[32688] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kerberos troubles

daemon@ATHENA.MIT.EDU (Christopher D. Clausen)
Tue Sep 21 15:28:01 2010

Message-ID: <3CA81CF7260B4B22AA01C064FB135C42@CDCHOME>
From: "Christopher D. Clausen" <cclausen@acm.org>
To: "Jean-Yves Avenard" <jyavenard@gmail.com>
Date: Tue, 21 Sep 2010 14:28:00 -0500
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Jean-Yves Avenard <jyavenard@gmail.com> wrote:
> I have now identified the cause of the issue.
> When using mod_auth_kerb with MIT krb5 v1.6.x it works perfectly
> with krb5 1.7 and 1.7.1 same.
> However, I get this "GSS-API major_status:000d0000,
> minor_status:000186a3" error whenever I use MIT 1.8.x kerberos
> libraries (tested with 1.8.1 and 1.8.3)

I'm guessing you need to enable single DES encryption types on the KDCs, the 
web server and the clients.

You should look into the allow_weak_crypto = true in the [libdefaults] 
section of krb5.conf

<<CDC

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post