[27561] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Bizzare problem with authenticating a service principal with

daemon@ATHENA.MIT.EDU (Jason Testart)
Mon Mar 12 14:11:58 2007

Message-ID: <45F5942C.9060406@cs.uwaterloo.ca>
Date: Mon, 12 Mar 2007 13:55:56 -0400
From: Jason Testart <jatestart@cs.uwaterloo.ca>
MIME-Version: 1.0
To: Tom Yu <tlyu@mit.edu>
In-Reply-To: <ldv3b4abf3f.fsf@cathode-dark-space.mit.edu>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu



Tom Yu said the following on 3/12/2007 12:29 PM:

> 
> In one case I encountered, I think the reason was that AD was using
> the NetBIOS name for the server instead of its FQDN to create the
> "principal name" for the salt.  Does the server in question have a
> hostname which is longer than 14 or 15 (I can't remember the exact
> number) characters?

I just watched the traffic, and I'm getting a pre-auth required followed 
by a pre-auth failed.  In both cases, the salt appears to be the name of 
the AD account that the service principal is mapped to.  Is this my 
problem?  How does one fix this?

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post