Re: Bug in 1.5.1 KDC is session key selection
Jeffrey Altman <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | Secure Endpoints Inc. |
| Message-ID | <[email protected]> |
On 10/14/2011 8:16 AM, Andreas Haupt wrote: > Hi Harald, Love, > > On Thu, 2011-10-13 at 16:02 +0200, Andreas Haupt wrote: >> On Thu, 2011-10-13 at 15:38 +0200, Harald Barth wrote: >>> There might be more than one bug lurking here. >> >> Maybe. From my point of view it looks like the 1.5.1 KDC sends out a >> slightly different reply now (in the encrypted parts of the ticket) >> which klog.krb5 doesn't understand. So this can be a bug in klog.krb5 >> (when its not compatible to some new features) or in the new Heimdal KDC >> (it sends out broken replies). Or it's even a configuration issue ... I >> don't know. > > This is what Jeffrey Altman wrote on the openafs-info mailing list: > > --- > Heimdal 1.5.1 should also be restricting the session key to one of the > encryption types that are known to the [email protected] principal. That is > also a bug and should be reported on the heimdal mailing list. > --- > > Love, can you confirm this? > > Cheers, > Andreas The bug exists only in the AS-REQ processing and not the TGS-REQ processing. The TGS-REQ is properly restricting the possible enc-type list. Jeffrey Altman
signature.asc
(application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (MingW32) iQEcBAEBAgAGBQJOmCyLAAoJENxm1CNJffh4I3gIAOoQ5+MZ47zaY7w1hsMfwVy3 HQQ1oK71M1/YLJILVgBa76iYIOpMCb7SCqtj3D6fgVK/YrbDHsbgjgVwWWw5To8Q m0f7bTx5P0KRmZL3h/OkVuMTGKLRhl1nGNIBtZl9k+j0nAXxTfLUi+PdKjrJNiYY LKfBA5Ob9lX39ktNMZec2NgpQognpYimVrUCsi9PR/zi9nTcTj0IYrvQdjEdBn5C xzHmvwbVns27NKACrCm6Hkd45cg0EYZ9E66EamSfwS2j+1HSuuy1s1pb+2H/QXsJ zALsyuHNEY6caAjsFfTxIR7+rfS5cGs0YzuAYLEkABrQ4qoX9qFTR7gPpDCABAc= =OwOh -----END PGP SIGNATURE-----