[37206] in Kerberos

home help back first fref pref prev next nref lref last post

Re: [EXTERNAL] Re: Heimdahl Kerberos on MacOSX 10.9.5 using pkinit

daemon@ATHENA.MIT.EDU (Greg Hudson)
Tue Aug 25 10:41:39 2015

Message-ID: <55DC7E95.6080307@mit.edu>
Date: Tue, 25 Aug 2015 10:41:25 -0400
From: Greg Hudson <ghudson@mit.edu>
MIME-Version: 1.0
To: Glenn Machin <gmachin@sandia.gov>
In-Reply-To: <55DBF40F.3080003@sandia.gov>
Cc: "<kerberos@mit.edu>" <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On 08/25/2015 12:50 AM, Glenn Machin wrote:
> Looks like it is an openssl issue, apparently fixed in version 1.0.1f
> .   Seems I asked a similar question then and found this on the
> krb5-bugs list -
> http://mailman.mit.edu/pipermail/krb5-bugs/2011-January/008510.html

Thanks for finding this; I remembered that too, but couldn't find the
details.

After I sent my last response, I was able to produce the "wrong tag"
error with your packet by disabling the use of CMS functions and forcing
the use of PKCS7 functions instead.  But it doesn't quite match the
"nested asn1 error" you are seeing, so I'm not sure it's the same thing.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post