Re: Kerberos authentication with dsDoDirNodeAuth ?
site_archiver@lists.apple.com Delivered-To: darwin-dev@lists.apple.com On 01/03/2006, at 1:19 AM, Paul Nelson wrote: Because I want to authenticate to the node? :) A vanilla Open Directory Master LDAP node. Thanks, Nigel -- Nigel Kersten [Senior Technical Officer] College of Fine Arts, University of NSW, Australia. CRICOS Provider Code: 00098G _______________________________________________ Do not post admin requests to the list. They will be ignored. Darwin-dev mailing list (Darwin-dev@lists.apple.com) Help/Unsubscribe/Update your Subscription: http://lists.apple.com/mailman/options/darwin-dev/site_archiver%40lists.appl... It would help if you can tell us why you are doing the dsDoDirNodeAuth. I'm using in-directory ACLs to allow network account users to edit their own Contqct info, and would like to take advantage of the fact that all my users have Kerberos identities. What directory service node are you trying to authenticate with? Does the user already have a Kerberos ticket granting ticket in their cache? You can check for the TGT using 'klist'. Yes, I know. Irrespective of whether the user currently has a TGT or not, I can't work out how to this, or whether it's even possible in the DirectoryService API. This email sent to site_archiver@lists.apple.com
participants (1)
-
Nigel Kersten