Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

Last yeer I kudn't spel Engineer. Now I are won.


devel / comp.protocols.kerberos / Re: Force to change password for users

SubjectAuthor
o Re: Force to change password for usersKen Hornstein

1
Re: Force to change password for users

<mailman.94.1713548079.2322.kerberos@mit.edu>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1162&group=comp.protocols.kerberos#1162

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: kenh@cmf.nrl.navy.mil (Ken Hornstein)
Newsgroups: comp.protocols.kerberos
Subject: Re: Force to change password for users
Date: Fri, 19 Apr 2024 13:34:32 -0400
Organization: TNet Consulting
Lines: 11
Message-ID: <mailman.94.1713548079.2322.kerberos@mit.edu>
References: <PRAP251MB056715F9F72A4C47C0AE558CDB0D2@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM>
<eea80750-d5a6-48f9-b2c4-4efc399655e5@mit.edu>
<PRAP251MB0567B093E24E8C80B382C245DB0D2@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM>
<202404191734.43JHYWQK028397@hedwig.cmf.nrl.navy.mil>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="26814"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: Greg Hudson <ghudson@mit.edu>, "kerberos@mit.edu" <kerberos@mit.edu>
To: Carlos Lopez <clopmz@outlook.com>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=UdEFbRJH;
dkim=pass (2048-bit key,
unprotected) header.d=nrl.navy.mil header.i=@nrl.navy.mil header.a=rsa-sha256
header.s=s2.dkim header.b=MVlaDjL7
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=Deua67S6fp3ZUkWrWa/9ZQhbz6U2T+pnymQf2kV5OYteuqehSXLy4PhHx85/xzmcaf6wPN0w1gsR8yOQ8BjiCNbTPJGaq6FFa08L9IWYX5hUq7b17cpbzaNC3pN1a8M8yhryemltbEyQSNLvJKskHB/45gO6OR5Mj31sn8fbzm+VDPtfSi9ZeK8AEZR9whgzDcTLj7gkHerzZf3V26g3zZf0khkssTPvmEo0LvdEHrVqLnSITgHg7BFueiWxHdlvXULpwV47p6xw7VvtNAN9twH3H6+0Ao01MTqQqPaWtV2CiDNVSp2Vg1EGJDuuvs9B1X0lFTqW1c71BpwXq4nK5A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=wL5yuwIu5ZnLfUzPoAikvJDpUtHdioFcCCiSCTXcTkI=;
b=FOOsmOzQyNVisB0GGoCHeDGfM3n0eBZX8OfUSM2clOK3dhbcmCByGbN/6mqMI6WZFj9Ib4X9G425RNvCSFfNE4oY1YWRu9sEoMlY5DSW38rcxMzg93FZXy7TZYXmx/mIMC5DaNqoRlwuWattZd8cbItfc9wKn+6J9166FQ5Vma/qrFr70DV0t76XXhbq0hVbScgPeBPhMnxUYWrxU8TCkP8CRIddJYOspoA+noHvyEervCdJRzwAFlexgBsbNRBVPFU3z3Cbm8ILJPJ78GEgzgVvHe7S8RQl4p7kijJMxr0QOYa4tBodTYvhAkaB3DJd30HVVx4bu1KqdbdNLLkI3Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
140.32.59.234) smtp.rcpttodomain=mit.edu smtp.mailfrom=cmf.nrl.navy.mil;
dmarc=pass (p=reject sp=reject pct=100) action=none
header.from=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=wL5yuwIu5ZnLfUzPoAikvJDpUtHdioFcCCiSCTXcTkI=;
b=UdEFbRJHLHv5UnqExYgj0Pg1XSlW/2rqAYusKvwkZHR4x+wTcKQqtFsbHl8v//uk9AqY9haUd8ZV8TLE0NvAfp58YWn3dShvWXufsyGl4W91VrZ4zs3MQHUI84rK0ZX4pEwo+iTxOYIsH6h9RkOYlFHHR8j2enfIEVXNFd+HVFU=
Authentication-Results: spf=pass (sender IP is 140.32.59.234)
smtp.mailfrom=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil;dmarc=pass action=none header.from=cmf.nrl.navy.mil;
Received-SPF: Pass (protection.outlook.com: domain of cmf.nrl.navy.mil
designates 140.32.59.234 as permitted sender)
receiver=protection.outlook.com; client-ip=140.32.59.234; helo=mf.dren.mil;
pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nrl.navy.mil;
h=message-id : from :
to : cc : subject : in-reply-to : references : mime-version : content-type
: date; s=s2.dkim; bh=wL5yuwIu5ZnLfUzPoAikvJDpUtHdioFcCCiSCTXcTkI=;
b=MVlaDjL7qUOX1yk0pxAH5TCqtZTntGy0nJ948QZ0hq7uoCHASJm/LL7LvIzw4IX51y04
krh444/evRlrwI/rUN/CFrrDFE+kSaaWtN/dCVh64CaGJ92hQByO5EvfESFHFvNJGgmS
Vw1x3ZFIRSRzRGDNhtb0WMgnj1ki1/D2VGoGjViAOtWhFTVSxiB+uT7vHeSb2zV4Yd46
