[32204] in Kerberos
Re: CANT_FIND_CLIENT_KEY
daemon@ATHENA.MIT.EDU (Russ Allbery)
Tue Mar 30 17:46:26 2010
From: Russ Allbery <rra@stanford.edu>
To: Matt Zagrabelny <mzagrabe@d.umn.edu>
In-Reply-To: <1269985283.4868.170.camel@grateful.d.umn.edu> (Matt Zagrabelny's
message of "Tue, 30 Mar 2010 16:41:23 -0500")
Date: Tue, 30 Mar 2010 14:46:24 -0700
Message-ID: <874ojxbhzj.fsf@windlord.stanford.edu>
MIME-Version: 1.0
Cc: kerberos <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Matt Zagrabelny <mzagrabe@d.umn.edu> writes:
> Thanks for the quick help, Russ. Still the same problem, though.
> # grep -B1 allow_weak_crypto /etc/krb5.conf
> [libdefaults]
> allow_weak_crypto = true
> # /etc/init.d/krb5-kdc restart
> % telnet blah...
> AS_REQ (1 etypes {1}) 10.25.1.14: CANT_FIND_CLIENT_KEY:
> mzagrabe@D.UMN.EDU for krbtgt/D.UMN.EDU@D.UMN.EDU, KDC has no support
> for encryption type
> Any other ideas?
You need it on the client in addition to the server.
--
Russ Allbery (rra@stanford.edu) <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos