
>>> 	pam_krb5(5).  Are you saying these stacks are unnecessary and
>>> 	the pam_krb5(5) man page is incorrect?
>>>   
>>>       
>> The man page describes various permutations of these stacks.  Which one 
>> is incorrect?  That is difficult to know.  Should we provide another 
>> interface that we can specify the control flag and hope that they know 
>> which account authorities will be updated during change password?
>>     
>
> 	Let's try again.  I initially asked about the stacks other than
> 	the auth stack and how that related to the -s option.  I understood
> 	you to say that nothing was done with them: "This is left untouched
> 	as well."  So I tried to ask how the other stacks were intended
> 	to be populated in the pam.conf file.  If they were unnecessary,
> 	then why were they shown in pam_krb5(5) and why does the default
> 	pam.conf(4) state:
> # Support for Kerberos V5 authentication and example configurations can
> # be found in the pam_krb5(5) man page under the "EXAMPLES" section.
>
> 	So, I'm confused about what this project is doing or recommending
> 	relative to the -s option.
>
>   
>>> 	As I read kclient, I would have expected all I needed to correctly
>>> 	configure a service would have been -s <service>.
>>> 	If that's not the case, then it seems to me that either the
>>> 	pam_krb5(5) man page needs correction, or kclient needs to do more
>>> 	work, or the kclient man page needs to say -s only does part of the
>>> 	job and the admin must use $EDITOR to do the rest as described on
>>> 	the pam_krb5(5) man page.
>>>       
>> The point was to cover a broad range of environments w/o having to know 
>> about control flags and their affects.  But if this is not sufficient we 
>> need to either increase the complexity of the interface or make more 
>> assumptions of their environment.
>>     
>
> 	From the project spec and the various man pages and the default
> 	pam.conf, I don't know what is sufficient.  If adding a single
> 	line to the auth stack of a service will do it or not.
> 	What if that service is not in the existing pam.conf file, does
> 	it take the default service stack and replicate it adding pam_krb5?
> 	
> 	I'm having trouble understanding the efficacy of -s.
>   

The -s option will place a pam_krb5(5) auth entry in the specified 
service stack.  If the service stack does not exist it could base the 
new stack off of the "other" stack and place the entry after the 
pam_unix_cred(5).  If the other module types were to be included I could 
make an assumption that they are performing password/account expiration 
and that the only auth tok to be changed is Kerberos.  Any failure would 
be considered optional and would continue with the other modules.  Is 
this a safe assumption for most cases?

Shawn.
--

From Darren.Moffat@Sun.COM Fri Jul 13 04:50:26 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6DBoPWD008028
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 13 Jul 2007 04:50:25 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6DBmKh7024905
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 13 Jul 2007 12:48:27 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL400G0D8SQNV00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 13 Jul 2007 04:48:26 -0700 (PDT)
Received: from gmp-ea-fw-1.sun.com ([129.156.42.5])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL4003BN8SO7CA0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 13 Jul 2007 04:48:25 -0700 (PDT)
Received: from d1-emea-10.sun.com (d1-emea-10.sun.com [192.18.2.120])
	by gmp-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6DBmO6i014397	for
 <PSARC-ext@sun.com>; Fri, 13 Jul 2007 11:48:24 +0000 (GMT)
Received: from conversion-daemon.d1-emea-10.sun.com by d1-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JL400K018R1G800@d1-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 13 Jul 2007 12:48:24 +0100 (BST)
Received: from [129.156.173.21] by d1-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JL40007L8SMW800@d1-emea-10.sun.com>; Fri,
 13 Jul 2007 12:48:23 +0100 (BST)
Date: Fri, 13 Jul 2007 12:48:22 +0100
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <4696BA12.1040303@sun.com>
Sender: Darren.Moffat@Sun.COM
To: "Shawn M. Emery" <Shawn.Emery@Sun.COM>
Cc: Gary Winiger <gww@eng.sun.com>, PSARC-ext@Sun.COM,
        wyllys@borg.sfbay.sun.com
Message-id: <46976686.1060801@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
 <4696BA12.1040303@sun.com>
User-Agent: Thunderbird 2.0.0.0 (X11/20070605)
Status: RO
Content-Length: 1244

Shawn M. Emery wrote:
> The -s option will place a pam_krb5(5) auth entry in the specified 
> service stack.  If the service stack does not exist it could base the 
> new stack off of the "other" stack and place the entry after the 
> pam_unix_cred(5).  If the other module types were to be included I could 
> make an assumption that they are performing password/account expiration 
> and that the only auth tok to be changed is Kerberos.  Any failure would 
> be considered optional and would continue with the other modules.  Is 
> this a safe assumption for most cases?

I think that is actually a bad idea and could easily lead to quite 
strange configurations.   Past experience with modifying the pam.conf 
has show that it is unfortunately very complex as soon as there is a 
single change from one of the default versions we have shipped.

I think this area needs some more thought.  I suspect what what we 
really want to do with kclient is put the pam.conf file in to one of the 
known good and recommended states that is documented in pam_krb5(5) already.

Maybe this project should be using PSARC 2005/217 and delivering one of 
more include files that have the different recommended ways of using 
pam_krb5.


-- 
Darren J Moffat

From Shawn.Emery@Sun.COM Fri Jul 13 08:57:19 2007
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6DFvJVB013237
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 13 Jul 2007 08:57:19 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6DFtMks005094
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 13 Jul 2007 08:55:22 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL400905K89NJ00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 13 Jul 2007 09:55:21 -0600 (MDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL400926K80LU00@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 13 Jul 2007 09:55:12 -0600 (MDT)
Received: from fe-amer-03.sun.com ([192.18.108.177])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6DFtCH7016109	for
 <PSARC-ext@sun.com>; Fri, 13 Jul 2007 15:55:12 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JL400401K4DDB00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 13 Jul 2007 09:55:12 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.35.114])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JL400CNVK7YC4F4@mail-amer.sun.com>; Fri,
 13 Jul 2007 09:55:12 -0600 (MDT)
Date: Fri, 13 Jul 2007 09:52:49 -0600
From: "Shawn M. Emery" <Shawn.Emery@Sun.COM>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <46976686.1060801@Sun.COM>
Sender: Shawn.Emery@Sun.COM
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: Gary Winiger <gww@eng.sun.com>, PSARC-ext@Sun.COM,
        wyllys@borg.sfbay.sun.com
Message-id: <46979FD1.1000200@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
 <4696BA12.1040303@sun.com> <46976686.1060801@Sun.COM>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 1452

Darren J Moffat wrote:
> Shawn M. Emery wrote:
>> The -s option will place a pam_krb5(5) auth entry in the specified 
>> service stack.  If the service stack does not exist it could base the 
>> new stack off of the "other" stack and place the entry after the 
>> pam_unix_cred(5).  If the other module types were to be included I 
>> could make an assumption that they are performing password/account 
>> expiration and that the only auth tok to be changed is Kerberos.  Any 
>> failure would be considered optional and would continue with the 
>> other modules.  Is this a safe assumption for most cases?
>
> I think that is actually a bad idea and could easily lead to quite 
> strange configurations.   Past experience with modifying the pam.conf 
> has show that it is unfortunately very complex as soon as there is a 
> single change from one of the default versions we have shipped.
>
> I think this area needs some more thought.  I suspect what what we 
> really want to do with kclient is put the pam.conf file in to one of 
> the known good and recommended states that is documented in 
> pam_krb5(5) already.
>
> Maybe this project should be using PSARC 2005/217 and delivering one 
> of more include files that have the different recommended ways of 
> using pam_krb5.

Given the complexity of the interface necessary to do this and the 
difficulty to represent all customer environments I will drop the -s 
option from kclient.

Shawn.
--

From gww@eng.sun.com Fri Jul 13 10:08:07 2007
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6DH87QN014992
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 13 Jul 2007 10:08:07 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6DH68nW026936
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Fri, 13 Jul 2007 10:06:10 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL400D2HNI9ZG00@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Fri, 13 Jul 2007 11:06:09 -0600 (MDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL400991NI8LP30@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Fri,
 13 Jul 2007 11:06:08 -0600 (MDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6DH66Sp000554; Fri, 13 Jul 2007 10:06:06 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6DH9REr021251; Fri,
 13 Jul 2007 10:09:27 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6DH9RCI021250; Fri,
 13 Jul 2007 10:09:27 -0700 (PDT)
Date: Fri, 13 Jul 2007 10:09:27 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
To: Darren.Moffat@sun.com, Shawn.Emery@sun.com
Cc: gww@eng.sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <200707131709.l6DH9RCI021250@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 1071


> > Maybe this project should be using PSARC 2005/217 and delivering one 
> > of more include files that have the different recommended ways of 
> > using pam_krb5.

	That would indeed be a useful addition to kclient and IMO,
	a good way to implement -s.  Here is a preconfigured kerberos
	pam stack.  -s adds to the existing pam.conf
	<service> auth include		<preconfigured krb5 pam stack>
	<service> account include	<preconfigured krb5 pam stack>
	<service> session include	<preconfigured krb5 pam stack>
	<service> passwd include	<preconfigured krb5 pam stack>

> Given the complexity of the interface necessary to do this and the 
> difficulty to represent all customer environments I will drop the -s 
> option from kclient.

	Sigh, don't give up yet.  Indeed Kerberos was one of the reasons
	for doing the include control flag.  Then you never have to screw
	around with i.pamconf.  Seems like a great win all the way around.

	Darren, thanks for the refreshing suggestion.  I'd even be happy
	to do the libpam backport should kclient -s be backported ;-)

Gary..

From Shawn.Emery@sun.com Fri Jul 13 21:23:15 2007
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6E4NEbL002483
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 13 Jul 2007 21:23:14 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6E4LHVc027771
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 13 Jul 2007 21:21:17 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL500L01IRETH00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 13 Jul 2007 21:21:14 -0700 (PDT)
Received: from brmea-mail-3.sun.com ([192.18.98.34])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL500JQ4IRDI800@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 13 Jul 2007 21:21:13 -0700 (PDT)
Received: from fe-amer-03.sun.com ([192.18.108.177])
	by brmea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6E4LD26025844	for
 <PSARC-ext@sun.com>; Sat, 14 Jul 2007 04:21:13 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JL500001H89RM00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 13 Jul 2007 22:21:13 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.32.107])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JL5004RHIQQDB40@mail-amer.sun.com>; Fri,
 13 Jul 2007 22:21:13 -0600 (MDT)
Date: Fri, 13 Jul 2007 22:18:26 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <46976686.1060801@Sun.COM>
Sender: Shawn.Emery@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, PSARC-ext@sun.com,
        wyllys@borg.sfbay.sun.com
Message-id: <46984E92.5070604@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
 <4696BA12.1040303@sun.com> <46976686.1060801@Sun.COM>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 2278

Darren J Moffat wrote:
> Shawn M. Emery wrote:
>> The -s option will place a pam_krb5(5) auth entry in the specified 
>> service stack.  If the service stack does not exist it could base the 
>> new stack off of the "other" stack and place the entry after the 
>> pam_unix_cred(5).  If the other module types were to be included I 
>> could make an assumption that they are performing password/account 
>> expiration and that the only auth tok to be changed is Kerberos.  Any 
>> failure would be considered optional and would continue with the 
>> other modules.  Is this a safe assumption for most cases?
>
> I think that is actually a bad idea and could easily lead to quite 
> strange configurations.   Past experience with modifying the pam.conf 
> has show that it is unfortunately very complex as soon as there is a 
> single change from one of the default versions we have shipped.
>
> I think this area needs some more thought.  I suspect what what we 
> really want to do with kclient is put the pam.conf file in to one of 
> the known good and recommended states that is documented in 
> pam_krb5(5) already.
>
> Maybe this project should be using PSARC 2005/217 and delivering one 
> of more include files that have the different recommended ways of 
> using pam_krb5.

Setting include files apart there still should be a way of specifying 
how Kerberos interacts with other modules.  -s could include a qualifier 
for pam_krb5's control flag with:

-s service_name:{binding | sufficient | optional | required | 
requisite}[,...]

As an example:

-s xscreensaver:optional,dtlogin:optional

would configure files:

other auth requisite           pam_authtok_get.so.1
other auth required           pam_dhkeys.so.1
other auth required           pam_unix_cred.so.1
other auth required           pam_unix_auth.so.1
other auth optional           pam_krb5.so.1

other   account requisite       pam_roles.so.1
other   account required       pam_unix_account.so.1
other   account required       pam_krb5.so.1

other   password required      pam_dhkeys.so.1
other   password requisite      pam_authtok_get.so.1
other   password requisite      pam_authtok_check.so.1
other   password required      pam_authtok_store.so.1
other   password optional      pam_krb5.so.1

Shawn.
--

From Darren.Moffat@sun.com Mon Jul 16 03:21:00 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6GAKxw7008298
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 16 Jul 2007 03:20:59 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6GAIvic001547
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 16 Jul 2007 11:18:59 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JL900J05ONLZ500@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 16 Jul 2007 03:18:57 -0700 (PDT)
Received: from gmp-ea-fw-1.sun.com ([129.156.42.5])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JL900H55ONK7UE0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 16 Jul 2007 03:18:57 -0700 (PDT)
Received: from d1-emea-09.sun.com (d1-emea-09.sun.com [192.18.2.119])
	by gmp-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6GAItYB005558	for
 <PSARC-ext@sun.com>; Mon, 16 Jul 2007 10:18:55 +0000 (GMT)
Received: from conversion-daemon.d1-emea-09.sun.com by d1-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JL900801OFNOQ00@d1-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 16 Jul 2007 11:18:55 +0100 (BST)
Received: from [129.156.173.21] by d1-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JL900BMBONAXF10@d1-emea-09.sun.com>; Mon,
 16 Jul 2007 11:18:46 +0100 (BST)
Date: Mon, 16 Jul 2007 11:18:46 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <46984E92.5070604@sun.com>
Sender: Darren.Moffat@sun.com
To: "Shawn M. Emery" <Shawn.Emery@sun.com>
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com,
        Gary Winiger <gww@eng.sun.com>
Message-id: <469B4606.5070709@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
 <4696BA12.1040303@sun.com> <46976686.1060801@Sun.COM>
 <46984E92.5070604@sun.com>
User-Agent: Thunderbird 2.0.0.0 (X11/20070605)
Status: RO
Content-Length: 1629

Shawn M. Emery wrote:
>> I think this area needs some more thought.  I suspect what what we 
>> really want to do with kclient is put the pam.conf file in to one of 
>> the known good and recommended states that is documented in 
>> pam_krb5(5) already.
>>
>> Maybe this project should be using PSARC 2005/217 and delivering one 
>> of more include files that have the different recommended ways of 
>> using pam_krb5.
> 
> Setting include files apart there still should be a way of specifying 
> how Kerberos interacts with other modules.  -s could include a qualifier 
> for pam_krb5's control flag with:
> 
> -s service_name:{binding | sufficient | optional | required | 
> requisite}[,...]
> 
> As an example:
> 
> -s xscreensaver:optional,dtlogin:optional

That is interesting but it assumes you always want it at the end.  As 
you can see this is quite complex.

I think that setting up pam.conf to do one of the normal Kerberos 
configurations is a key part of this project.

My recommendation is that the kclient interface be quite high level eg:

As per the pam_krb5(5) examples: first, only, optional are the keywords 
here.

kclient should (probably in conjunction with some other part of the 
system that we can work out offline) only update the pam.conf file if it 
is in a known original state.

If there are any customisations to pam.conf for the  services listed 
then kclient should not attempt to change those.  It is just too hard to 
work out where the correct place to put the module in a customised stack 
is.  In this case it should tell the operator that they must do it 
themselves.

-- 
Darren J Moffat

From gww@eng.sun.com Mon Jul 16 12:00:25 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6GJ0Pv8018864
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 16 Jul 2007 12:00:25 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6GIwOaW011476
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Mon, 16 Jul 2007 11:58:25 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLA00F0HCPC9Q00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Mon, 16 Jul 2007 11:58:24 -0700 (PDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLA00D7LCPC4540@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Mon,
 16 Jul 2007 11:58:24 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6GIwMCj010851; Mon, 16 Jul 2007 11:58:22 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6GJ1lMs023644; Mon,
 16 Jul 2007 12:01:47 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6GJ1lHo023643; Mon,
 16 Jul 2007 12:01:47 -0700 (PDT)
Date: Mon, 16 Jul 2007 12:01:47 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
To: Darren.Moffat@sun.com, Shawn.Emery@sun.com
Cc: gww@eng.sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <200707161901.l6GJ1lHo023643@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 1047


> Setting include files apart there still should be a way of specifying 
> how Kerberos interacts with other modules.  -s could include a qualifier 
> for pam_krb5's control flag with:
> 
> -s service_name:{binding | sufficient | optional | required | 
> requisite}[,...]
> 
> As an example:
> 
> -s xscreensaver:optional,dtlogin:optional
     ^^^^^^^^^^^^

> would configure files:
[snip]
> other auth required           pam_unix_auth.so.1
> other auth optional           pam_krb5.so.1
  ^^^^^

	I'm missing seeing the correlation between service name and this
	example.

	In any case, I'm concerned that unless pam.conf is the default
	one delivered changing the other stacks, or cloning the other
	stacks for the -s specified services and adding pam_krb5.so.1
	optional or otherwise is a wise thing to do.

	I do believe that there's value in kclient being able to completely
	set up a kerberos client even (or especially) for sites with pam.conf
	changes in other areas.  That's why I seconded Darren's comments
	about using include.

Gary..

From Shawn.Emery@sun.com Mon Jul 16 13:27:10 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6GKR9kd021535
	for <psarc-ext@sac.sfbay.Sun.COM>; Mon, 16 Jul 2007 13:27:09 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l6GKOu7k029234
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 17 Jul 2007 04:25:08 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLA00607GPTJ400@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 16 Jul 2007 13:25:05 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLA003QJGPTAS30@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 16 Jul 2007 13:25:05 -0700 (PDT)
Received: from fe-amer-06.sun.com ([192.18.108.180])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6GKP4Ks010787	for
 <PSARC-ext@sun.com>; Mon, 16 Jul 2007 20:25:04 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JLA00F01GPF7E00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 16 Jul 2007 14:25:04 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.36.199])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JLA001HQGPRQDF7@mail-amer.sun.com>; Mon,
 16 Jul 2007 14:25:04 -0600 (MDT)
Date: Mon, 16 Jul 2007 14:22:40 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <200707161901.l6GJ1lHo023643@marduk.eng.sun.com>
Sender: Shawn.Emery@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <469BD390.4040405@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707161901.l6GJ1lHo023643@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 1481

Gary Winiger wrote:
>> Setting include files apart there still should be a way of specifying 
>> how Kerberos interacts with other modules.  -s could include a qualifier 
>> for pam_krb5's control flag with:
>>
>> -s service_name:{binding | sufficient | optional | required | 
>> requisite}[,...]
>>
>> As an example:
>>
>> -s xscreensaver:optional,dtlogin:optional
>>     
>      ^^^^^^^^^^^^
>
>   
>> would configure files:
>>     
> [snip]
>   
>> other auth required           pam_unix_auth.so.1
>> other auth optional           pam_krb5.so.1
>>     
>   ^^^^^
>
> 	I'm missing seeing the correlation between service name and this
> 	example.
>   
In the above example these are the contents of the include file, so 
pam.conf would only have the service name specified configured.

> 	In any case, I'm concerned that unless pam.conf is the default
> 	one delivered changing the other stacks, or cloning the other
> 	stacks for the -s specified services and adding pam_krb5.so.1
> 	optional or otherwise is a wise thing to do.
>
> 	I do believe that there's value in kclient being able to completely
> 	set up a kerberos client even (or especially) for sites with pam.conf
> 	changes in other areas.  That's why I seconded Darren's comments
> 	about using include.
>   

I would rather produce an error message to the administrator for the 
case that the pam.conf file already had a stack for the service name 
specified with -s that didn't match a vanilla version.

Shawn.
--

From gww@eng.sun.com Mon Jul 16 13:42:58 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6GKgwRM022368
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 16 Jul 2007 13:42:58 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6GKetgb005998
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 16 Jul 2007 13:40:56 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLA00J15HG7XX00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 16 Jul 2007 13:40:55 -0700 (PDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLA00D4EHG646A0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 16 Jul 2007 13:40:55 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6GKerV4004595; Mon, 16 Jul 2007 13:40:53 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6GKiIDB023779; Mon,
 16 Jul 2007 13:44:18 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6GKiIrc023778; Mon,
 16 Jul 2007 13:44:18 -0700 (PDT)
Date: Mon, 16 Jul 2007 13:44:18 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
To: gww@eng.sun.com, Shawn.Emery@sun.com
Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <200707162044.l6GKiIrc023778@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 1587


> > 	I'm missing seeing the correlation between service name and this
> > 	example.
> >   
> In the above example these are the contents of the include file, so 
> pam.conf would only have the service name specified configured.


	Ah, OK.  That's what I missed.

> > 	In any case, I'm concerned that unless pam.conf is the default
> > 	one delivered changing the other stacks, or cloning the other
> > 	stacks for the -s specified services and adding pam_krb5.so.1
> > 	optional or otherwise is a wise thing to do.
> >
> > 	I do believe that there's value in kclient being able to completely
> > 	set up a kerberos client even (or especially) for sites with pam.conf
> > 	changes in other areas.  That's why I seconded Darren's comments
> > 	about using include.
> >   
> 
> I would rather produce an error message to the administrator for the 
> case that the pam.conf file already had a stack for the service name 
> specified with -s that didn't match a vanilla version.

	I would think if you're going to leverage include that you'd
	verify that <service> wasn't already specified (or maybe
	specified but including pam_krb5) and error out on that.
	If not specified perhaps produce an informational message saying
	something like,
	``Default configuration for <service> added to default pam.conf.
	You can view the default configuration at
	"/usr/lib/security/<arch>/kerberos_common".''

	kerberos_common would be read only and say something about not
	modifying the file, but customizing by making a copy.

Gary..
P.S.	I guess I need to start the backport of PSARC/2005/217 ;-)
	

From Shawn.Emery@sun.com Mon Jul 16 13:43:09 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6GKh86Y022385
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 16 Jul 2007 13:43:08 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6GKf2ON012912
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 16 Jul 2007 21:41:07 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLA00J0DHGFY300@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 16 Jul 2007 13:41:03 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLA00DQ6HGF4290@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 16 Jul 2007 13:41:03 -0700 (PDT)
Received: from fe-amer-03.sun.com ([192.18.108.177])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6GKf33G020379	for
 <PSARC-ext@sun.com>; Mon, 16 Jul 2007 20:41:03 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JLA00I01HAYJB00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 16 Jul 2007 14:41:03 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.36.199])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JLA00BA9HGDQC80@mail-amer.sun.com>; Mon,
 16 Jul 2007 14:41:03 -0600 (MDT)
Date: Mon, 16 Jul 2007 14:38:39 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <469B4606.5070709@Sun.COM>
Sender: Shawn.Emery@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com,
        Gary Winiger <gww@eng.sun.com>
Message-id: <469BD74F.5000804@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
 <4696BA12.1040303@sun.com> <46976686.1060801@Sun.COM>
 <46984E92.5070604@sun.com> <469B4606.5070709@Sun.COM>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 1981

Darren J Moffat wrote:
> Shawn M. Emery wrote:
>>> I think this area needs some more thought.  I suspect what what we 
>>> really want to do with kclient is put the pam.conf file in to one of 
>>> the known good and recommended states that is documented in 
>>> pam_krb5(5) already.
>>>
>>> Maybe this project should be using PSARC 2005/217 and delivering one 
>>> of more include files that have the different recommended ways of 
>>> using pam_krb5.
>>
>> Setting include files apart there still should be a way of specifying 
>> how Kerberos interacts with other modules.  -s could include a 
>> qualifier for pam_krb5's control flag with:
>>
>> -s service_name:{binding | sufficient | optional | required | 
>> requisite}[,...]
>>
>> As an example:
>>
>> -s xscreensaver:optional,dtlogin:optional
>
> That is interesting but it assumes you always want it at the end.  As 
> you can see this is quite complex.

Its behavior is how I interpret something of being optional in quality.

> I think that setting up pam.conf to do one of the normal Kerberos 
> configurations is a key part of this project.
>
> My recommendation is that the kclient interface be quite high level eg:
>
> As per the pam_krb5(5) examples: first, only, optional are the 
> keywords here.

I don't think the pam_krb5 examples are comprehensive enough.  I may 
wish to authenticate through Kerberos _and_ through other additional 
modules.

> kclient should (probably in conjunction with some other part of the 
> system that we can work out offline) only update the pam.conf file if 
> it is in a known original state.

Agreed.

> If there are any customisations to pam.conf for the  services listed 
> then kclient should not attempt to change those.  It is just too hard 
> to work out where the correct place to put the module in a customised 
> stack is.  In this case it should tell the operator that they must do 
> it themselves.

Yes, assumptions made could break their authentication.

Shawn.
--

From Darren.Moffat@sun.com Tue Jul 17 05:44:49 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6HCine2015992
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Jul 2007 05:44:49 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6HCgfkj021961
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 17 Jul 2007 13:42:47 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLB00007PZ6C600@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Jul 2007 05:42:42 -0700 (PDT)
Received: from gmp-ea-fw-1.sun.com ([129.156.42.5])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLB00M7YPZ5I610@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Jul 2007 05:42:41 -0700 (PDT)
Received: from d1-emea-09.sun.com (d1-emea-09.sun.com [192.18.2.119])
	by gmp-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6HCgeKJ020411	for
 <PSARC-ext@sun.com>; Tue, 17 Jul 2007 12:42:40 +0000 (GMT)
Received: from conversion-daemon.d1-emea-09.sun.com by d1-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JLB00L01PUX1F00@d1-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Jul 2007 13:42:40 +0100 (BST)
Received: from [129.156.173.21] by d1-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JLB0086SPZ2UT00@d1-emea-09.sun.com>; Tue,
 17 Jul 2007 13:42:39 +0100 (BST)
Date: Tue, 17 Jul 2007 13:42:38 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <469BD74F.5000804@sun.com>
Sender: Darren.Moffat@sun.com
To: "Shawn M. Emery" <Shawn.Emery@sun.com>
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com,
        Gary Winiger <gww@eng.sun.com>
Message-id: <469CB93E.9050403@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
 <4696BA12.1040303@sun.com> <46976686.1060801@Sun.COM>
 <46984E92.5070604@sun.com> <469B4606.5070709@Sun.COM>
 <469BD74F.5000804@sun.com>
User-Agent: Thunderbird 2.0.0.0 (X11/20070605)
Status: RO
Content-Length: 822

Shawn M. Emery wrote:
>> I think that setting up pam.conf to do one of the normal Kerberos 
>> configurations is a key part of this project.
>>
>> My recommendation is that the kclient interface be quite high level eg:
>>
>> As per the pam_krb5(5) examples: first, only, optional are the 
>> keywords here.
> 
> I don't think the pam_krb5 examples are comprehensive enough.  I may 
> wish to authenticate through Kerberos _and_ through other additional 
> modules.

You don't need to provide every possible combination just the ones we 
believe are the commonly used ones.  For anything else pam.conf is still 
an end admin editable policy file.  I think the common ways of using 
pam_krb5 are the ones listed in the current pam_krb5(5) man page and 
would be a good start for kclient(1) to support.


-- 
Darren J Moffat

From Shawn.Emery@sun.com Tue Jul 17 09:50:43 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6HGogxa022026
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Jul 2007 09:50:42 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6HGmUuo012835
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 17 Jul 2007 17:48:40 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLC00A0P1D3IB00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Jul 2007 09:48:39 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLC006ZF1D25Q50@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Jul 2007 09:48:38 -0700 (PDT)
Received: from fe-amer-04.sun.com ([192.18.108.178])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6HGmcqr015272	for
 <PSARC-ext@sun.com>; Tue, 17 Jul 2007 16:48:38 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JLC00H0110W1M00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Jul 2007 10:48:38 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.33.207])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JLC00CUX1D0GSN4@mail-amer.sun.com>; Tue,
 17 Jul 2007 10:48:38 -0600 (MDT)
Date: Tue, 17 Jul 2007 10:46:13 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <469CB93E.9050403@Sun.COM>
Sender: Shawn.Emery@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com,
        Gary Winiger <gww@eng.sun.com>
Message-id: <469CF255.3040506@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
 <4696BA12.1040303@sun.com> <46976686.1060801@Sun.COM>
 <46984E92.5070604@sun.com> <469B4606.5070709@Sun.COM>
 <469BD74F.5000804@sun.com> <469CB93E.9050403@Sun.COM>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 1005

Darren J Moffat wrote:
> Shawn M. Emery wrote:
>>> I think that setting up pam.conf to do one of the normal Kerberos 
>>> configurations is a key part of this project.
>>>
>>> My recommendation is that the kclient interface be quite high level eg:
>>>
>>> As per the pam_krb5(5) examples: first, only, optional are the 
>>> keywords here.
>>
>> I don't think the pam_krb5 examples are comprehensive enough.  I may 
>> wish to authenticate through Kerberos _and_ through other additional 
>> modules.
>
> You don't need to provide every possible combination just the ones we 
> believe are the commonly used ones.  For anything else pam.conf is 
> still an end admin editable policy file.  I think the common ways of 
> using pam_krb5 are the ones listed in the current pam_krb5(5) man page 
> and would be a good start for kclient(1) to support.

Ok, I'll leave "and" out if everyone one is happy with the current set:

first
only
optional

What if the qualifier is left out?  "first" or fail?

Shawn.
--

From Darren.Moffat@sun.com Tue Jul 17 10:03:45 2007
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6HH3ib3023027
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Jul 2007 10:03:44 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6HH0lmp029737
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 17 Jul 2007 11:00:48 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLC00B0N1YU4500@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Jul 2007 10:01:42 -0700 (PDT)
Received: from gmp-ea-fw-1.sun.com ([129.156.42.6])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLC006TT1YT5Q60@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Jul 2007 10:01:42 -0700 (PDT)
Received: from d1-emea-10.sun.com ([192.18.2.120])
	by gmp-ea-fw-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6HH1eOq008428	for
 <PSARC-ext@sun.com>; Tue, 17 Jul 2007 17:01:40 +0000 (GMT)
Received: from conversion-daemon.d1-emea-10.sun.com by d1-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JLC001011WVSY00@d1-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Jul 2007 18:01:40 +0100 (BST)
Received: from [129.156.173.21] by d1-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JLC007WW1YS4K00@d1-emea-10.sun.com>; Tue,
 17 Jul 2007 18:01:40 +0100 (BST)
Date: Tue, 17 Jul 2007 18:01:40 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <469CF255.3040506@sun.com>
Sender: Darren.Moffat@sun.com
To: "Shawn M. Emery" <Shawn.Emery@sun.com>
Cc: PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com,
        Gary Winiger <gww@eng.sun.com>
Message-id: <469CF5F4.1000108@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707121951.l6CJpkQZ019885@marduk.eng.sun.com>
 <4696BA12.1040303@sun.com> <46976686.1060801@Sun.COM>
 <46984E92.5070604@sun.com> <469B4606.5070709@Sun.COM>
 <469BD74F.5000804@sun.com> <469CB93E.9050403@Sun.COM>
 <469CF255.3040506@sun.com>
User-Agent: Thunderbird 2.0.0.0 (X11/20070605)
Status: RO
Content-Length: 1123

