Re: Bug in 1.5.1 KDC is session key selection

Andreas Haupt <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization DESY
Message-ID <[email protected]>
Hi Love,

On Sun, 2012-01-08 at 14:57 +0000, Love Hörnquist Åstrand wrote:
> this was probably fixed by 
> 
> https://github.com/heimdal/heimdal/commit/c757eb7fb04a9b0ca883ddb72c1bc75bf5d814f3

hmm, I'm not really sure. At least the (broken) klog.krb5 in the current
OpenAFS version 1.6.0 is not able to get a token from a new Heimdal
1.5.2 server:

[titus-vm8] ~ % k5log 
Password for [email protected]: 
klog: ticket contained unknown key version number Can't get your viceid

So the error message did not change referring to a Heimdal 1.5.1 server
and I assume it still uses a session key klog.krb5 doesn't understand.

Am I right Heimdal won't ever behave again like in version 1.2.1 when
talking to broken clients (that send an empty list of supported
enctypes)?

Cheers,
Andreas
-- 
| Andreas Haupt             | E-Mail: [email protected]
|  DESY Zeuthen             | WWW:    http://www-zeuthen.desy.de/~ahaupt
|  Platanenallee 6          | Phone:  +49/33762/7-7359
|  D-15738 Zeuthen          | Fax:    +49/33762/7-7216
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.