Bug in 1.5.1 KDC is session key selection (was: Heimdal KDC 1.5.1 as AFS KA-server)
Andreas Haupt <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | DESY |
| Message-ID | <[email protected]> |
Hi Harald, Love, On Thu, 2011-10-13 at 16:02 +0200, Andreas Haupt wrote: > On Thu, 2011-10-13 at 15:38 +0200, Harald Barth wrote: > > There might be more than one bug lurking here. > > Maybe. From my point of view it looks like the 1.5.1 KDC sends out a > slightly different reply now (in the encrypted parts of the ticket) > which klog.krb5 doesn't understand. So this can be a bug in klog.krb5 > (when its not compatible to some new features) or in the new Heimdal KDC > (it sends out broken replies). Or it's even a configuration issue ... I > don't know. This is what Jeffrey Altman wrote on the openafs-info mailing list: --- Heimdal 1.5.1 should also be restricting the session key to one of the encryption types that are known to the [email protected] principal. That is also a bug and should be reported on the heimdal mailing list. --- Love, can you confirm this? Cheers, Andreas -- | Andreas Haupt | E-Mail: [email protected] | DESY Zeuthen | WWW: http://www-zeuthen.desy.de/~ahaupt | Platanenallee 6 | Phone: +49/33762/7-7359 | D-15738 Zeuthen | Fax: +49/33762/7-7216