Shawn M. Emery wrote:
> Darren J Moffat wrote:
>> Shawn M. Emery wrote:
>>>> I think that setting up pam.conf to do one of the normal Kerberos 
>>>> configurations is a key part of this project.
>>>>
>>>> My recommendation is that the kclient interface be quite high level eg:
>>>>
>>>> As per the pam_krb5(5) examples: first, only, optional are the 
>>>> keywords here.
>>>
>>> I don't think the pam_krb5 examples are comprehensive enough.  I may 
>>> wish to authenticate through Kerberos _and_ through other additional 
>>> modules.
>>
>> You don't need to provide every possible combination just the ones we 
>> believe are the commonly used ones.  For anything else pam.conf is 
>> still an end admin editable policy file.  I think the common ways of 
>> using pam_krb5 are the ones listed in the current pam_krb5(5) man page 
>> and would be a good start for kclient(1) to support.
> 
> Ok, I'll leave "and" out if everyone one is happy with the current set:
> 
> first
> only
> optional
> 
> What if the qualifier is left out?  "first" or fail?

Don't allow it to be left out, make it required.

-- 
Darren J Moffat

From gww@eng.sun.com Tue Jul 17 18:13:26 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6I1DQa8008317
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Jul 2007 18:13:26 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6I1BP13011787
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Tue, 17 Jul 2007 18:11:25 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLC00J01ON16A00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 17 Jul 2007 18:11:25 -0700 (PDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLC00EWFON0KS90@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Tue,
 17 Jul 2007 18:11:24 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6I1BMiM002280; Tue, 17 Jul 2007 18:11:22 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6I1EoBh026263; Tue,
 17 Jul 2007 18:14:50 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6I1EoUB026262; Tue,
 17 Jul 2007 18:14:50 -0700 (PDT)
Date: Tue, 17 Jul 2007 18:14:50 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
To: Darren.Moffat@Sun.COM, Shawn.Emery@Sun.COM
Cc: PSARC-ext@Sun.COM, wyllys@borg.sfbay.sun.com, gww@eng.sun.com
Message-id: <200707180114.l6I1EoUB026262@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 233

> Ok, I'll leave "and" out if everyone one is happy with the current set:
> 
> first
> only
> optional
> 
> What if the qualifier is left out?  "first" or fail?

	So, now I'm lost again.  What's the spec that's under review?

Gary..

From Shawn.Emery@sun.com Tue Jul 17 19:27:11 2007
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6I2RAkr009230
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Jul 2007 19:27:10 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6I2P8Y7027112
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 17 Jul 2007 19:25:09 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLC0090DS1VVL00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Jul 2007 20:25:07 -0600 (MDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLC005DUS1U8O30@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Jul 2007 20:25:06 -0600 (MDT)
Received: from fe-amer-04.sun.com ([192.18.108.178])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6I2P6d2001802	for
 <PSARC-ext@sun.com>; Wed, 18 Jul 2007 02:25:06 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JLC00B01RSR7X00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Jul 2007 20:25:06 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.33.20])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JLC00C00S1QGTM2@mail-amer.sun.com>; Tue,
 17 Jul 2007 20:25:06 -0600 (MDT)
Date: Tue, 17 Jul 2007 20:22:37 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
	07/13/2007]]
In-reply-to: <200707180114.l6I1EoUB026262@marduk.eng.sun.com>
Sender: Shawn.Emery@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <469D796D.4090908@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707180114.l6I1EoUB026262@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 446

Gary Winiger wrote:
>> Ok, I'll leave "and" out if everyone one is happy with the current set:
>>
>> first
>> only
>> optional
>>
>> What if the qualifier is left out?  "first" or fail?
>>     
>
> 	So, now I'm lost again.  What's the spec that's under review?
>   

-s service_name:{first | only | optional}

On another topic, did we come to consensus on whether the -T option was 
acceptable with the way I had originally specified?

Shawn.
--

From gww@eng.sun.com Wed Jul 18 12:03:48 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6IJ3lu3029878
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 18 Jul 2007 12:03:48 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l6IJ1YSN006250
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 19 Jul 2007 03:01:44 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLE00D0F26SAH00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 18 Jul 2007 12:01:40 -0700 (PDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLE00B8Q26SWG10@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 18 Jul 2007 12:01:40 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6IJ1cPH003347; Wed, 18 Jul 2007 12:01:38 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6IJ56hC027363; Wed,
 18 Jul 2007 12:05:06 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6IJ56em027362; Wed,
 18 Jul 2007 12:05:06 -0700 (PDT)
Date: Wed, 18 Jul 2007 12:05:06 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
To: Shawn.Emery@sun.com, gww@eng.sun.com
Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <200707181905.l6IJ56em027362@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 1504

> From Shawn.Emery@sun.com Tue Jul 17 19:27:11 2007
> Date: Tue, 17 Jul 2007 20:22:37 -0600
> From: "Shawn M. Emery" <Shawn.Emery@sun.com>
> Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
> 	07/13/2007]]
> To: Gary Winiger <gww@eng.sun.com>
> Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
> Content-transfer-encoding: 7BIT
> X-PMX-Version: 5.2.0.264296
> User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
> 
> Gary Winiger wrote:
> >> Ok, I'll leave "and" out if everyone one is happy with the current set:
> >>
> >> first
> >> only
> >> optional
> >>
> >> What if the qualifier is left out?  "first" or fail?
> >>     
> >
> > 	So, now I'm lost again.  What's the spec that's under review?
> >   
> 
> -s service_name:{first | only | optional}
> 
> On another topic, did we come to consensus on whether the -T option was 
> acceptable with the way I had originally specified?

	I know the project team is occupied with other issues.
	I'd like to see an updated spec particularly relative to
	-s just so we're all on the same page.
	
	I'm guessing the project teams response to mean that it will ship
	3 PAM stacks that can be (2005/217) included in the master
	pam.conf to provide a generic use Kerberos first and fall
	back on Unix if Kerberos isn't the user's account authority
	| Kerberos is the only account authority for users | try
	Unix first and then optionally Kerberos as an account authority.

	So, more time or waiting need spec.

Gary..

From Shawn.Emery@sun.com Thu Jul 19 08:35:03 2007
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6JFZ3nY029696
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 19 Jul 2007 08:35:03 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6JFVcud047618
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 19 Jul 2007 09:32:03 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLF00I0JN6Q8R00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 19 Jul 2007 08:32:50 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLF00ASLN6P3P40@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 19 Jul 2007 08:32:49 -0700 (PDT)
Received: from fe-amer-05.sun.com ([192.18.108.179])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6JFWnCG018550	for
 <PSARC-ext@sun.com>; Thu, 19 Jul 2007 15:32:49 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JLF00E01MSLTI00@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 19 Jul 2007 09:32:49 -0600 (MDT)
Received: from shawn-emerys-computer.local ([129.150.36.99])
 by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JLF003M7N6NLD56@mail-amer.sun.com>; Thu,
 19 Jul 2007 09:32:49 -0600 (MDT)
Date: Thu, 19 Jul 2007 09:30:21 -0600
From: "Shawn M. Emery" <Shawn.Emery@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
In-reply-to: <200707181905.l6IJ56em027362@marduk.eng.sun.com>
Sender: Shawn.Emery@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <469F838D.8010505@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_xE/yStJPlFZ9vmGDKJW8aw)"
X-PMX-Version: 5.2.0.264296
References: <200707181905.l6IJ56em027362@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
Status: RO
Content-Length: 6477

This is a multi-part message in MIME format.

--Boundary_(ID_xE/yStJPlFZ9vmGDKJW8aw)
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

Gary Winiger wrote:
>> From Shawn.Emery@sun.com Tue Jul 17 19:27:11 2007
>> Date: Tue, 17 Jul 2007 20:22:37 -0600
>> From: "Shawn M. Emery" <Shawn.Emery@sun.com>
>> Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
>> 	07/13/2007]]
>> To: Gary Winiger <gww@eng.sun.com>
>> Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
>> Content-transfer-encoding: 7BIT
>> X-PMX-Version: 5.2.0.264296
>> User-Agent: Thunderbird 2.0.0.4 (Macintosh/20070604)
>>
>> Gary Winiger wrote:
>>     
>>>> Ok, I'll leave "and" out if everyone one is happy with the current set:
>>>>
>>>> first
>>>> only
>>>> optional
>>>>
>>>> What if the qualifier is left out?  "first" or fail?
>>>>     
>>>>         
>>> 	So, now I'm lost again.  What's the spec that's under review?
>>>   
>>>       
>> -s service_name:{first | only | optional}
>>
>> On another topic, did we come to consensus on whether the -T option was 
>> acceptable with the way I had originally specified?
>>     
>
> 	I know the project team is occupied with other issues.
> 	I'd like to see an updated spec particularly relative to
> 	-s just so we're all on the same page.
> 	
> 	I'm guessing the project teams response to mean that it will ship
> 	3 PAM stacks that can be (2005/217) included in the master
> 	pam.conf to provide a generic use Kerberos first and fall
> 	back on Unix if Kerberos isn't the user's account authority
> 	| Kerberos is the only account authority for users | try
> 	Unix first and then optionally Kerberos as an account authority.
>
> 	So, more time or waiting need spec.
>   
Following diff shows:

1. revised -s text
2. kept the -T option with auto-detection as something to be considered 
with more careful thought
3. dropped the -t option due to security concerns and conflicting mechanisms

Shawn.
--

--Boundary_(ID_xE/yStJPlFZ9vmGDKJW8aw)
Content-type: text/plain; name=kc2.op.1.diff; x-mac-creator=0; x-mac-type=0
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=kc2.op.1.diff

kc2.op:
@@ -43,13 +43,26 @@
 	be mapped to the Kerberos realm specified
 -K: configure a client that does not have host/service keys
 -h logical_host_name: where logical_host_name is the logical host name of the
 	cluster
 -m master_kdc: where master_kdc is the master KDC host name
--s pam_service: where pam_service is the service name to be configured for
-	Kerberos authentication in the pam.conf(4) file
--t: configure a simple broadcast/multicast NTP client
+-s pam_service:{first | only | optional}[,...]
+	where pam_service is the service name to be configured for
+	Kerberos as the account authority in the pam.conf(4) file
+	first: try authenticating through Kerberos first, if this fails try to
+		authenticate through Unix
+	only: only try to authenticate through Kerberos
+	optional: try authenticating through Unix first, if this is successful
+		try to authenticate through Kerberos
+	multiple services can be delimited by commas (",")
+
+	Three files will be installed with this project under /etc/security/pam:
+		pam_krb5_first
+		pam_krb5_only
+		pam_krb5_optional
+	These files pertain to the "include" references in pam.conf when the -s
+	option has been used for any service names specified.	
 -T kdc_vendor: specify the KDC of the client to be of kdc_vendor.  Supported
 vendors are currently:
 	ms_ad: Microsoft Active Directory
 	mit: MIT KDC server
 	heimdal: Heimdal KDC server
@@ -88,11 +101,11 @@
 is a matrix that indicates which is used by the clients for the various types
 of servers:
 
 		MIT<1.4	Heimdal	Shishi	AD	Solaris	No keys		MIT1.4+
 -------------------------------------------------------------------------------
-option (-t)	mit	heimdal	shishi	ms_ad	none	-K		none
+option (-T)	mit	heimdal	shishi	ms_ad	none	-K		none
 -------------------------------------------------------------------------------
 keytab					X	X			X
 -------------------------------------------------------------------------------
 no keytab	X	X	X			X
 -------------------------------------------------------------------------------
@@ -115,11 +128,11 @@
 -     /usr/sbin/kclient [-n] [-R realm] [-k  kdc]  [-a  adminuser]
 -     [-c filepath] [-d dnsarg] [-f fqdn_list] [-p profile]
 +     /usr/sbin/kclient [ -K ] [ -R realm ] [ -a adminuser ]
 +     [ -c filepath ] [ -d dnsarg ] [ -f fqdn_list ] [ -h logical_host_name ]
 +     [ -k kdc_list ] [ -m master_kdc ] [ -n ] [ -p profile ]
-+     [ -s pam_service ] [ -t ] [ -T kdc_vendor ] 
++     [ -s pam_service ] [ -T kdc_vendor ] 
 
 DESCRIPTION
      You can use the kclient utility to:
 
        o  Configure a machine as a Kerberos client for  a  speci-
@@ -301,17 +314,17 @@
 -        NFS,   DNSLOOKUP,  and  FQDN.   These  profile  entries
 -        correspond to the -R [realm], -k [kdc], -a  [adminuser],
 -        -c  [filepath],  -n,  -d  [dnsarg],  and  -f [fqdn_list]
 -        command-line  options,  respectively.  Any  other  PARAM
 -        entry is considered invalid and is ignored.
-+        NFS, DNSLOOKUP, FQDN, NOKEY, NOSOL, LHN, KDCVENDOR, RMAP, MAS, PAM,
-+	 and NTP.
++        NFS, DNSLOOKUP, FQDN, NOKEY, NOSOL, LHN, KDCVENDOR, RMAP,
++	 MAS, and PAM.
 +
 +	 These profile entries correspond to the -R [realm], -k [kdc_list],
 +	 -a [adminuser], -c [filepath], -n, -d [dnsarg], -f [fqdn_list],
 +	 -K, -h [logical_host_name], -T [kdc_vendor], -D [domain_list],
-+	 -m [master_kdc], -s [pam_service], and -t command-line options,
++	 -m [master_kdc], and -s [pam_service] command-line options,
 +	 respectively.  Any other PARAM entry is considered invalid and is
 +	 ignored.
 
          The NFS profile entry can have a value of 0 (do nothing)
          or  1  (operation is requested). Any other value is con-
@@ -323,15 +336,10 @@
 +	 to authenticate through Kerberos foremost.  Using this option updates
 +	 pam.conf(4) to include pam_krb5(5) to existing authentication stacks
 +	 for the specified service(s) in pam_service.  An example of a possible
 +	 pam_service is "dtlogin,sshd-kbdint".
 +
-+    -t
-+
-+	 Configures the client to be a NTP broadcast/multicast client if it
-+	 has not already been configured to be one.
-+
 ...
      ADMIN clntconfig
      FILEPATH /net/example1.com/export/krb5.conf
      NFS 0
      DNSLOOKUP none

--Boundary_(ID_xE/yStJPlFZ9vmGDKJW8aw)--

From gww@eng.sun.com Thu Jul 19 13:32:08 2007
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6JKW7uX009060
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 19 Jul 2007 13:32:07 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6JKU3v6027701
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 19 Jul 2007 21:30:03 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JLG00J0B0Y1IT00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 19 Jul 2007 14:30:01 -0600 (MDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JLG008720Y0CG90@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 19 Jul 2007 14:30:00 -0600 (MDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6JKTwd5022039; Thu, 19 Jul 2007 13:29:58 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6JKXSLu028820; Thu,
 19 Jul 2007 13:33:28 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6JKXSrR028819; Thu,
 19 Jul 2007 13:33:28 -0700 (PDT)
Date: Thu, 19 Jul 2007 13:33:28 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
To: gww@eng.sun.com, Shawn.Emery@sun.com
Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <200707192033.l6JKXSrR028819@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 1302


> Following diff shows:
> 
> 1. revised -s text

> --s pam_service: where pam_service is the service name to be configured for
> -	Kerberos authentication in the pam.conf(4) file
> --t: configure a simple broadcast/multicast NTP client
> +-s pam_service:{first | only | optional}[,...]
> +	where pam_service is the service name to be configured for
> +	Kerberos as the account authority in the pam.conf(4) file
> +	first: try authenticating through Kerberos first, if this fails try to
> +		authenticate through Unix
> +	only: only try to authenticate through Kerberos
> +	optional: try authenticating through Unix first, if this is successful
> +		try to authenticate through Kerberos
> +	multiple services can be delimited by commas (",")
> +
> +	Three files will be installed with this project under /etc/security/pam:
> +		pam_krb5_first
> +		pam_krb5_only
> +		pam_krb5_optional
> +	These files pertain to the "include" references in pam.conf when the -s
> +	option has been used for any service names specified.	

	Please install the files to "include" in the default place defined
	in PSARC/2005/217 PAM include control flag.  That is:
	included PAM configuration
	files are assumed to be relative to /usr/lib/security/.

	Then absolute paths will not be required in "master" pam.conf.

Gary..

From gww@eng.sun.com Tue Jul 31 12:25:28 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6VJPRgT000772
	for <psarc-ext@sac.sfbay.Sun.COM>; Tue, 31 Jul 2007 12:25:27 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l6VJNA9H002352
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 1 Aug 2007 03:23:13 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JM20030B5UNVW00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 31 Jul 2007 12:23:11 -0700 (PDT)
Received: from engmail3mpk.sfbay.Sun.COM ([129.146.11.26])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JM2001Y55UNRB20@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 31 Jul 2007 12:23:11 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by engmail3mpk.sfbay.Sun.COM (8.13.6+Sun/8.13.6/ENSMAIL,v2.2)
 with ESMTP id l6VJN9hg027402; Tue, 31 Jul 2007 12:23:09 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id l6VJQv33015556; Tue,
 31 Jul 2007 12:26:57 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id l6VJQv5g015555; Tue,
 31 Jul 2007 12:26:57 -0700 (PDT)
Date: Tue, 31 Jul 2007 12:26:57 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
To: Shawn.Emery@sun.com, gww@eng.sun.com
Cc: Darren.Moffat@sun.com, PSARC-ext@sun.com, wyllys@borg.sfbay.sun.com
Message-id: <200707311926.l6VJQv5g015555@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
Status: RO
Content-Length: 1408

> > Following diff shows:
> > 
> > 1. revised -s text
> 
> > --s pam_service: where pam_service is the service name to be configured for
> > -	Kerberos authentication in the pam.conf(4) file
> > --t: configure a simple broadcast/multicast NTP client
> > +-s pam_service:{first | only | optional}[,...]
> > +	where pam_service is the service name to be configured for
> > +	Kerberos as the account authority in the pam.conf(4) file
> > +	first: try authenticating through Kerberos first, if this fails try to
> > +		authenticate through Unix
> > +	only: only try to authenticate through Kerberos
> > +	optional: try authenticating through Unix first, if this is successful
> > +		try to authenticate through Kerberos
> > +	multiple services can be delimited by commas (",")
> > +
> > +	Three files will be installed with this project under /etc/security/pam:
> > +		pam_krb5_first
> > +		pam_krb5_only
> > +		pam_krb5_optional
> > +	These files pertain to the "include" references in pam.conf when the -s
> > +	option has been used for any service names specified.	
> 
> 	Please install the files to "include" in the default place defined
> 	in PSARC/2005/217 PAM include control flag.  That is:
> 	included PAM configuration
> 	files are assumed to be relative to /usr/lib/security/.
> 
> 	Then absolute paths will not be required in "master" pam.conf.

	Can we close on this issue from 2 weeks ago?

Gary..

From wyllys.ingersoll@sun.com Tue Jul 31 12:30:11 2007
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6VJUBIK000840
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 31 Jul 2007 12:30:11 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id l6VJRsLg022478;
	Tue, 31 Jul 2007 12:27:55 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JM200D0Z62IXW00@brm-avmta-1.central.sun.com>; Tue,
 31 Jul 2007 13:27:54 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JM200BXG62HZO10@brm-avmta-1.central.sun.com>; Tue,
 31 Jul 2007 13:27:53 -0600 (MDT)
Received: from [10.7.251.182] (punchin-wyllys.SFBay.Sun.COM [10.7.251.182])
	by jurassic-x4600.sfbay.sun.com (8.14.1+Sun/8.14.1)
 with ESMTP id l6VJRp6s883273
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue,
 31 Jul 2007 12:27:52 -0700 (PDT)
Date: Tue, 31 Jul 2007 15:27:36 -0400
From: Wyllys Ingersoll <wyllys.ingersoll@sun.com>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
In-reply-to: <200707311926.l6VJQv5g015555@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>
Cc: Shawn.Emery@sun.com, Darren.Moffat@sun.com, PSARC-ext@sun.com,
        wyllys@borg.sfbay.sun.com
Message-id: <46AF8D28.7040500@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707311926.l6VJQv5g015555@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.0 (X11/20070521)
Status: RO
Content-Length: 1680

Gary Winiger wrote:
>>> Following diff shows:
>>>
>>> 1. revised -s text
>>>       
>>> --s pam_service: where pam_service is the service name to be configured for
>>> -	Kerberos authentication in the pam.conf(4) file
>>> --t: configure a simple broadcast/multicast NTP client
>>> +-s pam_service:{first | only | optional}[,...]
>>> +	where pam_service is the service name to be configured for
>>> +	Kerberos as the account authority in the pam.conf(4) file
>>> +	first: try authenticating through Kerberos first, if this fails try to
>>> +		authenticate through Unix
>>> +	only: only try to authenticate through Kerberos
>>> +	optional: try authenticating through Unix first, if this is successful
>>> +		try to authenticate through Kerberos
>>> +	multiple services can be delimited by commas (",")
>>> +
>>> +	Three files will be installed with this project under /etc/security/pam:
>>> +		pam_krb5_first
>>> +		pam_krb5_only
>>> +		pam_krb5_optional
>>> +	These files pertain to the "include" references in pam.conf when the -s
>>> +	option has been used for any service names specified.	
>>>       
>> 	Please install the files to "include" in the default place defined
>> 	in PSARC/2005/217 PAM include control flag.  That is:
>> 	included PAM configuration
>> 	files are assumed to be relative to /usr/lib/security/.
>>
>> 	Then absolute paths will not be required in "master" pam.conf.
>>     
>
> 	Can we close on this issue from 2 weeks ago?
>
> Gary..
>   

I agree, I meant to email about this but forgot to get to it before I 
left on vacation
last week.    Lets try to come to agreement before tomorrow so we can 
approve it and be
done with the PSARC part.

-Wyllys

From Shawn.Emery@Sun.COM Tue Jul 31 16:18:36 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l6VNIZX9014192
	for <psarc-ext@sac.sfbay.Sun.COM>; Tue, 31 Jul 2007 16:18:35 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l6VNGKd6019781
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 1 Aug 2007 07:16:20 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JM200M01GN8ZT00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 31 Jul 2007 16:16:20 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JM200FQPGN7JV20@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 31 Jul 2007 16:16:19 -0700 (PDT)
Received: from fe-amer-04.sun.com ([192.18.108.178])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id l6VNGJPA010240	for
 <PSARC-ext@sun.com>; Tue, 31 Jul 2007 23:16:19 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 id <0JM200I01G26D500@mail-amer.sun.com>
 (original mail from Shawn.Emery@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 31 Jul 2007 17:16:19 -0600 (MDT)
Received: from [129.150.48.17] by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPSA id <0JM200COMGN3GRD5@mail-amer.sun.com>; Tue,
 31 Jul 2007 17:16:19 -0600 (MDT)
Date: Tue, 31 Jul 2007 17:14:39 -0600
From: Shawn M Emery <Shawn.Emery@Sun.COM>
Subject: Re: [Fwd: kclient version 2 [PSARC/2007/401 FastTrack timeout
 07/13/2007]]
In-reply-to: <200707311926.l6VJQv5g015555@marduk.eng.sun.com>
Sender: Shawn.Emery@Sun.COM
To: Gary Winiger <gww@eng.sun.com>
Cc: Darren.Moffat@Sun.COM, PSARC-ext@Sun.COM, wyllys@borg.sfbay.sun.com
Message-id: <46AFC25F.9030701@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
References: <200707311926.l6VJQv5g015555@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.5 (X11/20070720)
Status: RO
Content-Length: 5794


