Bug in 1.5.1 KDC is session key selection (was: Heimdal KDC 1.5.1 as AFS KA-server)

Andreas Haupt <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization DESY
Message-ID <[email protected]>
Hi Harald, Love,

On Thu, 2011-10-13 at 16:02 +0200, Andreas Haupt wrote:
> On Thu, 2011-10-13 at 15:38 +0200, Harald Barth wrote:
> > There might be more than one bug lurking here.
> 
> Maybe. From my point of view it looks like the 1.5.1 KDC sends out a
> slightly different reply now (in the encrypted parts of the ticket)
> which klog.krb5 doesn't understand. So this can be a bug in klog.krb5
> (when its not compatible to some new features) or in the new Heimdal KDC
> (it sends out broken replies). Or it's even a configuration issue ... I
> don't know.

This is what Jeffrey Altman wrote on the openafs-info mailing list:

---
Heimdal 1.5.1 should also be restricting the session key to one of the
encryption types that are known to the [email protected] principal.  That is
also a bug and should be reported on the heimdal mailing list.
---

Love, can you confirm this?

Cheers,
Andreas
-- 
| Andreas Haupt             | E-Mail: [email protected]
|  DESY Zeuthen             | WWW:    http://www-zeuthen.desy.de/~ahaupt
|  Platanenallee 6          | Phone:  +49/33762/7-7359
|  D-15738 Zeuthen          | Fax:    +49/33762/7-7216
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.