HP CIFS Server and Kerberos

96
The only significant drawback to Wireshark usage is ensuring that it is resident on the customer
system. Wireshark binaries can be downloaded from:
The HP-UX Porting and Archive Center
o http://hpux.cs.utah.edu/hppd/hpux/Gtk/Applications/wireshark-1.1.1/
Includes 11iv1, 11iv2, 11iv3
www.software.hp.com Internet Express
o https://h20392.www2.hp.com/portal/swdepot/try.do?productNumber=HPUXIEXP
1123 (11iv2)
o https://h20392.www2.hp.com/portal/swdepot/try.do?productNumber=HPUXIEXP
1131 (11iv3)
o 11iv1 is only available from HP on the 0803 AR media
The Internet Express package is especially handy because it installs as a .depot file with swinstall.
The Wireshark User’s Guide is available at:
http://www.wireshark.org/download/docs/user-guide-us.pdf
For basic CIFS-Kerberos tracing, a simple trace and subsequent display filter will display the packet
exchanges that are interesting. Most cases will require tracing between the client and the CIFS
server. The numerous trace examples in Chapter 7 are simple IP address filters. Protocol filters are
also useful (simply “kerberos”, “smb”, or maybe “kerberos || smb”). Because there are many trace
screens already included in this paper, refer to those for filter examples.
8.1.8 Kerbtray
Kerbtray is a Microsoft Windows application that runs on the client, and displays the client ticket cache
along with details about the tickets that it holds. This data can be very useful for determining that the
client is receiving the correct ticket information from the KDC. Observe the examples below: