[16650] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: message size incompatible with type error for krb5-1.9 lib using

daemon@ATHENA.MIT.EDU (Luke Howard)
Wed Feb 16 20:00:45 2011

Mime-Version: 1.0 (Apple Message framework v1082)
From: Luke Howard <lukeh@padl.com>
In-Reply-To: <4D5C237D.7020306@anl.gov>
Date: Thu, 17 Feb 2011 12:00:33 +1100
Message-Id: <21B36B1B-6F59-4A09-BB53-37E271ED4BFE@padl.com>
To: "Douglas E. Engert" <deengert@anl.gov>
Cc: "'krbdev@mit.edu'" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

> That is 0x2200200.
> You also have the USE_DES_KEY_ONLY bit (0x200000) turned on, so the Windows DC will
> assume the machine can only do DES. So that may be why the PAC signature
> is using DES.


I haven't read the whole thread, but I believe the signature is hard-coded to use RC4-HMAC (at least pre-AES).

-- Luke
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post