This is the mail archive of the
mailing list for the Cygwin project.
RE: NTsec permissions issue over inet
- From: Igor Pechtchanski <pechtcha at cs dot nyu dot edu>
- To: "Banville, Stephen" <Stephen dot Banville at sycamorenet dot com>
- Cc: cygwin at cygwin dot com
- Date: Tue, 3 Jun 2003 08:56:46 -0400 (EDT)
- Subject: RE: NTsec permissions issue over inet
- Reply-to: cygwin at cygwin dot com
Windows "security" is built in such a way that it won't trust
authentication tokens from remote machines that don't contain a password.
Thus, if you use passwordless ssh or rexec, the token created will be
enough for the local machine, but won't be accepted by a remote share.
Password-authenticated ssh *will* let you access network shares (you may
have to re-authenticate for the share itself by providing a user and
password to "net use". An alternative is to run sshd from a shell owned
by the user you'll be logging in as, and then you should be able to use
passwordless authentication and access network shares too, at the price of
not being able to log in as other users. You might be able to pull the
same trick with inetd as well (i.e., don't "--install-as-service")... In
this case, they will reuse the token created when you logged in, IIUC.
On Tue, 3 Jun 2003, Banville, Stephen wrote:
> Sorry about that. Here si the body of the message that I am replying
> too. I am basically looking for a work-around regarding this issue with
> not being able too access network driver during remote acess. There has
> been some insight on what the problem seems to be in regards to the
> version of Cygwin. My question is regards to a immediate work-around
> this permissions issue with inetd/xinetd ?
> Thanks everyone for taking the time in looking into this issue.
> Fwd: Re: NTsec permissions issue over inet]
> From: Larry Hall <cygwin-lh at cygwin dot com>
> To: Cygwin <cygwin at cygwin dot com>
> Date: Mon, 02 Jun 2003 23:33:51 -0400
> Subject: [Fwd: Re: NTsec permissions issue over inet]
> Reply-to: cygwin at cygwin dot com
> -------- Original Message --------
> Bruce Dobrin wrote:
> > YIKES!!!!! There it is, and right there in the users guide no less....
> > not only that, but in a section I've actually read a number of
> > times!!!!!..... Well, that does explain almost everything that is going on
> > ( though, it seems to have gotten even tighter since the 1.3.12 release
> > that allows me to access net drives if I specify a passwd during rlogin( as
> > mentioned below)). The perl script is actually running as a service; as a
> > user with net access rights.
> > I hate to ask this without looking at the inetd/xinetd code first: But is
> > there any chance that context switching will be "fixed" to allow net access
> > too someday?
> Not without some mechanism to provide the password to Windows, no. If
> someone would like to take this statement as a challenge and provide an
> alternate solution, please do. :-)
> -----Original Message-----
> From: Igor Pechtchanski [mailto:email@example.com]
> Sent: Tuesday, June 03, 2003 8:35 AM
> To: Banville, Stephen
> Cc: firstname.lastname@example.org
> Subject: Re: NTsec permissions issue over inet
> On Tue, 3 Jun 2003, Banville, Stephen wrote:
> > Bruce,
> > This is starting to become clear o what is actually going on.
> > How do you currently get around this issue ?
> > Steve
> Please either quote the message you're replying to, or make sure your
> mailer contains threading information (the In-Reply-To and/or References
> headers). Personally, I have no idea which message you replied to.
|\ _,,,---,,_ email@example.com
ZZZzz /,`.-'`' -. ;-;;,_ firstname.lastname@example.org
|,4- ) )-,_. ,\ ( `'-' Igor Pechtchanski
'---''(_/--' `-'\_) fL a.k.a JaguaR-R-R-r-r-r-.-.-. Meow!
"I have since come to realize that being between your mentor and his route
to the bathroom is a major career booster." -- Patrick Naughton
Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple
Problem reports: http://cygwin.com/problems.html