Setting up Kerberos, AFS, and Putty on Windows Vista/Windows 7



Similar documents
OpenVPN over SSH tunneling

Contents. VPN Instructions. VPN Instructions... 1

Securing Windows Remote Desktop with CopSSH

GlobalProtect Agent User Guide for Windows

ProxyCap Help. Table of contents. Configuring ProxyCap Proxy Labs

IIS, FTP Server and Windows

Securing Windows Remote Desktop with CopSSH

MultiSite Manager. Setup Guide

Using WinSCP to Transfer Data with Florida SHOTS

Defender Token Deployment System Quick Start Guide

Connecting To SOM Network Drives With Windows XP

MultiSite Manager. Setup Guide

Undergraduate Academic Affairs \ Student Affairs IT Services. VPN and Remote Desktop Access from a Windows 7 PC

Miami University RedHawk Cluster Connecting to the Cluster Using Windows

MIGRATING TO AVALANCHE 5.0 WITH MS SQL SERVER

Windows Clients and GoPrint Print Queues

Install FileZilla Client. Connecting to an FTP server

Quick Connect. Overview. Client Instructions. LabTech

Quick Instructions Installing on a VPS (Virtual Private Server)

owncloud Configuration and Usage Guide

Setting up VMware ESXi for 2X VirtualDesktopServer Manual

TAMUS Terminal Server Setup BPP SQL/Alva

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

Apple Mac VPN Service Setting up Remote Desktop

Microsoft FrontPage 2003

AutoMate BPA Server 10 Installation Guide

Getting Started with Tableau Server 6.1

QUANTIFY INSTALLATION GUIDE

Install and configure SSH server

How to Use Remote Desktop over a Secure Connection (SSH)

Acunetix Web Vulnerability Scanner. Getting Started. By Acunetix Ltd.

Hallpass Instructions for Connecting to Mac with a Mac

Connecting to the Remote Desktop Service

Computer Science and Engineering MacOS Cisco VPN Client Installation and Setup Guide

Connecting to Delta College Exchange services off-campus

How to Connect to Remote Desktop & How to Use Cisco AnyConnect Secure Mobility Client Secure VPN Connection

APNS Certificate generating and installation

Tunnel VNC through SSH Tutorial Version 1

Mesa DMS. Once you access the Mesa Document Management link, you will see the following Mesa DMS - Microsoft Internet Explorer" window:

1. Data Domain Pre-requisites. 2. Enabling OST

NovaBACKUP xsp Version 12.2 Upgrade Guide

How to install and use the File Sharing Outlook Plugin

BushSoft Accounts - Installation manual

Add in Guide for Microsoft Dynamics CRM May 2012

Training module 2 Installing VMware View

TM Online Storage: StorageSync

How To Upgrade Your Microsoft SQL Server for Accounting CS Version

Introduction. Before you begin. Installing efax from our CD-ROM. Installing efax after downloading from the internet

Kaseya 2. User Guide. Version 6.1

Add in Guide for Microsoft Dynamics NAV May 2012

Crystal Reports Installation Guide

Global VPN Client Getting Started Guide

Install and Configure Oracle Outlook Connector

Snow Active Directory Discovery

How to use FTP Commander

Internet Explorer 7 for Windows XP: Obtaining MIT Certificates

Configuring Claims Based FBA with Active Directory store 1

Livezilla How to Install on Shared Hosting By: Jon Manning

eduroam Network guide configuration for Microsoft Windows 7

Sage Intelligence Financial Reporting for Sage ERP X3 Version 6.5 Installation Guide

OSPI SFTP User Guide

Setting up a Scheduled task to upload pupil records to ParentPay

MICROSTRATEGY 9.3 Supplement Files Setup Transaction Services for Dashboard and App Developers

Check current version of Remote Desktop Connection for Mac.. Page 2. Remove Old Version Remote Desktop Connection..Page 8

Secure File Transfer Protocol User Guide

BIGPOND ONLINE STORAGE USER GUIDE Issue August 2005

Quick Start Guide v4.0 Client Outlook Connection

UltraSite32 Network Installation Guidelines

Campus VPN. Version 1.0 September 22, 2008

Extending Remote Desktop for Large Installations. Distributed Package Installs

Getting the most out of your new Aalto workstation An Aalto IT guide for personnel migrating to the new Aalto workstation environment

How to Tunnel Remote Desktop Through SSH on a Windows Computer

Upgrading MySQL from 32-bit to 64-bit

USERS GUIDE. How to acquire an Associate Digital Identity Certificates from the ica Identity Authority and Configure MAS

Egnyte Single Sign-On (SSO) Installation for Okta

CONNECTING TO DEPARTMENT OF COMPUTER SCIENCE SERVERS BOTH FROM ON AND OFF CAMPUS USING TUNNELING, PuTTY, AND VNC Client Utilities

SECURE MOBILE ACCESS MODULE USER GUIDE EFT 2013

DocumentMall PPDM Upload Link Version 1.0 User s Guide

Configuring for SFTP March 2013

Coillte IT has recently upgraded the Remote Access Solution to a new platform.

TECHNICAL NOTE. The following information is provided as a service to our users, customers, and distributors.

2X ApplicationServer & LoadBalancer Manual

AssetGen Desktop Professional Download and Installation Instructions

Getting started with 2c8 plugin for Microsoft Sharepoint Server 2010

User Guide Microsoft Exchange Remote Test Instructions

Installing the Virtual Desktop Application (MAC)

1. Navigate to Control Panel and click on User Accounts and Family Safety. 2. Click on User Accounts

OCS Client Installation - Quick Start Guide. Web Conferencing & Secure Instant Messaging via Microsoft Office Communications Server 2007

Cloud Server powered by Mac OS X. Getting Started Guide. Cloud Server. powered by Mac OS X. AKJZNAzsqknsxxkjnsjx Getting Started Guide Page 1

HOW TO SILENTLY INSTALL CLOUD LINK REMOTELY WITHOUT SUPERVISION

educ Office Remove & create new Outlook profile

client configuration guide. Business

SecureAware on IIS8 on Windows Server 2008/- 12 R2-64bit

How to Setup and Connect to an FTP Server Using FileZilla. Part I: Setting up the server

Global VPN Client Getting Started Guide

MultiSite Manager. User Guide

Transcription:

Setting up Kerberos, AFS, and Putty on Windows Vista/Windows 7 Note on 64-bit Windows systems: On 64-bit Windows systems you will need to install both 32-bit and 64-bit distributions of both Kerberos and AFS. Installing just 64-bit editions will not work properly. Installing Kerberos The recommended version of Kerberos for use with AFS 1.7+ is now Heimdal. 1) Download the appropriate installer from here: https://www.secure-endpoints.com/heimdal/ Note: For Kerberos + AFS on 64-bit Windows, download the combined 64-bit and 32-bit installer. 2) Run the installer that you downloaded: Note: You may encounter an open file security prompt depending on your system configuration.

Accept the license agreement: Leave the install options at default:

Finally, confirm that you wish to proceed Once installation has completed, click Finish: Note that the Heimdall installer does not include a user interface. You will need to download and install one as detailed below:

3) Download the Network Identity Manager installer from here: https://www.secure-endpoints.com/netidmgr/v2/ Note: For 64-bit installs, only download the 64-bit installer (non-sdk). 4) Run the installer that just downloaded: Accept the license agreement:

Select Typical install: Click Install to proceed: Finally, click Finish once the installer completes.

5) Run Network Identity Manager from the Start Menu: 6) Open the Network Identity Manager main window: Right click the Kerberos for Windows icon in the system tray (you may need to click the up or left arrow first) and click Show Network Identity Manager window. You may have to do this twice the first time:

7) Setup your account and obtain tickets for the first time Click the Obtain new credentials icon in the toolbar: Enter your DICE username in the Username box, and INF.ED.AC.UK (case sensitive) in the Realm box: The first time after you click Next the following window should appear. Tick the Proxiable and Make this the default identity boxes and click Next (do not click Finish ):

Enter your password in the Password box, then click Make this the default identity. Optionally, select Save password in My Keystore if you want the password stored on your machine: Finally, click Finish. You should see a status dialog for a few seconds. Note: If you have chosen to save your password, click Next instead, and follow the prompts to setup a keystore password to protect it. You ll then be returned to the main Network Identity Manager window where there should be a new entry indicating your credentials have been successfully validated and a Kerberos ticket obtained:

Installing PuTTY PuTTY can be used to remotely login to Informatics machines and servers from anywhere on the internet using SSH. Where possible, you should use Kerberos authentication instead of keyboardinteractive by setting up Putty to use your Kerberos credentials. 1) Download PuTTY or its automated installer: http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html The easiest option is to just save putty.exe on its own to a location of your choice, though there is also a Windows installer package. 2) Setup PuTTY to work with Kerberos: To start off, run the PuTTY executable, and then enter one of the following into the Host Name box. Put whatever you want the connection to be called in the Saved Sessions box, though we d recommend keeping it the same as the Host Name: student.ssh.inf.ed.ac.uk staff.ssh.inf.ed.ac.uk for taught students for staff and research students Leave the remaining options as-is for now.

From the Category menu on the left, select Data under Connection. If you are the only user of your machine, enter your DICE username in the Auto-login username box. If the user account on your machine is used by multiple people, it s best to leave this box blank. Again from the Category box, expand the SSH group, then the Auth group and finally select GSSAPI. In this window, tick the Allow GSSAPI credential delegation box.

Then, click Browse and select the gssapi32.dll of your Kerberos installation. On 32-bit systems this will normally be C:\Program Files\Heimdal\bin\gssapi32.dll. On 64-bit Windows, this file will normally be C:\Program Files (x86)\heimdal\bin\gssapi32.dll. Finally, select the User-specified GSSAPI DLL entry in the Preference order box and then click Up twice so it is top of the list: If you wish to use X11 forwarding (i.e. running graphical X window applications remotely), navigate down to the X11 entry under SSH, select the Enable X11 forwarding checkbox and enter localhost:0 for X display location. You will need to have an X11 server installed on your local computer first.

If you wish to use port-forwarding and tunnelling, e.g. for remote VNC access, navigate to the Tunnels page under SSH and enter the ports as required (the following is only an example): Finally, navigate back to the Session page and click Save:

From now on, when you start PuTTY, you can just double-click your connection entry in the Saved Sessions list to automatically connect, authenticate, and open a terminal session, without you having to type your username and password each time: Note that if you haven t already authenticated via Kerberos you ll be asked to enter your Kerberos credentials the first time you run PuTTY after you start your computer.