Re: Bug in 1.5.1 KDC is session key selection
Andreas Haupt <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | DESY |
| Message-ID | <[email protected]> |
Hi Love, On Sun, 2012-01-08 at 14:57 +0000, Love Hörnquist Åstrand wrote: > this was probably fixed by > > https://github.com/heimdal/heimdal/commit/c757eb7fb04a9b0ca883ddb72c1bc75bf5d814f3 hmm, I'm not really sure. At least the (broken) klog.krb5 in the current OpenAFS version 1.6.0 is not able to get a token from a new Heimdal 1.5.2 server: [titus-vm8] ~ % k5log Password for [email protected]: klog: ticket contained unknown key version number Can't get your viceid So the error message did not change referring to a Heimdal 1.5.1 server and I assume it still uses a session key klog.krb5 doesn't understand. Am I right Heimdal won't ever behave again like in version 1.2.1 when talking to broken clients (that send an empty list of supported enctypes)? Cheers, Andreas -- | Andreas Haupt | E-Mail: [email protected] | DESY Zeuthen | WWW: http://www-zeuthen.desy.de/~ahaupt | Platanenallee 6 | Phone: +49/33762/7-7359 | D-15738 Zeuthen | Fax: +49/33762/7-7216