![]() |
![]() |
| Home | What's New | Products | Download | Purchase | Support | About Us | Contact |
SUPPORT > TIPS
|
|
|
|
Accessing Network Resources With VShell And Public-Key-Only AuthenticationPrevious to VShell server version 2.6.3 and Windows 2003 Active Directory, Windows file shares were not easily available to Secure Shell users who authenticate using public keys, as they are with password authentication. There are work-arounds, but they can be inconvenient or cumbersome. However, if the VShell server and shared resources are running in a properly configured Windows 2003 Active Directory domain, file shares can be made available to accounts that authenticate using public keys. This page includes all the steps necessary to configure the domain and VShell server. Access to file shares applies to all SSH2 clients, including SecureFX, SecureCRT, and the sfxcl.exe, vsftp.exe, and vcp.exe command-line utilities. Versions 2.6.3 and later of the VShell server support a Windows capability called Kerberos Protocol Transition (KPT), which is part of the infrastructure created by Microsoft to support Kerberos. The VShell server takes advantage of Windows KPT to create the user's credentials, but does not use Kerberos authentication. Configuration is straightforward and occurs largely on the domain controller, where the administrator sets up constrained delegation for the systems that will handle authentication requests. VShell configuration consists entirely of ensuring that the Kerberos Protocol Transition option is enabled, which is the default for VShell 3.0 and later. System Requirements for File Share Access Using KPTIn order to support Windows file shares via Kerberos Protocol Transition, the Windows environment must meet the following conditions:
Configuring Constrained Delegation on the Domain ControllerIn this procedure, the following example environment is used:
To configure constrained delegation, log onto dc.somedomain.com as a domain administrator and launch the Active Directory Users and Computers MMC interface (open the Start menu and select Administrative Tools): 1. In the tree view, select somedomain.com.
3. Find vshell.somedomain.com
in the list of computers.
6. Click on the Add button.
9. Back in the Add Services dialog, select
cifs from the list of Available services.
In the Properties dialog for vshell.somedomain.com, confirm that the service type you just added is listed, and that the User or Computer is fs.somedomain.com. ![]() Configuring VShell to Use Kerberos Protocol TransitionVShell Server Version 3.6 and later on vshell.somedomain.com
VShell Server Version 2.6.3 through 3.5.4 on vshell.somedomain.com WARNING: If you use the registry editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. There is no guarantee that you can solve problems that result from using the registry editor incorrectly. Use the registry editor at your own risk. 1. Start regedit and navigate to:
2. If a REG_DWORD value named "Use
Kerberos Protocol Transition" does not already exist, create
it. With the VShell server and the Active Directory domain controller configured properly as described above, users should be able to authenticate to VShell on vshell.somedomain.com using public-key-only authentication and gain access to the share "fileshare" on fs.somedomain.com whether by SFTP roots or other means.
|
|||||||||
| Products | Downloads | Purchase | Support | About Us | |
|---|---|---|---|---|---|
| VShell Server | VShell Server | Buy Direct | Evaluation | Contact | |
| SecureCRT | SecureCRT | License Pricing | Updates Policy | Press Releases | |
| SecureFX | SecureFX | About Encryption Export | FAQs | What's New | |
| VanDyke ClientPack | VanDyke ClientPack | Orders FAQ | Tips & How-Tos | Customer Stories | |
| Beta Software | Beta Software | Resellers | Forums | Secure Solutions | |
|
Site Map | Legal Notices | Privacy Policy | Refund Policy VShell, SecureCRT, SecureFX, Entunnel, CRT, and AbsoluteFTP are trademarks or registered trademarks of VanDyke Software, Inc. in the United States and/or other countries. All other trademarks or registered trademarks are the property of their respective owners. Copyright © 1995 - VanDyke Software, Inc. All rights reserved. |
|||||