[31840] in Kerberos
Decrypt integrity check failed
daemon@ATHENA.MIT.EDU (miten)
Sun Jan 3 18:24:13 2010
From: miten <indiamiten@gmail.com>
Date: Sat, 2 Jan 2010 10:14:30 -0800 (PST)
Message-ID: <892f95f4-183b-4c63-81d0-557d1716847c@j5g2000yqm.googlegroups.com>
Mime-Version: 1.0
X-Complaints-To: groups-abuse@google.com
Complaints-To: groups-abuse@google.com
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Hi,
I am trying to setup kerberos on laptop. Below is dump of few items
that shows that shows that I have principal mitenm and host setup. I
am able to kinit as admin but for mitenm I get errror.
output of klist:
--------------------
4 host/
opensolarismiten.mehta.ghatkopar.mumbai.mh.in.com@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM
(AES-256 CTS mode with 96-bit SHA-1 HMAC)
4 host/
opensolarismiten.mehta.ghatkopar.mumbai.mh.in.com@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM
(AES-128 CTS mode with 96-bit SHA-1 HMAC)
4 host/
opensolarismiten.mehta.ghatkopar.mumbai.mh.in.com@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM
(Triple DES cbc mode with HMAC/sha1)
4 host/
opensolarismiten.mehta.ghatkopar.mumbai.mh.in.com@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM
(ArcFour with HMAC/md5)
4 host/
opensolarismiten.mehta.ghatkopar.mumbai.mh.in.com@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM
(DES cbc mode with RSA-MD5)
5 mitenm@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM (AES-256 CTS mode with 96-
bit SHA-1 HMAC)
5 mitenm@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM (AES-128 CTS mode with 96-
bit SHA-1 HMAC)
5 mitenm@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM (Triple DES cbc mode with
HMAC/sha1)
5 mitenm@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM (ArcFour with HMAC/md5)
5 mitenm@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM (DES cbc mode with RSA-
MD5)
mitenm@opensolarismiten:/usr/lib/krb5# svcadm -v enable -s telnet
svc:/network/telnet:default enabled.
mitenm@opensolarismiten:/usr/lib/krb5# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM
Valid starting Expires Service principal
01/02/10 20:16:11 01/03/10 06:16:11 krbtgt/
MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM
renew until 01/09/10 20:16:11
error for kinit as mitenm:
----------------------------------
Jan 02 22:52:35 opensolarismiten krb5kdc[1158](info): AS_REQ (6 etypes
{18 17 16 23 3 1}) 192.168.1.3: NEEDED_PREAUTH:
mitenm@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM for krbtgt/
MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM,
Additional pre-authentication required
Jan 02 22:52:49 opensolarismiten krb5kdc[1158](info): preauth
(timestamp) verify failure: Decrypt integrity check failed
Jan 02 22:52:49 opensolarismiten krb5kdc[1158](info): AS_REQ (6 etypes
{18 17 16 23 3 1}) 192.168.1.3: PREAUTH_FAILED:
mitenm@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM for krbtgt/
MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM@MEHTA.GHATKOPAR.MUMBAI.MH.IN.COM,
Decrypt integrity check failed
~
Please advise.
Regards,
Miten.
imiten@yahoo.com
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos