Re: Bug in 1.5.1 KDC is session key selection
Jeffrey Altman <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | Secure Endpoints Inc. |
| Message-ID | <[email protected]> |
On 1/18/2012 8:40 AM, Andreas Haupt wrote: > Hi Love, > > On Sun, 2012-01-08 at 14:57 +0000, Love Hörnquist Åstrand wrote: >> this was probably fixed by >> >> https://github.com/heimdal/heimdal/commit/c757eb7fb04a9b0ca883ddb72c1bc75bf5d814f3 > > hmm, I'm not really sure. At least the (broken) klog.krb5 in the current > OpenAFS version 1.6.0 is not able to get a token from a new Heimdal > 1.5.2 server: > > [titus-vm8] ~ % k5log > Password for [email protected]: > klog: ticket contained unknown key version number Can't get your viceid > > So the error message did not change referring to a Heimdal 1.5.1 server > and I assume it still uses a session key klog.krb5 doesn't understand. > > Am I right Heimdal won't ever behave again like in version 1.2.1 when > talking to broken clients (that send an empty list of supported > enctypes)? > > Cheers, > Andreas What Kerberos was klog.krb5 built against that the Kerberos library is sending an empty list of enctypes?
signature.asc
(application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (MingW32) iQEcBAEBAgAGBQJPF3eBAAoJENxm1CNJffh4k4gIAOj4M3H5gCP0XZQyfJzm820H cG5FnD5yRwislEgrhgWiLdWPcDNRmQjaZVdN5aJ7PlNyHF1xCp+/ao1vvCpViYsL ZN2qEsSVgD33xF39JeZgG84khl01jxmaJeHlBtnmnl6Vu6Y94fPgBMEHxxtsLGOG 3U5pE2rhWVf0QF1xJGGCPcbkF/UpwqMtjv17Iz9pzQnkc9Hk6kVYOYmihe1i3B+V ASzVgVl/4YFfa9JBWvAcjwbAjGfuk9uzrOa37+jKd9BoPGhH8nTP+P7Dbt+8h/oY SBbca4rnOKtNnIFhA3ritN2u1YlaUj1kS5c/0rd4d7fnC9UWbi+eOjaibp5Xdu0= =FUHi -----END PGP SIGNATURE-----