[27556] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Bizzare problem with authenticating a service principal with

daemon@ATHENA.MIT.EDU (Jason Testart)
Mon Mar 12 11:24:17 2007

Message-ID: <45F4CDC8.6070607@cs.uwaterloo.ca>
Date: Sun, 11 Mar 2007 23:49:28 -0400
From: Jason Testart <jatestart@cs.uwaterloo.ca>
MIME-Version: 1.0
To: jaltman@secure-endpoints.com
In-Reply-To: <45F4C1E7.2010807@secure-endpoints.com>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu



Jeffrey Altman wrote:
> Jason Testart wrote:
>> I'm trying to get pam_krb5 working with an Active Directory domain.  It 
>> works when I don't have a krb5.keytab file but it doesn't when I do, 
>> since the verification of the TGT using the service principal fails with 
>> an error: "Key table entry not found".  The keytab file is simple as it 
>> only contains the "host" service principal for the Ubuntu Linux box that 
>> I am testing with.
> What enctype is the service ticket being encrypted with?

I used the default.  "ktpass /?" says that's RC4-HMAC-NT.

> 
> Does that enctype exist in the keytab?

"ArcFour with HMAC/md5".  Sounds like a match.

> 
> Does the kvno of the service ticket match the kvno of the entry in the
> keytab?

Yes.

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post