[32410] in Kerberos

home help back first fref pref prev next nref lref last post

Re: KRB5KRB_AP_ERR_MODIFIED: MIT Kerberos 1.8.1 & arcfour-hmac-md5

daemon@ATHENA.MIT.EDU (Richard Silverman)
Thu Jun 3 00:06:33 2010

Date: Thu, 3 Jun 2010 00:06:22 -0400 (EDT)
From: Richard Silverman <res@qoxp.net>
To: Greg Hudson <ghudson@mit.edu>
In-Reply-To: <1275517354.2419.798.camel@ray>
Message-ID: <Pine.OSX.4.64.1006030003340.5006@darwin.oankali.net>
MIME-Version: 1.0
Cc: "kerberos@mit.edu" <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On Wed, 2 Jun 2010, Greg Hudson wrote:

> On Wed, 2010-06-02 at 03:33 -0400, Richard E. Silverman wrote:
>> After upgrading to MIT Kerberos 1.8.1, I get KRB5KRB_AP_ERR_MODIFIED while
>> trying to authenticate to certain devices; so far, a NetApp filer, and
>> Windows hosts running BitVise WinSSHD and MS SQL Server (alll part of a
>> Windows AD realm).
>
> FYI, I tried reproducing this using MIT code on both ends (a 1.7 KDC and
> GSS sample server, and a 1.8 client) and wasn't able to get it to break.

Thanks for looking at it.  I don't know that 1.7 is OK, though;
the latest release I know does *not* have the problem, is 1.6.3.

> That doesn't rule out a lot of possibilities since I didn't use actual
> Windows server components, but it does suggest that the problem might
> not be in the crypto layer per se, despite the fact that it works with
> DES and not with RC4.

-- 
   Richard Silverman
   res@qoxp.net

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post