Package: openafs-fileserver
Version: 1.8.2-1+deb10u1
Severity: important
Tags: upstream

Dear Maintainer,

The servers in this release do not work when used with des3-cbc-sha1
(enctype 16) keys. The requested size of the key is computed incorrectly
as 21 bytes instead of 24, and authcon.c:_afsconf_GetRxkadKrb5Key rejects
the key from the KeyFileExt. If the 3des key is the only one available,
it is impossible to authenticate to the server, even with -localauth.

This has been fixed upstream (https://gerrit.openafs.org/#/c/14203/),
but the patch is apparently not yet in any release

-- System Information:
Debian Release: 10.9
  APT prefers stable
  APT policy: (990, 'stable'), (500, 'stable-updates'), (500,
'stable-debug'), (500, 'proposed-updates-debug')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-16-amd64 (SMP w/1 CPU core)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE,
TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8),
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages openafs-fileserver depends on:
ii  debconf [debconf-2.0]  1.5.71
ii  libc6                  2.28-10
ii  libhcrypto4-heimdal    7.5.0+dfsg-3
ii  libroken18-heimdal     7.5.0+dfsg-3
ii  lsb-base               10.2019051400
ii  openafs-client         1.8.2-1+deb10u1

Versions of packages openafs-fileserver recommends:
ii  ntp  1:4.2.8p12+dfsg-4

Versions of packages openafs-fileserver suggests:
pn  openafs-doc  <none>

-- debconf information:
  openafs-fileserver/thiscell: grand.central.org
  openafs-fileserver/alpha-broken:

Reply via email to