Re: Bug in 1.5.1 KDC is session key selection

Jeffrey Altman <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Organization Secure Endpoints Inc.
Message-ID <[email protected]>
On 1/18/2012 8:40 AM, Andreas Haupt wrote:
> Hi Love,
> 
> On Sun, 2012-01-08 at 14:57 +0000, Love Hörnquist Åstrand wrote:
>> this was probably fixed by 
>>
>> https://github.com/heimdal/heimdal/commit/c757eb7fb04a9b0ca883ddb72c1bc75bf5d814f3
> 
> hmm, I'm not really sure. At least the (broken) klog.krb5 in the current
> OpenAFS version 1.6.0 is not able to get a token from a new Heimdal
> 1.5.2 server:
> 
> [titus-vm8] ~ % k5log 
> Password for [email protected]: 
> klog: ticket contained unknown key version number Can't get your viceid
> 
> So the error message did not change referring to a Heimdal 1.5.1 server
> and I assume it still uses a session key klog.krb5 doesn't understand.
> 
> Am I right Heimdal won't ever behave again like in version 1.2.1 when
> talking to broken clients (that send an empty list of supported
> enctypes)?
> 
> Cheers,
> Andreas

What Kerberos was klog.krb5 built against that the Kerberos library is
sending an empty list of enctypes?
signature.asc (application/pgp-signature, 487 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)

iQEcBAEBAgAGBQJPF3eBAAoJENxm1CNJffh4k4gIAOj4M3H5gCP0XZQyfJzm820H
cG5FnD5yRwislEgrhgWiLdWPcDNRmQjaZVdN5aJ7PlNyHF1xCp+/ao1vvCpViYsL
ZN2qEsSVgD33xF39JeZgG84khl01jxmaJeHlBtnmnl6Vu6Y94fPgBMEHxxtsLGOG
3U5pE2rhWVf0QF1xJGGCPcbkF/UpwqMtjv17Iz9pzQnkc9Hk6kVYOYmihe1i3B+V
ASzVgVl/4YFfa9JBWvAcjwbAjGfuk9uzrOa37+jKd9BoPGhH8nTP+P7Dbt+8h/oY
SBbca4rnOKtNnIFhA3ritN2u1YlaUj1kS5c/0rd4d7fnC9UWbi+eOjaibp5Xdu0=
=FUHi
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.