[23009] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Preauth and ticket forwarding

daemon@ATHENA.MIT.EDU (Rachel Elizabeth Dillon)
Tue Dec 7 16:33:55 2004

Date: Tue, 7 Dec 2004 16:33:06 -0500
From: Rachel Elizabeth Dillon <red@mit.edu>
To: Donn Cave <donn@u.washington.edu>
Message-ID: <20041207213306.GV290@yiff.mit.edu>
Mime-Version: 1.0
In-Reply-To: <donn-9AF829.12532507122004@gnus01.u.washington.edu>
cc: kerberos@mit.edu
Content-Type: multipart/mixed; boundary="===============13874134859941289=="
Errors-To: kerberos-bounces@mit.edu


--===============13874134859941289==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="h0EypPxsCPvv0kw1"
Content-Disposition: inline


--h0EypPxsCPvv0kw1
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Tue, Dec 07, 2004 at 12:53:25PM -0800, Donn Cave wrote:
> In case it may help, you can find more detail about the
> preauthentication failure in the syslog output from the KDC.
> The error message can be a little misleading - I believe
> "No such file or directory" really means that the key was
> wrong.  Other errors are "no valid preauth type", which
> I think may commonly be a Microsoft issue, and "Clock skew
> too great."  These messages appear on a separate line, so
> you have to locate the failure event in the log and then
> look for diagnostic messages on the line before.

See, I would expect that, but all I get is this for multiple=20
login attempts:

Dec 07 13:12:45 kerberos-1 krb5kdc[1163](info): AS_REQ (7 etypes {3 1 2 16 =
8 23 0}) 10.1.16.253: NEEDED_PREAUTH: ptadmin
@IC.COM for krbtgt/IC.COM@IC.COM, Additional pre-authentication required
Dec 07 13:13:16 kerberos-1 krb5kdc[1163](info): AS_REQ (7 etypes {3 1 2 16 =
8 23 0}) 10.1.16.253: NEEDED_PREAUTH: ptadmin
@IC.COM for krbtgt/IC.COM@IC.COM, Additional pre-authentication required
Dec 07 13:14:03 kerberos-1 krb5kdc[1163](info): AS_REQ (7 etypes {3 1 2 16 =
8 23 0}) 10.1.16.253: NEEDED_PREAUTH: ptadmin
@IC.COM for krbtgt/IC.COM@IC.COM, Additional pre-authentication required
Dec 07 13:15:06 kerberos-1 krb5kdc[1163](info): AS_REQ (7 etypes {3 1 2 16 =
8 23 0}) 10.1.16.253: NEEDED_PREAUTH: ptadmin
@IC.COM for krbtgt/IC.COM@IC.COM, Additional pre-authentication required

And this is the same message I get with a successful kinit from
elsewhere in the system:

Dec 07 11:43:34 kerberos-1 krb5kdc[1163](info): AS_REQ (7 etypes {18 17 16 =
23 1 3 2}) 10.1.16.234: NEEDED_PREAUTH: ptadm
in@IC.COM for krbtgt/IC.COM@IC.COM, Additional pre-authentication required
Dec 07 11:43:36 kerberos-1 krb5kdc[1163](info): AS_REQ (7 etypes {18 17 16 =
23 1 3 2}) 10.1.16.234: ISSUE: authtime 11024
48616, etypes {rep=3D16 tkt=3D16 ses=3D16}, ptadmin@IC.COM for krbtgt/IC.CO=
M@IC.COM

Thanks for the suggestion, though. I looked at some other log files but
I don't think the KDC is writing anywhere else; these lines are coming
=66rom /var/krb5/kdc.log, as specified in /etc/krb5.conf.

-r.

--h0EypPxsCPvv0kw1
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBtiGSrAG/UVUP/b0RAtgyAKDEgAwwrrC8z/d64aQLRzWNtMdSsgCfVQU/
C3UEw50PRC2QBT4YY6CFb+I=
=n+JI
-----END PGP SIGNATURE-----

--h0EypPxsCPvv0kw1--

--===============13874134859941289==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============13874134859941289==--

home help back first fref pref prev next nref lref last post