Skip to content

fix: krb5 ticket forwarding#227

Merged
jaysa68 merged 8 commits intomainfrom
fix-krb5-tix
Apr 2, 2026
Merged

fix: krb5 ticket forwarding#227
jaysa68 merged 8 commits intomainfrom
fix-krb5-tix

Conversation

@jaysa68
Copy link
Copy Markdown
Member

@jaysa68 jaysa68 commented Apr 2, 2026

  • add forwardable flag to tickets (run klist -f to see flags)
  • limit ticket forwarding from desktops to login servers

@jaysa68 jaysa68 requested a review from 24apricots April 2, 2026 00:24
oliver-ni
oliver-ni previously approved these changes Apr 2, 2026
Copy link
Copy Markdown
Member

@24apricots 24apricots left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

knuckles approved

@jaysa68 jaysa68 enabled auto-merge (squash) April 2, 2026 04:22
@jaysa68 jaysa68 merged commit 48bc1a6 into main Apr 2, 2026
3 checks passed
@jaysa68 jaysa68 deleted the fix-krb5-tix branch April 2, 2026 04:23
danxliu pushed a commit that referenced this pull request Apr 2, 2026
* use openssh_gssapi for sshd on all hosts

* GSSAPIKeyExchange = yes if host has a keytab

* test an option

* ticket forwarding flag

* undo unhelpful option

* test without specifying openssh package

* implement oliver suggestions

---------

Co-authored-by: 24apricots <michaelzls@berkeley.edu>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants