Stopping the service principle from requesting a TGT

Is there a way to stop the service end of the JGSS negotiation from requesting a TGT for its service principle ?
</P>
In a Kerberos GSSAPI negotiation the accepting service only needs access to a keytable containing the exported service key to successfully authentication and identify the client principal. The service does not need any network access to the KDC.
</P>
The JGSS implementation during the acceptSecContext requests a TGT for the service principal, even though it makes no use of it and discards it. The service therefore requires network access to the KDC and incurs the overhead of a KDC access for each authentication.
</P>
This can simply be demonstrated using the sample code at:
</P>
http://java.sun.com/javase/6/docs/technotes/guides/security/jgss/tutorials/BasicClientServer.html
</P>
If the com.sun.security.jgss.accept entry is bcsLogin.conf is modified to:
</P>
com.sun.security.jgss.accept {
com.sun.security.auth.module.Krb5LoginModule required storeKey=true doNotPrompt=true useKeyTab=true keyTab="service.keytab" principal="service";
</P>
I would not expect the service to request a TGT, but it does, as the KDC log shows:
</P>
Jun 27 16:06:35 kdc krb5kdc[1865](info): AS_REQ (3 etypes {16 3 1}) 192.168.111.1: ISSUE: authtime 1151420795, etypes {rep=16 tkt=16 ses=16}, service@REALM for krbtgt/REALM@REALM
Jun 27 16:06:35 kdc krb5kdc[1865](info): AS_REQ (3 etypes {16 3 1}) 192.168.111.1: ISSUE: authtime 1151420795, etypes {rep=16 tkt=16 ses=16}, service@REALM for krbtgt/REALM@REALM
</P>
Any ideas ?
</P>
Thank
</P>
Phil

Hi Seema,
Thanks for the reply. I assume you're talking about the isInitiator flag ?
I'm using Java version 1.6.0-beta2 and still getting the same results. The config file is now:
com.sun.security.jgss.initiate {
  com.sun.security.auth.module.Krb5LoginModule required
useTicketCache=true ticketCache=ticket.cache debug=true;
com.sun.security.jgss.accept {
  com.sun.security.auth.module.Krb5LoginModule required isInitiator=false
storeKey=true doNotPrompt=true useKeyTab=true
keyTab="service.keytab" principal="service" debug=true;
};The output from the SampleServer is:
[root@kdc gssapi.new]# ./server
Waiting for incoming connection...
Got connection from client /127.0.0.1
Will read input token of size 445 for processing by acceptSecContext
Debug is  true storeKey true useTicketCache false useKeyTab true
doNotPrompt true ticketCache is null KeyTab is service.keytab
refreshKrb5Config is false principal is service tryFirstPass is false
useFirstPass is false storePass is false clearPass is false
principal's key obtained from the keytab principal is service@REALM
Acquire TGT using AS Exchange
EncryptionKey: keyType=3 keyBytes (hex dump)=0000: 57 08 1A 80 75 D0 7C 31
...As you can see the server is still acquiring a TGT. Also the isInitiator flag is not showing up in the debug options.
Is this functionality in version 1.6.0-beta2 ?
Thanks again
Phil

Similar Messages

  • Stopping the service order from further processing

    Hi Experts,
    According to my requirement, the service orders will be generated by the call centre agents , then they will release and the technicians will be determined . The pager messages will go to the technicians.
    But the service order whic are generated after 5 PM , we should not send the messages to the technicians althought the service orders are released.
    For this where should I do the coding , which is the exact place to stop the service order from further processing.
    Please help me out in this.
    Thanks in Advance,
    Praveen

    Hi,
    The best way would be to implement a ORDER_SAVE Badi..wherein u can stop a service order for further processing based on the status..
    Regards,
    PePe

  • Start and stop the Communication channel from Java Mapping

    How to start and stop the Communication channel from Java Mapping in XI 3.0
    Scenario  PI - > MQ -> Third Party web application 
    Web application is down and then Communication channels are stop manually .  
    We need to automate this process,
    MQ Solution - Trigger will be set in MQ which will be called when web application is stopped
    Trigger will send u201CSTOP u201C message to PI
    How to configure PI scenario to stop different com channels when this message received ?

    check this link: http://help.sap.com/saphelp_nw04/helpdata/EN/45/0c86aab4d14dece10000000a11466f/frameset.htm
    make sure that MQ send http request to PI. i dont think a configuration scenario is required in PI. Only roles should be enabled with proper user provided to MQ team.
    However, for security reasons, you can configure a scenario if you dont want to expose PI infrastructure directly to 3rd parties.

  • How can I stop the voice over from my apple tv

    I have just connected my Apple TV which appears to be working ok. How do I stop the interactive voice from speaking.

    I have the 2nd Gen Apple TV and it is where I said. Have you updated yours to the latest firmware/software? I can't see why you are unable to find it otherwise. I will take pictures if you want me to.

  • How to stop the tab bar from automatically hiding itself?

    ive only found how to stop the address bar from disappearing and everyone with the tab problem seems to have posted this over a week ago and still hasnt been fixed yet if noone has a fix im out and done with firefox they can suck a fat one
    why add this feature! i can understand the address bar but not the tabs all you have to do to hide it was push the tab button again and its gone was that so fucking hard that you had ruin a perfectly fine browser

    Hello,
    In Firefox 23, as part of an effort to simplify the Firefox options set and facilitate future improvements to Firefox, the option to hide the tab bar was removed.
    Fortunately, this can easily be resolved if you desire the keep tabs hidden. You can install "[https://addons.mozilla.org/firefox/addon/hide-tab-bar-with-one-tab/ Hide tab bar with one tab]", an extension hosted on Mozilla's add-ons site, which will restore the ability to hide the tab bar.
    Thank you and I hope this helps!

  • How to stop the option key from changing tools when trying to subtract from a selection?

    How to stop the option key from changing my tools when I am trying to subtract from a selection?
    I'm running CS3 on Mac OS Leopard, and the automatic tool switching slows me down, but even preferences doesn't show a way to turn this off.
    Thanks for your help.

    With any marquee tool, JUST holding down the option key should not switch tools. You need to explain the problem much more carefully, It's completely impossible to tell from your description whats going wrong.
    automatic tool switching
    The only preference related to this, is to do with the SHIFT KEY - "use Shift key for tool switch".

  • How to stop the services provided by net80 and oracle9i

    how to stop the services provided by net80 and oracle9i during the installation of forms6i & reports6i in windows 2003 server

    Go into the control panel and choose services ... stop the services.

  • How to stop the gray wheel from spinning after logging out

    how to stop the gray wheel from spinning after logging out?

    Frank ...
    Make sure to quit all open applications before logging out.
    Your proflie indicates your Mac has v10.7.1 installed.
    If that is the case, updating your system software will help as far as functionaly as well as security.
    Install the OS X Lion Update 10.7.5 (Client Combo)
    Then restart your Mac.
    message edited by:  cs

  • TS1567 What if the "Stop the service" is not available?

    I really need some help. My iPod will not sync to my iTunes as the "Apple Mobile Device Service" is off or something however I found instructions to help me turn it on and back off but there is no setting for "Stop The Service". I wondered if anyone could help me! Thank you

    See the actions for AMDS included here:
    iOS: Device not recognized in iTunes for Windows

  • Connect-SPOService : The Application ID (AppID) for which the service ticket is requested does not exist on the system.

    I am trying to connect to SharePoint in my Office 365 environment by following https://support.office.com/article/Set-up-the-SharePoint-Online-Management-Shell-environment-7b931221-63e2-45cc-9ebc-30e042f17e2c and I am getting:
    Connect-SPOService : The Application ID (AppID) for which the service ticket is requested does not exist on the system.
    Is there some setting I need to change on the O365 side? Thanks.

