[29261] in Kerberos
Re: Kerberos V5 refuses authentication because Kerberos
daemon@ATHENA.MIT.EDU (Victor Sudakov)
Fri Feb 15 01:00:40 2008
From: Victor Sudakov <vas@mpeks.no-spam-here.tomsk.su>
Date: Fri, 15 Feb 2008 05:43:13 +0000 (UTC)
Message-ID: <fp38ph$f8i$1@relay.tomsk.ru>
X-Complaints-To: noc@sibptus.tomsk.ru
X-Comment-To: Steven Miller <stevenraymillerjr@yahoo.com>
To: kerberos@mit.edu
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Steven Miller wrote:
> >
> > What could be the reason that I cannot telnet from
> > FreeBSD to Solaris 10
> > with the following error:
> >
> > Connected to oracle.sibptus.tomsk.ru.
> > Escape character is '^]'.
> > [ Trying mutual KERBEROS5
> > (host/oracle.sibptus.tomsk.ru@SIBPTUS.TOMSK.RU)... ]
> > [ Kerberos V5 refuses authentication because
> > Kerberos checksum verification failed: Bad
> > encryption type ]
> > [ Trying KERBEROS5
> > (host/oracle.sibptus.tomsk.ru@SIBPTUS.TOMSK.RU)... ]
> > [ Kerberos V5 refuses authentication because
> > Kerberos checksum verification failed: Bad
> > encryption type ]
> > Password:
> I believe that solaris (as as solaris 9) only supports
> des-cbc-crc encrypion.
Actually, there *is* a des-cbc-crc key in the keytab, why wouldn't it just
use it?
# klist -e -k /etc/krb5/krb5.keytab
Keytab name: FILE:/etc/krb5/krb5.keytab
KVNO Principal
---- -----------------------------------------------------------------------
1 host/oracle.sibptus.tomsk.ru@SIBPTUS.TOMSK.RU (DES cbc mode with CRC-32)
1 host/oracle.sibptus.tomsk.ru@SIBPTUS.TOMSK.RU (etype 2)
1 host/oracle.sibptus.tomsk.ru@SIBPTUS.TOMSK.RU (DES cbc mode with RSA-MD5)
1 host/oracle.sibptus.tomsk.ru@SIBPTUS.TOMSK.RU (Triple DES cbc mode with HMAC/sha1)
#
--
Victor Sudakov, VAS4-RIPE, VAS47-RIPN
2:5005/49@fidonet http://vas.tomsk.ru/
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos