[22398] in Kerberos

home help back first fref pref prev next nref lref last post

Re: "key type not supported" and XP SP2 changes ?

daemon@ATHENA.MIT.EDU (Sam Hartman)
Tue Sep 7 18:57:37 2004

To: "Tim Alsop" <Tim.Alsop@cybersafe.ltd.uk>
From: Sam Hartman <hartmans@mit.edu>
Date: Tue, 07 Sep 2004 18:56:07 -0400
In-Reply-To: <0D8F2EFD3A10E24DAEEA48EA6DA07D30062184@postman-pat.csafe.local>
	(Tim Alsop's message of "Tue, 7 Sep 2004 22:47:25 +0100")
Message-ID: <tslhdq9sn7c.fsf@cz.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
cc: Jeffrey Altman <jaltman2@nyc.rr.com>
Errors-To: kerberos-bounces@mit.edu

>>>>> "Tim" == Tim Alsop <Tim.Alsop@cybersafe.ltd.uk> writes:

    Tim> Jeffrey, Sorry to be confusing. Our code is not requesting a
    Tim> tgt, but I know for a fact that setting AllowTGTSessionKey to
    Tim> 0 on XP SP2 (the default setting) causes our code to work as
    Tim> required, but setting it to 1 causes it to complain with "key
    Tim> type not supported". My explanation I have given so far has
    Tim> been based on my assumptions from this test - maybe wrongly,
    Tim> but I am trying to draw a conclusion and it seems likely to
    Tim> me that if the key is not exported we don't give an error
    Tim> because we don't see the RC4 key. 

Why don't you modify your code to map unsupported key types to the
same null key type you get when you try to look at the key and
AllowTGTSessionKey is set to 0?  I.E. emulate the behavior you desire.


--Sam
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post