[email protected] wrote: > Moreover, do you even see the KRB5KRB_ERR_RESPONSE_TOO_BIG reply from the KDC?
The MIT KDC doesn't seem to see the fragmented UDP packets at all, only when the occasional non-fragmented packet arrives does anything happen. From the client side the connection (I'm testing with a web page on apache) just seems to hang for 20-30 seconds before the connection falls back to username/password authentication. -BT > > > Met vriendelijke groet > Best regards > Bien à vous > > Miguel SANDERS > ArcelorMittal Gent > > UNIX Systems & Storage > IT Supply Western Europe | John Kennedylaan 51 > B-9042 Gent > > T +32 9 347 3538 | F +32 9 347 4901 | M +32478 805 023 > E [email protected] > www.arcelormittal.com/gent > > -----Oorspronkelijk bericht----- > Van: [email protected] [mailto:[email protected]] Namens Bjoern > Tore Sund > Verzonden: vrijdag 22 mei 2009 11:05 > Aan: [email protected] > Onderwerp: UDP/TCP problem in cross-realm authentication > > > We have linux clients in an MIT Kerberos realm (1.6.3), Windows XP SP3 > clients in AD and two-way trust configured. Accessing AD resources from > Linux clients work perfectly. > > Accessing resources in the MIT Kerberos realm from Windows fails more often > than not. Lots of packet sniffing shows fragmented UDP packets which the > unix server isn't able to reassemble. So, in accordance with > http://support.microsoft.com/kb/244474 we've set > HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\ > Kerberos\Parameters\MaxPacketSize to 1 on the XP clients. Still no go, they > never try TCP (again sniffing both on the XP client and the unix kerberos > server) but go straight for TCP. TCP is working on the unix kerberos server, > the linux clients are happily using it. Have anyone seen MaxPacketSize fail > to have effect before? Any ideas on how to trace this further? > > -BT -- Bjørn Tore Sund Phone: 555-84894 Email: [email protected] IT department VIP: 81724 Support: http://bs.uib.no Univ. of Bergen When in fear and when in doubt, run in circles, scream and shout. ________________________________________________ Kerberos mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/kerberos
