Package: libkrb53
Version: 1.3.6-2sarge2
Tags: sarge

I install winbind which pulled in libkrb53. After setting winbind up to
join an Active Directory domain, and trying to do so, the event logs on
the PDC were filled with errors containing the message:

===
While processing a TGS request for the target
server foo/bar, the account [EMAIL PROTECTED] did not
have a suitable key for generating a Kerberos ticket (the missing key
has an ID of <somenumber>). The requested etypes were <anothernumber>.
The accounts available etypes were 23  -133  -128  3  1.
===

I remembered having the same problem last summer, but did not remember
how exactly I fixed it. In the end I found
http://diswww.mit.edu:8008/menelaus.mit.edu/krb5-bugs/7083 and
http://diswww.mit.edu:8008/menelaus.mit.edu/krb5-bugs/7084 which put me on
the right track: libkrb53 was requesting the wrong etype. I remembered
fixing that by modifying the krb5 configuration file in the other case so
I copied it over to the new machine (which had no krb5.conf in place).
This fixed it.

Apparently libkrb53 has bad compiled in defaults; these should be fixed.


Regards,

Filip

-- 
"I decry the current tendency to seek patents on algorithms. There are
 better ways to earn a living than to prevent other people from making
 use of one's contributions to computer science."
        -- D.E. Knuth, TAoCP 3


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to