JiscMail Logo
Email discussion lists for the UK Education and Research communities

Help for MOONSHOT-DEV Archives


MOONSHOT-DEV Archives

MOONSHOT-DEV Archives


MOONSHOT-DEV@JISCMAIL.AC.UK


View:

Message:

[

First

|

Previous

|

Next

|

Last

]

By Topic:

[

First

|

Previous

|

Next

|

Last

]

By Author:

[

First

|

Previous

|

Next

|

Last

]

Font:

Proportional Font

LISTSERV Archives

LISTSERV Archives

MOONSHOT-DEV Home

MOONSHOT-DEV Home

MOONSHOT-DEV  July 2014

MOONSHOT-DEV July 2014

Options

Subscribe or Unsubscribe

Subscribe or Unsubscribe

Log In

Log In

Get Password

Get Password

Subject:

Re: Problems with the Windows SSP, or not?

From:

Kevin Wasserman <[log in to unmask]>

Date:

Fri, 25 Jul 2014 12:11:49 -0400

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (107 lines)

1) What Rhys said about using gssclient/server test to start :-)

2) If you are not a domain machine, you'll need to use msetupgui to add 
a user mapping to a local account; you can specify * for nai to map 
everything to the same account.

3) From the logs you posted, I can tell that no call was ever made to 
GsspInitSecContext(), so no attempt was made to establish a security 
context through the SSP.

Kevin Wasserman
Painless Security

On 7/25/2014 12:00 PM, Rhys Smith wrote:
> Suggest you use gss-client and gas-server to test what’s going on. Run gas-server on the machine running SSH, and gss-client on the windows box, and make sure that it’s able to authenticate and get a message sent from one to the other - and you can see what radius attributes are present.
>
> Which reminds me that I haven’t written the wiki page on how to test using gss-client/server yet.
>
> On server, run  /opt/moonshot/sbin/gss-server -verbose gss@SERVER-FQDN (or wherever the binary lives)
>
> On client, run .\gssclient.exe -user user@realm -pass XXX SERVER-FQDN gss/SERVER-FQDN “hello?"
>
> That should throw up the prompt for creds, and get the ball rolling...
>
> Rhys.
> --
> Dr Rhys Smith
> Identity, Access, and Middleware Specialist
> Cardiff University & Janet, the UK's research and education network
>
> email: [log in to unmask] / [log in to unmask]
> GPG: 0x4638C985
>
> On 25 Jul 2014, at 11:56, Rhys Smith <[log in to unmask]> wrote:
>
>> Bugger, sorry, I was thinking about things on the server end not the client end sorry. Ignore what I said.
>>
>> So remember that on the client end the SSP is not configured to talk to a RADIUS server, that’s only on the server end.
>>
>> On the client end, there should be no configuration necessary and you should not expect to see any RADIUS traffic. The connection to RadSec is at the SSH server end of things. All the SSP client does is get credentials from its credential store (i.e. windows credman).
>>
>> Rhys.
>> --
>> Dr Rhys Smith
>> Identity, Access, and Middleware Specialist
>> Cardiff University & Janet, the UK's research and education network
>>
>> email: [log in to unmask] / [log in to unmask]
>> GPG: 0x4638C985
>>
>> On 25 Jul 2014, at 11:41, Stefan Paetow <[log in to unmask]> wrote:
>>
>>> I'm working on putty. I've tried an authentication (AcquireCredentialsHandle is being called and I get a prompt from the credential manager to enter a password for my principal), but the SSH server says
>>>
>>> debug1: No credentials were supplied, or the credentials were unavailable or inaccessible.
>>> Unknown error
>>> debug1: Got no client credentials
>>>
>>> The files capture that specific run (after a reboot). I am pointing at the correct RADIUS server (and I know I am because when I telnet to port 2083 on the machine in question, I get a connection ok). I don't however see any connections to the RADIUS server at all, so I'd like to know how I can know whether AcquireCredentialsHandle has in fact received credentials on the client end at all?
>>>
>>> It'll help me narrow down whether it is the putty part *after* the credential acquisition that is borked or whether it how the credential's been put into the credentials manager.
>>>
>>> The Windows machine is a *workgroup* machine (i.e. *not* with a domain).
>>>
>>> Stefan
>>>
>>> -----Original Message-----
>>> From: Kevin Wasserman [mailto:[log in to unmask]]
>>> Sent: 25 July 2014 16:30
>>> To: Stefan Paetow; [log in to unmask]
>>> Subject: Re: Problems with the Windows SSP, or not?
>>>
>>> I'm sorry; I don't understand the question. Can you tell me what you were doing (precisely what apps you were running on what machines), what results you got, and what you expected?
>>>
>>> Kevin Wasserman
>>> Painless Security, LLC
>>>
>>> On 7/25/2014 11:21 AM, Stefan Paetow wrote:
>>>> Hi,
>>>>  From the attached logs I'm not sure whether the SSPI actually
>>>> releases an identity or not... Can someone who knows the SSP tell me if
>>>> it actually does? From what I see in the logs it doesn't seem to release a principal?
>>>> Stefan Paetow
>>>> Moonshot Industry & Research Liaison Coordinator
>>>> t: +44 (0)1235 822 125
>>>> Janet, the UK's research and education network.
>>>>
>>>> Janet(UK) is a trading name of Jisc Collections and Janet Limited, a
>>>> not-for-profit company which is registered in England under No.
>>>> 2881024 and whose Registered Office is at Lumen House, Library Avenue,
>>>> Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238
>>>>
>>>
>>> ---
>>> This email is free from viruses and malware because avast! Antivirus protection is active.
>>> http://www.avast.com
>>>
>>>
>>> Janet(UK) is a trading name of Jisc Collections and Janet Limited, a
>>> not-for-profit company which is registered in England under No. 2881024
>>> and whose Registered Office is at Lumen House, Library Avenue,
>>> Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238

---
This email is free from viruses and malware because avast! Antivirus protection is active.
http://www.avast.com

Top of Message | Previous Page | Permalink

JiscMail Tools


RSS Feeds and Sharing


Advanced Options


Archives

April 2024
March 2022
December 2021
October 2021
September 2021
August 2021
June 2021
April 2021
February 2021
January 2021
December 2020
November 2020
October 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
December 2019
November 2019
October 2019
September 2019
July 2019
June 2019
May 2019
April 2019
March 2019
February 2019
January 2019
December 2018
November 2018
April 2018
February 2018
January 2018
December 2017
November 2017
September 2017
August 2017
July 2017
June 2017
May 2017
April 2017
February 2017
January 2017
December 2016
October 2016
September 2016
August 2016
June 2016
April 2016
March 2016
February 2016
January 2016
December 2015
November 2015
October 2015
August 2015
July 2015
May 2015
April 2015
March 2015
February 2015
January 2015
December 2014
November 2014
October 2014
September 2014
August 2014
July 2014
June 2014
May 2014
April 2014
March 2014
February 2014
January 2014
December 2013
November 2013
October 2013
September 2013
August 2013
July 2013


JiscMail is a Jisc service.

View our service policies at https://www.jiscmail.ac.uk/policyandsecurity/ and Jisc's privacy policy at https://www.jisc.ac.uk/website/privacy-notice

For help and support help@jisc.ac.uk

Secured by F-Secure Anti-Virus CataList Email List Search Powered by the LISTSERV Email List Manager