Here are the contextual diffs from the initial one-pager to the current 
version:

@@ -43,13 +43,26 @@
 	be mapped to the Kerberos realm specified
 -K: configure a client that does not have host/service keys
 -h logical_host_name: where logical_host_name is the logical host name of the
 	cluster
 -m master_kdc: where master_kdc is the master KDC host name
--s pam_service: where pam_service is the service name to be configured for
-	Kerberos authentication in the pam.conf(4) file
--t: configure a simple broadcast/multicast NTP client
+-s pam_service:{first | only | optional}[,...]
+	where pam_service is the service name to be configured for
+	Kerberos as the account authority in the pam.conf(4) file
+	first: try authenticating through Kerberos first, if this fails try to
+		authenticate through Unix
+	only: only try to authenticate through Kerberos
+	optional: try authenticating through Unix first, if this is successful
+		try to authenticate through Kerberos
+	multiple services can be delimited by commas (",")
+
+	Three files will be installed with this project under /usr/lib/security:
+		pam_krb5_first
+		pam_krb5_only
+		pam_krb5_optional
+	These files pertain to the "include" references in pam.conf when the -s
+	option has been used for any service names specified.	
 -T kdc_vendor: specify the KDC of the client to be of kdc_vendor.  Supported
 vendors are currently:
 	ms_ad: Microsoft Active Directory
 	mit: MIT KDC server
 	heimdal: Heimdal KDC server
@@ -88,11 +101,11 @@
 is a matrix that indicates which is used by the clients for the various types
 of servers:
 
 		MIT<1.4	Heimdal	Shishi	AD	Solaris	No keys		MIT1.4+
 -------------------------------------------------------------------------------
-option (-t)	mit	heimdal	shishi	ms_ad	none	-K		none
+option (-T)	mit	heimdal	shishi	ms_ad	none	-K		none
 -------------------------------------------------------------------------------
 keytab					X	X			X
 -------------------------------------------------------------------------------
 no keytab	X	X	X			X
 -------------------------------------------------------------------------------
@@ -115,11 +128,11 @@
 -     /usr/sbin/kclient [-n] [-R realm] [-k  kdc]  [-a  adminuser]
 -     [-c filepath] [-d dnsarg] [-f fqdn_list] [-p profile]
 +     /usr/sbin/kclient [ -K ] [ -R realm ] [ -a adminuser ]
 +     [ -c filepath ] [ -d dnsarg ] [ -f fqdn_list ] [ -h logical_host_name ]
 +     [ -k kdc_list ] [ -m master_kdc ] [ -n ] [ -p profile ]
-+     [ -s pam_service ] [ -t ] [ -T kdc_vendor ] 
++     [ -s pam_service ] [ -T kdc_vendor ] 
 
 DESCRIPTION
      You can use the kclient utility to:
 
        o  Configure a machine as a Kerberos client for  a  speci-
@@ -301,17 +314,17 @@
 -        NFS,   DNSLOOKUP,  and  FQDN.   These  profile  entries
 -        correspond to the -R [realm], -k [kdc], -a  [adminuser],
 -        -c  [filepath],  -n,  -d  [dnsarg],  and  -f [fqdn_list]
 -        command-line  options,  respectively.  Any  other  PARAM
 -        entry is considered invalid and is ignored.
-+        NFS, DNSLOOKUP, FQDN, NOKEY, NOSOL, LHN, KDCVENDOR, RMAP, MAS, PAM,
-+	 and NTP.
++        NFS, DNSLOOKUP, FQDN, NOKEY, NOSOL, LHN, KDCVENDOR, RMAP,
++	 MAS, and PAM.
 +
 +	 These profile entries correspond to the -R [realm], -k [kdc_list],
 +	 -a [adminuser], -c [filepath], -n, -d [dnsarg], -f [fqdn_list],
 +	 -K, -h [logical_host_name], -T [kdc_vendor], -D [domain_list],
-+	 -m [master_kdc], -s [pam_service], and -t command-line options,
++	 -m [master_kdc], and -s [pam_service] command-line options,
 +	 respectively.  Any other PARAM entry is considered invalid and is
 +	 ignored.
 
          The NFS profile entry can have a value of 0 (do nothing)
          or  1  (operation is requested). Any other value is con-
@@ -323,15 +336,10 @@
 +	 to authenticate through Kerberos foremost.  Using this option updates
 +	 pam.conf(4) to include pam_krb5(5) to existing authentication stacks
 +	 for the specified service(s) in pam_service.  An example of a possible
 +	 pam_service is "dtlogin,sshd-kbdint".
 +
-+    -t
-+
-+	 Configures the client to be a NTP broadcast/multicast client if it
-+	 has not already been configured to be one.
-+
 ...
      ADMIN clntconfig
      FILEPATH /net/example1.com/export/krb5.conf
      NFS 0
      DNSLOOKUP none

Gary Winiger wrote:
>>> Following diff shows:
>>>
>>> 1. revised -s text
>>>       
>>> --s pam_service: where pam_service is the service name to be configured for
>>> -	Kerberos authentication in the pam.conf(4) file
>>> --t: configure a simple broadcast/multicast NTP client
>>> +-s pam_service:{first | only | optional}[,...]
>>> +	where pam_service is the service name to be configured for
>>> +	Kerberos as the account authority in the pam.conf(4) file
>>> +	first: try authenticating through Kerberos first, if this fails try to
>>> +		authenticate through Unix
>>> +	only: only try to authenticate through Kerberos
>>> +	optional: try authenticating through Unix first, if this is successful
>>> +		try to authenticate through Kerberos
>>> +	multiple services can be delimited by commas (",")
>>> +
>>> +	Three files will be installed with this project under /etc/security/pam:
>>> +		pam_krb5_first
>>> +		pam_krb5_only
>>> +		pam_krb5_optional
>>> +	These files pertain to the "include" references in pam.conf when the -s
>>> +	option has been used for any service names specified.	
>>>       
>> 	Please install the files to "include" in the default place defined
>> 	in PSARC/2005/217 PAM include control flag.  That is:
>> 	included PAM configuration
>> 	files are assumed to be relative to /usr/lib/security/.
>>
>> 	Then absolute paths will not be required in "master" pam.conf.
>>     
>
> 	Can we close on this issue from 2 weeks ago?
>
> Gary..
>
>   


-- 
Shawn.


From wyllys.ingersoll@sun.com Wed Aug  1 12:10:00 2007
Received: from sunmail4.Singapore.Sun.COM (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id l71J9xSn027492
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 1 Aug 2007 12:09:59 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.Singapore.Sun.COM (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id l71J7bkb017833;
	Thu, 2 Aug 2007 03:07:43 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0JM300601ZSU9N00@brm-avmta-1.central.sun.com>; Wed,
 01 Aug 2007 13:07:42 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0JM3002RMZSTB760@brm-avmta-1.central.sun.com>; Wed,
 01 Aug 2007 13:07:41 -0600 (MDT)
Received: from [10.7.251.182] (punchin-wyllys.SFBay.Sun.COM [10.7.251.182])
	by jurassic-x4600.sfbay.sun.com (8.14.1+Sun/8.14.1)
 with ESMTP id l71J7e2H275741
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed,
 01 Aug 2007 12:07:41 -0700 (PDT)
Date: Wed, 01 Aug 2007 15:07:25 -0400
From: Wyllys Ingersoll <wyllys.ingersoll@sun.com>
Subject: PSARC 2007/401kclient version 2
To: PSARC-ext@sun.com
Message-id: <46B0D9ED.7090408@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.2.0.264296
User-Agent: Thunderbird 2.0.0.0 (X11/20070521)
Status: RO
Content-Length: 40

This case was approved today.

-Wyllys


