[30810] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Using Smartcard with PK-INIT does not respond

daemon@ATHENA.MIT.EDU (Loren M. Lang)
Thu Mar 5 18:18:14 2009

From: "Loren M. Lang" <lorenl@alzatex.com>
To: Kevin Coffman <kwcoffman@gmail.com>
In-Reply-To: <4d569c330903040916n44e5067cgc14fdfb34deae684@mail.gmail.com>
Date: Wed, 04 Mar 2009 16:40:12 -0800
Message-Id: <1236213612.13692.4599.camel@ruth.aloha.tallye.com>
Mime-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: multipart/mixed; boundary="===============2091292739=="
Errors-To: kerberos-bounces@mit.edu


--===============2091292739==
Content-Type: multipart/signed; micalg="sha1";
	protocol="application/x-pkcs7-signature";
	boundary="=-TnGIzxV/GrHx/mFORa26"


--=-TnGIzxV/GrHx/mFORa26
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Wed, 2009-03-04 at 12:16 -0500, Kevin Coffman wrote:
> On Wed, Mar 4, 2009 at 10:24 AM, Loren M. Lang <lorenl@alzatex.com> wrote=
:
> > On Wed, 2009-03-04 at 06:33 -0800, Loren M. Lang wrote:
> >> >
> >> > > This symlinks point to missing certificates that have nothing to d=
o with
> >> > > the pki infrastructure I am using, but once I moved the symlinks o=
ut of
> >> > > the way, kinit continued and finally sent out an AS-REQ with the P=
K-INIT
> >> > > preauth data, but received no response.  According to Wireshark,
> >> > > following the initial AS-REQ with no preauth, the server responds =
with a
> >> > > NEEDED_PREAUTH error listing six preauth types including PA-PK-AS-=
REQ
> >> > > and PA-PK-AS-REP.  The client then sends a single IP fragment resp=
onse.
> >> > > The fragment has a payload of 1480 bytes with flag more fragments,=
 but
> >> > > no further fragments are sent.  I have no firewall rules installed=
 and
> >> > > am at a loss as to why there are no more fragments.
> >> >
> >> > I'm not sure what might be happening here.  This would just be a
> >> > work-around, but is it possible for you to try using TCP rather than
> >> > UDP?
> >>
> >> I enabled TCP support on my KDCs and netstat confirms they are listeni=
ng
> >> on them.  I tried setting udp_preference_limit to 1480, 1000, and 50,
> >> but kinit never uses TCP.  I put udp_preference_limit both at the very
> >> beginning and very end of my libdefaults section in krb5.conf and even
> >> tried using copy/paste to double check that I typed it correctly.
> >
> > Never mind, I only had UDP SRV records published, now it's using TCP.
> > The error I am getting now is KRB5KRB_ERR_GENERIC with e-data:
> > KDC_RETURN_PADATA.  The kdc log shows this relevant error:
> >
> > Mar 04 07:04:13 server krb5kdc[18148](info): AS_REQ (7 etypes {18 17 16
> > 23 1 3 2}) 192.168.1.237: KDC_RETURN_PADATA: user@EXAMPLE.COM for
> > krbtgt/EXAMPLE.COM@EXAMPLE.COM, Cannot allocate memory
> >
> > There is no memory crunch on the server.
>=20
> After a quick glance at the code, I don't see where ENOMEM is returned
> in cases where it wasn't an allocation error.  If you have output from
> -DDEBUG, that might give us a clue of the problem.

After running the server with -DDEBUG, the answer became clear, it could
not find the intermediate certificates either.  I setup pkinit_pool and
now I can log in with my smartcard.  The error message that was
producing in the log files was out of memory, but the debug output did
mention that it could not find a local issuer.  The pkinit_identity file
I am using I produced similar to the certificates I use for other
services such as Apache and Sendmail.  It contains the end-server
certificate followed by intermediates with the root CA certificate at
the bottom.  I have found that the easiest way to deal with
intermediates, but I guess KDC only looks at the first certificate.

>=20
> K.C.
>=20
--=20
Loren M. Lang
lorenl@alzatex.com
http://www.alzatex.com/


Public Key: ftp://ftp.tallye.com/pub/lorenl_pubkey.asc
Fingerprint: 10A0 7AE2 DAF5 4780 888A  3FA4 DCEE BB39 7654 DE5B

--=-TnGIzxV/GrHx/mFORa26
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Disposition: attachment; filename="smime.p7s"
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIZ0jCCBVcw
ggQ/oAMCAQICAQEwDQYJKoZIhvcNAQEFBQAwgYoxEzARBgoJkiaJk/IsZAEZFgNjb20xFjAUBgoJ
kiaJk/IsZAEZFgZ0YWxseWUxFjAUBgNVBAoMDUFsemF0ZXgsIEluYy4xFTATBgNVBAsMDENlcnRp
ZmljYXRlczEsMCoGA1UEAwwjQWx6YXRleCBVc2VycyBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcN
MDkwMzAzMjEwNjM4WhcNMTAwMzAzMjEwNjM4WjCBiDETMBEGCgmSJomT8ixkARkWA2NvbTEWMBQG
CgmSJomT8ixkARkWBnRhbGx5ZTEWMBQGA1UECgwNQWx6YXRleCwgSW5jLjEPMA0GA1UECwwGUGVv
cGxlMRYwFAYDVQQDDA1Mb3JlbiBNLiBMYW5nMRgwFgYKCZImiZPyLGQBAQwIc3R0bmczNTkwggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCtcOdQVV/H5exBjxMWJvYI0/ET0+7qDhiVFg6V
3nskL85lN8Yy5X7ZHKYiUIsFaAv4e+wzlSAerJxL5FMwW1KwFeDNyUseiarkNXifbCcOsEDu649V
4dP5pUi9R5OHRsFBqrAx5fe4AgIsNRGy+IAQ3CBN3Afn5RSbZkptz4jwE4ocBGCxWOVZYvmnrXXY
MbJkr7S5BDoBa15hJgZCD++jF8VEjmX0wS/WgngT5BX22p0dTmW0VVo9XPx79gTrSSqCQMJSWim6
L5WuqzflYQYGuFEjYxWmjjzYm24obA+XPOBkYxppnbc1QFeVCHjzYfd9CYGvTET166dytl6HKF8B
AgMBAAGjggHGMIIBwjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSr/6hpXUG3zum+8EVDIdPqppot
hzAfBgNVHSMEGDAWgBToL3pYj/2hGhatKthu4+wFjk2EmzA8BgNVHRIENTAzgQ1jYUB0YWxseWUu
Y29thiJodHRwOi8vd3d3LnRhbGx5ZS5jb20vY2VydHMvdXNlcnMvMDkGA1UdHwQyMDAwLqAsoCqG
KGh0dHA6Ly93d3cudGFsbHllLmNvbS9jZXJ0cy91c2Vycy9DQS5jcmwwXwYIKwYBBQUHAQEEUzBR
MDQGCCsGAQUFBzAChihodHRwOi8vd3d3LnRhbGx5ZS5jb20vY2VydHMvdXNlcnMvQ0EuY3J0MBkG
CCsGAQUFBzACgQ1jYUB0YWxseWUuY29tMAsGA1UdDwQEAwIFoDAmBgNVHSUEHzAdBggrBgEFBQcD
AgYIKwYBBQUHAwQGBysGAQUCAwQwEQYJYIZIAYb4QgEBBAQDAgWgMFAGA1UdEQRJMEeBEmxvcmVu
bEBhbHphdGV4LmNvbaAxBgYrBgEFAgKgJzAloAwbClRBTExZRS5DT02hFTAToAMCAQGhDDAKGwhz
dHRuZzM1OTANBgkqhkiG9w0BAQUFAAOCAQEAARlyZLBb1QBXc6Xqy74L/MtM+ewS9VfVROKO3up8
NF9wGyEUmj9SXOPzu5y8SxSGAuYua4HNWdCjJYjHtYdsfJO7poNvyWBwhj4MrWEseLhtIFIMs0a+
2rLss+NY2YocRz5xKkkdE6V+9rEnWMwDFASc7fz77wdjWyWzH4RC63CimSzO+AanCsUTArGnX0HW
a1tC58V7OYj1xREht8CIY/JU9TWbM80gN4jyN/2YKERFW4lGQs54LOnrkgs+4Mh9PfpnWIPSD4Ri
BK3AkIGS5NvpQfFUGKSyBJNBcXNCRDGnxd5vG4i1GvHdd45medrzKBqmmHFw/UZZ/WpmlcvlDDCC
BVcwggQ/oAMCAQICAQEwDQYJKoZIhvcNAQEFBQAwgYoxEzARBgoJkiaJk/IsZAEZFgNjb20xFjAU
BgoJkiaJk/IsZAEZFgZ0YWxseWUxFjAUBgNVBAoMDUFsemF0ZXgsIEluYy4xFTATBgNVBAsMDENl
cnRpZmljYXRlczEsMCoGA1UEAwwjQWx6YXRleCBVc2VycyBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkw
HhcNMDkwMzAzMjEwNjM4WhcNMTAwMzAzMjEwNjM4WjCBiDETMBEGCgmSJomT8ixkARkWA2NvbTEW
MBQGCgmSJomT8ixkARkWBnRhbGx5ZTEWMBQGA1UECgwNQWx6YXRleCwgSW5jLjEPMA0GA1UECwwG
UGVvcGxlMRYwFAYDVQQDDA1Mb3JlbiBNLiBMYW5nMRgwFgYKCZImiZPyLGQBAQwIc3R0bmczNTkw
ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCtcOdQVV/H5exBjxMWJvYI0/ET0+7qDhiV
Fg6V3nskL85lN8Yy5X7ZHKYiUIsFaAv4e+wzlSAerJxL5FMwW1KwFeDNyUseiarkNXifbCcOsEDu
649V4dP5pUi9R5OHRsFBqrAx5fe4AgIsNRGy+IAQ3CBN3Afn5RSbZkptz4jwE4ocBGCxWOVZYvmn
rXXYMbJkr7S5BDoBa15hJgZCD++jF8VEjmX0wS/WgngT5BX22p0dTmW0VVo9XPx79gTrSSqCQMJS
Wim6L5WuqzflYQYGuFEjYxWmjjzYm24obA+XPOBkYxppnbc1QFeVCHjzYfd9CYGvTET166dytl6H
KF8BAgMBAAGjggHGMIIBwjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSr/6hpXUG3zum+8EVDIdPq
ppothzAfBgNVHSMEGDAWgBToL3pYj/2hGhatKthu4+wFjk2EmzA8BgNVHRIENTAzgQ1jYUB0YWxs
eWUuY29thiJodHRwOi8vd3d3LnRhbGx5ZS5jb20vY2VydHMvdXNlcnMvMDkGA1UdHwQyMDAwLqAs
oCqGKGh0dHA6Ly93d3cudGFsbHllLmNvbS9jZXJ0cy91c2Vycy9DQS5jcmwwXwYIKwYBBQUHAQEE
UzBRMDQGCCsGAQUFBzAChihodHRwOi8vd3d3LnRhbGx5ZS5jb20vY2VydHMvdXNlcnMvQ0EuY3J0
MBkGCCsGAQUFBzACgQ1jYUB0YWxseWUuY29tMAsGA1UdDwQEAwIFoDAmBgNVHSUEHzAdBggrBgEF
BQcDAgYIKwYBBQUHAwQGBysGAQUCAwQwEQYJYIZIAYb4QgEBBAQDAgWgMFAGA1UdEQRJMEeBEmxv
cmVubEBhbHphdGV4LmNvbaAxBgYrBgEFAgKgJzAloAwbClRBTExZRS5DT02hFTAToAMCAQGhDDAK
GwhzdHRuZzM1OTANBgkqhkiG9w0BAQUFAAOCAQEAARlyZLBb1QBXc6Xqy74L/MtM+ewS9VfVROKO
3up8NF9wGyEUmj9SXOPzu5y8SxSGAuYua4HNWdCjJYjHtYdsfJO7poNvyWBwhj4MrWEseLhtIFIM
s0a+2rLss+NY2YocRz5xKkkdE6V+9rEnWMwDFASc7fz77wdjWyWzH4RC63CimSzO+AanCsUTArGn
X0HWa1tC58V7OYj1xREht8CIY/JU9TWbM80gN4jyN/2YKERFW4lGQs54LOnrkgs+4Mh9PfpnWIPS
D4RiBK3AkIGS5NvpQfFUGKSyBJNBcXNCRDGnxd5vG4i1GvHdd45medrzKBqmmHFw/UZZ/Wpmlcvl
DDCCBwkwggXxoAMCAQICAQswDQYJKoZIhvcNAQEFBQAwgYQxEzARBgoJkiaJk/IsZAEZFgNjb20x
FjAUBgoJkiaJk/IsZAEZFgZ0YWxseWUxFjAUBgNVBAoMDUFsemF0ZXgsIEluYy4xFTATBgNVBAsM
DENlcnRpZmljYXRlczEmMCQGA1UEAwwdQWx6YXRleCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcN
MDkwMzAzMjAyOTEzWhcNMTEwMzAzMjAyOTEzWjCBijETMBEGCgmSJomT8ixkARkWA2NvbTEWMBQG
CgmSJomT8ixkARkWBnRhbGx5ZTEWMBQGA1UECgwNQWx6YXRleCwgSW5jLjEVMBMGA1UECwwMQ2Vy
dGlmaWNhdGVzMSwwKgYDVQQDDCNBbHphdGV4IFVzZXJzIENlcnRpZmljYXRlIEF1dGhvcml0eTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALM4Gi1oIayl5PJSQPhTnc6Ko75/fGmsD5pl
ObNxCWzVozn9P1AVNKz5MHDswwSMlIy1RnVdJX4baNPTm69vEiAjrQrYHIBPSVQjzeRRFK6K8NAJ
YWCcGWiQYG03WlCBJcu5UusaAaOoKNrAGylf0mrItXv241i8X8+shcs4bexd/4Ez0TZoV4xuhDbf
58z/R50wu8t5wX2TheIryrc1kWWNrlc0Cr3V/YxNs7sVz5o4W0HYz42EU+xrZpra0D9+aVRxQ7Wf
UrX27vfN6E1wMGhWKUY8iGqbxr8wyj0Kl6Tru1yV9aqKisgUE2QkiDIn/a44rQ8jcsOXQY83n5hq
oMcCAwEAAaOCA3wwggN4MBIGA1UdEwEB/wQIMAYBAf8CAQAwHwYDVR0jBBgwFoAUUZag4M0uur28
nCtCAjyZgpkBrgEwNgYDVR0SBC8wLYENY2FAdGFsbHllLmNvbYYcaHR0cDovL3d3dy50YWxseWUu
Y29tL2NlcnRzLzAzBgNVHR8ELDAqMCigJqAkhiJodHRwOi8vd3d3LnRhbGx5ZS5jb20vY2VydHMv
Q0EuY3JsMH4GCCsGAQUFBwEBBHIwcDAjBggrBgEFBQcwAYYXaHR0cDovL29jc3AudGFsbHllLmNv
bS8wLgYIKwYBBQUHMAKGImh0dHA6Ly93d3cudGFsbHllLmNvbS9jZXJ0cy9DQS5jcnQwGQYIKwYB
BQUHMAKBDWNhQHRhbGx5ZS5jb20wMQYJYIZIAYb4QgEEBCQWImh0dHA6Ly93d3cudGFsbHllLmNv
bS9jZXJ0cy9DQS5jcmwwMQYJYIZIAYb4QgEDBCQWImh0dHA6Ly93d3cudGFsbHllLmNvbS9jZXJ0
cy9DQS5jcmwwHQYDVR0OBBYEFOgveliP/aEaFq0q2G7j7AWOTYSbMA4GA1UdDwEB/wQEAwIBBjAm
BgNVHSUEHzAdBggrBgEFBQcDAgYIKwYBBQUHAwQGBysGAQUCAwQwEQYJYIZIAYb4QgEBBAQDAgEG
MDoGCWCGSAGG+EIBDQQtFitBbHphdGV4LCBJbmMuIC0gVXNlcnMgQ2VydGlmaWNhdGUgQXV0aG9y
aXR5MDgGCWCGSAGG+EIBCAQrFilodHRwOi8vd3d3LnRhbGx5ZS5jb20vY2VydHMvdXNlcnMvcG9s
aWN5LzCBzwYDVR0gBIHHMIHEMIHBBgRVHSAAMIG4MDUGCCsGAQUFBwIBFilodHRwOi8vd3d3LnRh
bGx5ZS5jb20vY2VydHMvdXNlcnMvcG9saWN5LzB/BggrBgEFBQcCAjBzMBQWDUFsemF0ZXgsIElu
Yy4wAwIBBBpbVGhpcyBjZXJ0aWZpY2F0ZSBpcyB0byBiZSB1c2VkIG9ubHkgZm9yIHNpZ25pbmcg
Y2VydGlmaWNhdGVzIGZvciBlbmQgdXNlcnMgYXQgQWx6YXRleCwgSW5jLjA8BgNVHREENTAzgQ1j
YUB0YWxseWUuY29thiJodHRwOi8vd3d3LnRhbGx5ZS5jb20vY2VydHMvdXNlcnMvMA0GCSqGSIb3
DQEBBQUAA4IBAQC4hmaLISF/M8EbtslWOSyNi84v37+gl1tJS4oXnwsbTc7lMRLYbsvagxR7rgU1
lLSoVSV3JIDuHBjVUHnyqWwERhv7nFg4Pt6UU40rRp0eqc2O5/zk/dIkW4KW7uHog4wP46lufF1H
UfkdAHNaYVP4dQr55LmAhopv7MzSwf3nqLddDVxKQIUGCqMaLuBxKppgzmZOuij9V8Yt4T7tBvHC
EjD3aJRtEQlZsLGlZE+9yNtbWhZ7I+5wgUirWlWncL1P43GA3fXpz7DSMElh+K2s04VNd4C4+1v1
O+ic6GpHnxj/Y8H2cy/R4rv9mgIVmiJOdVAI8oNZnITVKGgcDu76MIIICzCCBfOgAwIBAgIBBjAN
BgkqhkiG9w0BAQUFADCBrzELMAkGA1UEBhMCVVMxDzANBgNVBAgTBk9yZWdvbjEOMAwGA1UEBxMF
QWxvaGExFDASBgNVBAoTC05vcnRoIFdpbmRzMRUwEwYDVQQLEwxDZXJ0aWZpY2F0ZXMxLzAtBgNV
BAMTJk5vcnRoIFdpbmRzIFJvb3QgQ2VydGlmaWNhdGUgQXV0aG9yaXR5MSEwHwYJKoZIhvcNAQkB
FhJjYUBub3J0aC13aW5kcy5vcmcwHhcNMDgwNzIzMDkwMTA2WhcNMTMwMTA4MDkwMTA2WjCBhDET
MBEGCgmSJomT8ixkARkWA2NvbTEWMBQGCgmSJomT8ixkARkWBnRhbGx5ZTEWMBQGA1UECgwNQWx6
YXRleCwgSW5jLjEVMBMGA1UECwwMQ2VydGlmaWNhdGVzMSYwJAYDVQQDDB1BbHphdGV4IENlcnRp
ZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMfRSGcjUPK9
JGNt9Zq5+/BHlKOKvi3FssF7I//6BdOr0L/rZmlHI045Sx6bY39YDyhRl0Z0PVMt6nn9QUxDh2rg
XvtuX8kzVl9fl7v/qspUA/mT7pzHmHaHrDhqZBciGhWl6xNZh8aL3QQzHte8NQgZt/BzcOiqLTtx
e/+ldabVzbcmH20jPCSfQtlDaRWTNl4+AoodpKCX4ulFWU5veTWweR3OV5qtfiCZrCpNJb6b4BVk
2tyYGd1sf7ZH4PZ6oo8Vwknr5P9sd3UxfQxcdpPU4L9A4s9KGRGk+pgA9gfpE8r/R+gPJ9WVZ2O3
QeNK6r5MwgszJSUCvyRivh9Bvo8CAwEAAaOCA1kwggNVMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0O
BBYEFFGWoODNLrq9vJwrQgI8mYKZAa4BMB8GA1UdIwQYMBaAFP6C3OGU9nu9hPPt97vwV1VqIAlb
MEAGA1UdEgQ5MDeBEmNhQG5vcnRoLXdpbmRzLm9yZ4YhaHR0cDovL3d3dy5ub3J0aC13aW5kcy5v
cmcvY2VydHMvMDgGA1UdHwQxMC8wLaAroCmGJ2h0dHA6Ly93d3cubm9ydGgtd2luZHMub3JnL2Nl
cnRzL0NBLmNybDA4BggrBgEFBQcBAQQsMCowKAYIKwYBBQUHMAGGHGh0dHA6Ly9vY3NwLm5vcnRo
LXdpbmRzLm9yZy8wDgYDVR0PAQH/BAQDAgEGMBEGCWCGSAGG+EIBAQQEAwIABzA0BglghkgBhvhC
AQ0EJxYlQWx6YXRleCwgSW5jLiAtIENlcnRpZmljYXRlIEF1dGhvcml0eTAyBglghkgBhvhCAQgE
JRYjaHR0cDovL3d3dy50YWxseWUuY29tL2NlcnRzL3BvbGljeS8wNgYDVR0RBC8wLYENY2FAdGFs
bHllLmNvbYYcaHR0cDovL3d3dy50YWxseWUuY29tL2NlcnRzLzCCATAGA1UdIASCAScwggEjMIIB
HwYEVR0gADCCARUwLwYIKwYBBQUHAgEWI2h0dHA6Ly93d3cudGFsbHllLmNvbS9jZXJ0cy9wb2xp
Y3kvMIHhBggrBgEFBQcCAjCB1DAUGg1BbHphdGV4LCBJbmMuMAMCAQEagbtUaGlzIGNlcnRpZmlj
YXRlIGlzIHRvIGJlIHVzZWQgb25seSBmb3Igc2lnbmluZyBjZXJ0aWZpY2F0ZXMgYW5kIENSTHMg
cGVydGFpbmluZyB0byBTU0wvVExTIHNlcnZpY2VzIGZvciBBbHphdGV4LCBJbmMuLCBpZGVudGlm
aW5nIEFsemF0ZXggZW1wbG95ZWVzLCBhbmQgc2ltaWxhciBBbHphdGV4IHJlbGF0ZWQgc2VyaXZj
ZXMuMFMGCCsGAQUFBwELBEcwRTAoBggrBgEFBQcwBYYcaHR0cDovL3d3dy50YWxseWUuY29tL2Nl
cnRzLzAZBggrBgEFBQcwBYENY2FAdGFsbHllLmNvbTANBgkqhkiG9w0BAQUFAAOCAgEAnt2wRYkc
esB9f8oeEpo9gwAs1xpIXlRd8g2ihDJF24AuPHICsU6SjNyaNvtEJFuxAtJ92LYTeePh7lpIIGUw
FlVPq2POC6sSScrqBjnt6NcJnGZBs5Dz1dnyuOA2uOzKWf2tblVdIJTDcJITWcARo5gbzc7GAgs4
IK2CE7PMo8Wi1KbvvLB6yRf/qDRMEAr1sY6TZ/6l4Wz6L5nShg6mXkEJUhHJ041BF/HEfthtGpR/
loG+XkR9ZAh4jub6MuZ018mr5DjjI0IaupfZKH1feSDhOpKPPVm+H4fMH8wbIjePMW6qhZQrxk9w
vik3IIqCH+V6dEitEj3DEM4WWDYGSA1zwxPf6I4u3nw2NvinKMhzP8H9nRKQrRZ+YlGrqQxx0PYB
VRzsFbL49kwfmXpav6dSa/gLgcVsBQzRyuI3K2/ihc9qTn9QEsarB6U0SSq0B4rC9uL8pTwg7pfN
3Vg9eQ+7TMYj4KUYNk3iEJuR7jdK5vKvcItosq9lwTCkNvqTdrA4btvDFHZrJFlcPhxCyYvJRL3l
jj+7Q892eNl9NMDTgFrc/tWYNIsYZwC49wU6CjEG7nnFj9x6NKQy+dPlvp1JBM1p07Y1wyK/V9QZ
aZTRxRNorGzacQlG7jdUoHl0IrEpSWoXpGvfwhEmJDOZvpUBKC4TcdZ3F5wCfW9vJ6gxggNjMIID
XwIBATCBkDCBijETMBEGCgmSJomT8ixkARkWA2NvbTEWMBQGCgmSJomT8ixkARkWBnRhbGx5ZTEW
MBQGA1UECgwNQWx6YXRleCwgSW5jLjEVMBMGA1UECwwMQ2VydGlmaWNhdGVzMSwwKgYDVQQDDCNB
bHphdGV4IFVzZXJzIENlcnRpZmljYXRlIEF1dGhvcml0eQIBATAJBgUrDgMCGgUAoIIBpzAYBgkq
hkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0wOTAzMDUwMDQwMTFaMCMGCSqG
SIb3DQEJBDEWBBTHOfEgQRi2LWVQeB19asc1BEkIMzCBoQYJKwYBBAGCNxAEMYGTMIGQMIGKMRMw
EQYKCZImiZPyLGQBGRYDY29tMRYwFAYKCZImiZPyLGQBGRYGdGFsbHllMRYwFAYDVQQKDA1BbHph
dGV4LCBJbmMuMRUwEwYDVQQLDAxDZXJ0aWZpY2F0ZXMxLDAqBgNVBAMMI0FsemF0ZXggVXNlcnMg
Q2VydGlmaWNhdGUgQXV0aG9yaXR5AgEBMIGjBgsqhkiG9w0BCRACCzGBk6CBkDCBijETMBEGCgmS
JomT8ixkARkWA2NvbTEWMBQGCgmSJomT8ixkARkWBnRhbGx5ZTEWMBQGA1UECgwNQWx6YXRleCwg
SW5jLjEVMBMGA1UECwwMQ2VydGlmaWNhdGVzMSwwKgYDVQQDDCNBbHphdGV4IFVzZXJzIENlcnRp
ZmljYXRlIEF1dGhvcml0eQIBATANBgkqhkiG9w0BAQEFAASCAQBOndxqUxvtk4+pfYLZ06ZfWCq1
0PBZK0CmAOvTygj9QbWPgGOrlJYr6P8LFSloSg2wXqUMAw7EKoEtQS+/2znzEiaY6G+sf13aAn8V
f6FHEg0WIlmE8HNLTu0KtJgUYM16bNnyrhKS9478TWiB9tv9HH64hiFwbDOfa04o5OeMEwTqiqrK
UvHpPySFjxFyN1ZKzDQGTtNtEZSuC8JCtWF8s1bCPn9h2fzBl5VTmhzltc+DgbBvQA2JYQTV3vcq
GjxgBCjS+gHcQQ/ROzkKgt2LZ8dG5FKFKZ86C3rlqKR7qS0TaVwMX8P+eWz+waK1aKjhLyoRDDMO
HdCfvqUIFqQgAAAAAAAA


--=-TnGIzxV/GrHx/mFORa26--


--===============2091292739==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============2091292739==--


home help back first fref pref prev next nref lref last post