On Tue, Oct 09, 2007 at 10:59:04PM -0400, Roberto C. Sánchez wrote: > > A posting by Russ Alberry on one of the OpenAFS sites mentioned using > the -K option to ssh on the client. The configuration file equivalent > is to add "GSSAPIDelegateCredentials yes" to /etc/ssh/ssh_config (for > system-wide) or to ~/.ssh/config (for per-user) credential delegation. > > So, now with that directive in my ~/.ssh/config I no longer receive the > permission denied, as the current ticket from my current session is > forwarded along properly. > Of course, if you are starting out on a host that is not in your Kerberos realm and then you ssh into a host that is in your Kerberos realm, then there is no ticket to delegate and you are sort of stuck. Regards, -Roberto -- Roberto C. Sánchez http://people.connexer.com/~roberto http://www.connexer.com
Attachment:
signature.asc
Description: Digital signature