    Hi,
    Based on your description, my understanding is that you want connect SharePoint Online using PowerShell.
    Please make sure that the following software is installed.
    Windows Management Framework 3.0
    SharePoint Online Management Shell
    And then, open the SharePoint Online Management Shell and use the Script below to test
    whether it works.
    $User = "[username]@[tenant].onmicrosoft.com"
    $Pass = "[password]"
    $creds = New-Object System.Management.Automation.PSCredential($User,(ConvertTo-SecureString $Pass -AsPlainText -Force));
    Connect-SPOService -Url https://[tenant]-admin.sharepoint.com -Credential $creds
    Get-SPOSite
    More information:
    http://blog.falchionconsulting.com/index.php/2013/01/using-powershell-to-manage-sharepoint-2013-online/
    Thanks,
    Dennis Guo
    TechNet Community Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Dennis Guo
    TechNet Community Support

  • I have a macbook pro.How do I stop the color wheel from spinning?

    I have a macbook pro.How do I stop the color wheel from spinning? I can not get the computer to shut down w/out doing a force quit.

    I suggest you download and install EtreCheck from http://etresoft.com/etrecheck
    Run EtreCheck and publish report here
    Allan

  • How do i stop the icloud window from poping up everytime i start iTunes ? i do not have an icloud account and don't want one., how do i stop the icloud window from poping up everytime i start iTunes ? i do not have an icloud account and don't want one.

    how do i stop the icloud window from poping up everytime i start iTunes ? i do not have an icloud account and don't want one., how do i stop the icloud window from poping up everytime i start iTunes ? i do not have an icloud account and don't want one.

    If you don't have an icloud account, then icloud is not the thing that's popping up a window.
    If you are being asked to enter a password when accessing itunes, then the problem may be that you have purchased items (apps, songs, etc) on the device that were purchased using a different itunes account than the one you currently have defined on your device. 
    Purchased items are forever associated with the itunes account (the apple ID) that was used to make the purchase.  If you change the ID on the device, you won't be able to update any of them.  You'll have to purchase them again.

  • How do i stop the keychain window from popping up it is really annoying?

    How do I stop the keychain window from popping up, it is really annoying?

    What is the specific message you are getting?
    If it's asking for a password, then enter it and you should be good. If you don't know the password, then I would probably recommend reseting your keychain entirely. Your keychain keeps saved password for certain websites and programs but in my expereince the average user is not tremendously affected by reseting the keychain. It's just a matter at that point of reentering your passwords manually if you've gotten used to them populating automatically.
    Check out http://support.apple.com/kb/ts1544 for an article on how to reset the keychain.

  • Anyone know how to stop the "activate" box from blocking usage of a perfectly legal copy of Ilisten? I want to help my dyslexic grandson and this box, including the activation code, keeps popping up, keeping me from using the software. I activated the pro

    Anyone know how to stop the "activate" box from blocking usage of a perfectly legal copy of Ilisten? I want to help my dyslexic grandson and this box, including the activation code, keeps popping up, keeping me from using the software. I activated the program and did a few profile building sessions, now it pops up each time I start the program, blocking me from using it. Help sure would be appreciated.
    Jay

    I looked at your post this morning and did not know enough to respond, other than to find out that links to iListen now go to newer, renamed software. Considering it's been nine hours with no response, I'm suspecting few people here have experience with that software. You could contact the current copmany that used to sell that package and see if they have any archived support info.
    BTW: please check you entry for "Mac OS" in your profile. It says iOS, which cannot run on an iMac. iOS is the system for phone and iPads but can't run on Mac computers. Do "About this Mac" from the Apple menu and see what it says about the OS version. Should look like this:
    If the "Processor" line says "Intel," you have a newer Mac than the old modles this forum covers; Intel iMac have their very own forum here:
    iMac (Intel)

  • Is there a way to stop the mail icon from bouncing

    Hi all.  Is there a way to stop the mail icon from bouncing on the dock when a new message is received?  It's irritating.  I'm running Lion.  Thanks.
    Kelly

    Thank you Linc.  I knew that I did something in system preferences to cause it to bounce, but couldn't remember what I did.  I appreciate your help!  Kelly

Maybe you are looking for