[27561] in Kerberos
Re: Bizzare problem with authenticating a service principal with
daemon@ATHENA.MIT.EDU (Jason Testart)
Mon Mar 12 14:11:58 2007
Message-ID: <45F5942C.9060406@cs.uwaterloo.ca>
Date: Mon, 12 Mar 2007 13:55:56 -0400
From: Jason Testart <jatestart@cs.uwaterloo.ca>
MIME-Version: 1.0
To: Tom Yu <tlyu@mit.edu>
In-Reply-To: <ldv3b4abf3f.fsf@cathode-dark-space.mit.edu>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Tom Yu said the following on 3/12/2007 12:29 PM:
>
> In one case I encountered, I think the reason was that AD was using
> the NetBIOS name for the server instead of its FQDN to create the
> "principal name" for the salt. Does the server in question have a
> hostname which is longer than 14 or 15 (I can't remember the exact
> number) characters?
I just watched the traffic, and I'm getting a pre-auth required followed
by a pre-auth failed. In both cases, the salt appears to be the name of
the AD account that the service principal is mapped to. Is this my
problem? How does one fix this?
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos