commended to prevent Kerberos Tickets and
password hashes to be cached on the server.
Typically these tickets and hashes are used for lateral movement after a
breach.
libfreerdp2-2 needs to be compiled with "WITH_GSSAPI=on" to be able to
connect with user accounts protected in such a way.
Kind Regads,
Markus Wigge
answers = [x for x in dns.resolver.query(query,
rdtype=dns.rdatatype.SRV)]
if answers:
host = str(answers[0].target)
port = int(answers[0].port)
Kind Regards,
Markus Wigge
Hi,
first of all: thanks for your great work.
Now the feedback:
I built the freeradius 3.0.12 packages for jessie on my own based on
your experimental sources.
Over all that worked fine but I needed the debhelper bpo-version.
The configuration looks unfamiliar but that is I suppose normal for a
Package: freeradius-ldap
Version: 2.2.5+dfsg-0.2
Severity: important
Tags: upstream
Dear Maintainer,
I encountered severe problems trying to match users to their LDAP Groups.
Within the inner-tunnel config I check the group ACL for a given user like
this:
if (LDAP-Group == "NET_eduroam") {
Package: icinga-common
Version: 1.5.1-1~bpo60+1
Severity: important
Tags: sid
Hi,
I noticed the following directory listing with icinga 1.5.1 from backports
which seems obviously wrong:
ls -l /usr/share/icinga/plugins/eventhandlers/
insgesamt 44
-rw-r--r-- 1 root root 822 12. Sep 15:46 disable_
Package: libapache2-mod-auth-kerb
Version: 5.4-1.1
Severity: important
Tags: squeeze patch
Hi,
I really need the option "KrbAppendRealm" to strip off the realm. Otherwise
it is not possible to check the group membership of the username using LDAP.
Simply readd the patch in "debian/patches/series
6 matches
Mail list logo