fDMu3sRnn842E3dYgRi6gny+2QuyKRogk1lDGFrgXgJgGSY5wa8Jw1WCCjyfbxgHkatJ
wUrBB+7ELWHhlAwGCjrSTeoBeNUZgR2g2m6/YoF9oJAmCb4/LS5orpRZO7QOmGZsTmvy lg==
In-Reply-To: <PRAP251MB0567B093E24E8C80B382C245DB0D2@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM>
X-Face: "Evs"_GpJ]],xS)b$T2#V&{KfP_i2`TlPrY$Iv9+TQ!6+`~+l)#7I)0xr1>4hfd{#0B4
WIn3jU;bql;{2Uq%zw5bF4?%F&&j8@KaT?#vBGk}u07<+6/`.F-3_GA@6Bq5gN9\+s;_d
gD\SW #]iN_U0 KUmOR.P<|um5yP<ea#^"SJK;C*}fMI;Mv(aiO2z~9n.w?@\>kEpSD@*e`
X-NRLCMF-Spam-Score: () hits=0 User Authenticated
X-NRLCMF-Virus-Scanned:
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: SN1PEPF000252A3:EE_|SJ0PR01MB6302:EE_
X-MS-Office365-Filtering-Correlation-Id: cea6a96b-dd2a-42dd-8521-08dc6096faa1
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: k9HdGFLnyq98pwJQEejQtfKHAPPijyR8bHFs0SSY8w2+XFy/84rOXI8/Flax
Qt82DTzgaGq6yCyN5Q+3vmS9gdheqc10Qnb/ZpjJwEdU5iBrQWR8/w4elYhA
lKCTvebXxA1Jk18isagcSB49X92gYNQ1h26wtDVcG/zHIjGYPja82Cai5FGN
zEooFUOGSkM+GhYqvIJO6H8lrPmS0NpgAJYhp8wOH489M3CnpntULhN5HFKT
JhPWgkCntsjy9qZphlKQm5WED3NTyf2NSGHxeYNBSmBZsYKvyHkbiPsFedbu
zHkmvWZCSQ/dBwrZ+rSG9bFkR7fkDS0JR5JAHZtzmp98Z7EJiR8A07zcm38M
61LzZwoOkzxAehjksTpmnb3oexRFmFZTDQVSQ9Y2gHejtC4MgR/EjC6JxmhT
lrujqz1a1A3zl42AYImSDypQsL4hnhF8hsSANMMiQrcvo03ce3CzCruTK3V7
Nu/Jsd1qHY/Am8m7r3mm6R9rEV4t3ckSCVA6MEBkBmjuC57EdMQ8gev0idZn
I2ml8uxlEkHqZzV1TFu6VOrepMLYL++lqcpcxJydP8rJCHAkFvYRP4esB9zV
UHzI7tHEkoqU3ykCtOztmF1jfwDvkB6ghimS2lD9BUE/L+aJaHCPnSJ/mw8a
+T0cuGb3Tu6qCHBiJ+a17Rv9pKLWyKc47EAZLdaFijBlU0hiptD9LjHJI9n9
n9ICQk1boX0WZf6KqQ9ovfMJXShNKrzsLp8YIVCt+Em5k+0seipe3MQyLu8X
OnXBxikH9HCndSnuxQqNcXNx84RXmQmPLKZTX2fLJ8GoUrPuGkIvpXrW/Cbl
wl/6YCwia9FTJo/+snFR6xEd3XNj3nIA+UomrGNPbfOPu87dDYjLDy5NFn2R
Tw6+2PfVYwlIC2tz2w9CwbkwpIPB8X0xvNmUEOUgbhZ42iueYG/8q6mhaqw4
AQoZEyuGTZH9H1q93F+1E+G1hjRbxlGG6cd+SM9tbQFV1dKPEfIcEeFCwehU
c+DAiQBFOmRNkub5Hgd68OWdv0clhxHqxqCyegKdHipXM4Svx2qOVTSglEPu
GqVPC8idVbl69Tp9W1gPXLsIlmDT0jfeNOqm3Qr0751DlXDT8SUUsLtdMFeZ
eJ+p+omFyNR1gWXr4fW65yEKS97DWxlWwgitTCwpF01gcErANRU6vNTBDDBr
E4JHxao4kaxEKMyqD1LR1KFeO3GUKfOD9EBuUoY/xdhU3ol1jQO16qNSF8La
LjFS6wSJ+uxOkb+iGW8eOgCJClSBOfM70I+ZacuDVONtikQpjOJcFCV9ot2w
dlK0b9NAVx3o/LVeSTM/YPEcj1gRUoVmLxXo+a0jYlPNgGtCcBCxNgjizyhH
urdJ67M=
X-Forefront-Antispam-Report: CIP:140.32.59.234; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mf.dren.mil; PTR:mfe.dren.mil; CAT:NONE;
SFS:(13230031)(376005)(48200799009)(61400799018); DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Apr 2024 17:34:34.4299 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: cea6a96b-dd2a-42dd-8521-08dc6096faa1
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: SN1PEPF000252A3.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR01MB6302
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <202404191734.43JHYWQK028397@hedwig.cmf.nrl.navy.mil>
X-Mailman-Original-References: <PRAP251MB056715F9F72A4C47C0AE558CDB0D2@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM>
<eea80750-d5a6-48f9-b2c4-4efc399655e5@mit.edu>
<PRAP251MB0567B093E24E8C80B382C245DB0D2@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM>
 by: Ken Hornstein - Fri, 19 Apr 2024 17:34 UTC

>User acquires kerberos ticket and login session is authorized. This log
>is for a ssh access ...

I think you're missing some of the details that Greg is asking. When you
say "ssh access", do you mean that you are using gssapi-with-mic or
gssapi-keyex authentication with ssh, or does ssh ask for the user's
Kerberos password? If the latter, ssh does not have that native ability,
so it it going through the PAM stack to make that happen? If so, which
PAM module are you using?

--Ken

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor