Re: [Bug 1332985] [NEW] Add the krb5-send-pr command to the ubuntu package

2014-06-22 Thread Russ Allbery
and operating system information with your bug report. Please note that bug reports are public; if you are reporting a security vulnerability, send mail to krbcore-secur...@mit.edu instead, ideally using PGP encryption. EOF -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You

[Bug 1119465] Re: credential verification failed: KDC has no support for encryption type

2013-02-08 Thread Russ Allbery
Reassigning to krb5, as: Feb 8 15:38:09 vpn-gw-ausfall openvpn[9031]: pam_krb5(openvpn- krb5:auth): (user hildeb) credential verification failed: KDC has no support for encryption type is an error message from the underlying Kerberos library that libpam- krb5 can't do anything about.

[Bug 1098294] Re: Use of uninitialized value $admin in string eq at ...

2013-01-10 Thread Russ Allbery
This should be harmless, just noisy, but will be fixed in the next release. Thanks! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to kerberos-configs in Ubuntu. https://bugs.launchpad.net/bugs/1098294 Title: Use of uninitialized

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-05-14 Thread Russ Allbery
Oh, wow, great job with the test case. It wouldn't have occurred to me to just do that. (And yes, you have to use the Git version because I've been adding a ton of new tests compared to the latest full release.) -- You received this bug notification because you are a member of Ubuntu Server

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-04-27 Thread Russ Allbery
I have a test case, but I'm not sure you'll particularly enjoy it, since it isn't in a neatly isolated form. But if you: git clone git://git.eyrie.org/kerberos/pam-krb5.git cd pam-krb5 ./autogen ./configure and then add the username and password of an account in a test Kerberos

[Bug 715765] Re: Can't change kerberos password, pam-krb5 try_first_pass also fails

2012-04-25 Thread Russ Allbery
This bug was introduced in MIT Kerberos 1.10. After a failing authentication with preauth required in a particular Kerberos context, all subsequent authentications in that context that require preauth will fail. Upstream has fixed this with commit 25822. This is a fairly serious issue, blocking

[Bug 715765] Re: Can't change kerberos password, pam-krb5 try_first_pass also fails

2012-04-25 Thread Russ Allbery
Actually, now that I look more at this, this may be an unrelated problem. The problem I encountered was reported upstream as a password change problem, but this may be a slightly different issue. I'll open another bug about the failed second authentication problem. -- You received this bug

[Bug 988520] [NEW] After failed auth, subsequent auths in same context fail

2012-04-25 Thread Russ Allbery
Public bug reported: MIT Kerberos 1.10 (including pre-releases and betas) exposed a bug in the tracking of preauth mechanisms such that, if an authentication fails after preauth was requested, all subsequent preauth-required authentications in the same Kerberos context will also fail. This

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-04-25 Thread Russ Allbery
** Bug watch added: Debian Bug tracker #670457 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670457 ** Also affects: krb5 (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670457 Importance: Unknown Status: Unknown -- You received this bug notification because you

[Bug 715765] Re: Can't change kerberos password

2012-04-25 Thread Russ Allbery
** Summary changed: - Can't change kerberos password, pam-krb5 try_first_pass also fails + Can't change kerberos password -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://bugs.launchpad.net/bugs/715765 Title:

Re: [Bug 715765] Re: Can't change kerberos password

2012-04-25 Thread Russ Allbery
Steve Langasek steve.langa...@canonical.com writes: Setting this back to 'triaged', which is the more-better bug state in LP. Thanks. I tried to do that but it didn't let me (probably not enough access bits). -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle

[Bug 962560] Re: pam-auth-update Account-Type should be Additional

2012-03-26 Thread Russ Allbery
This analysis looks right to me, and I think may run deeper than just this one module. If every account module should be additional and not primary, I think that points to an error in the data model or interpretation of the data model, rather than in individual PAM configurations. And viewing

[Bug 962560] Re: pam-auth-update Account-Type should be Additional

2012-03-26 Thread Russ Allbery
Ah, in fact, I see comment #20 mentioned above is from Steve. Steve, when would you ever want to have an account type of Primary given those semantics? Shouldn't Primary just be treated the same as Additional for the account stack? -- You received this bug notification because you are a member

Re: [Bug 179142] Re: /etc/krb5.conf is malformed

2012-03-19 Thread Russ Allbery
initializing Kerberos code [realms] MYGROUP.COM = { kdc = kerberos.mygroup.com.:88 I'm not sure if this is your problem, but the trailing period here looks suspicious. Try removing the period just before the colon. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle

Re: [Bug 913166] Re: kprop will not find slave-kdc

2012-01-11 Thread Russ Allbery
? -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://bugs.launchpad.net/bugs/913166 Title: kprop will not find slave-kdc To manage

Re: [Bug 913166] [NEW] kprop will not find slave-kdc

2012-01-07 Thread Russ Allbery
/kerbe...@example.net, which fails. Changing the system hostname of the master to kerberos.example.net will probably fix this problem. kprop should really gain an additional command-line option to specify the client principal to authenticate as. -- Russ Allbery (r...@debian.org) http

Re: [Bug 900447] [NEW] Man 5 page for kdc.conf does not mention acceptable encryption types

2011-12-05 Thread Russ Allbery
They're listed in the krb5-admin info pages included in krb5-doc under Configuration Files. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu

Re: [Bug 900447] Re: Man 5 page for kdc.conf does not mention acceptable encryption types

2011-12-05 Thread Russ Allbery
reference manual; they don't have very much useful structure.) -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://bugs.launchpad.net/bugs

[Bug 740477] Re: kinit should print an error if credentials cache has invalid permissions

2011-03-24 Thread Russ Allbery
The bug is trivially reproducible given the instructions given by the reporter. I don't see any need for them to run apport-collect to gather more data. ** Changed in: krb5 (Ubuntu) Status: Incomplete = Confirmed -- You received this bug notification because you are a member of Ubuntu

Re: [Bug 652433] Re: Init script dependency error: krb5-kdc starts before slapd

2011-01-26 Thread Russ Allbery
and repeated attempts to contact the LDAP server. Ideally, they should both be robust against the other not being up yet. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Server Team, which

Re: [Bug 652433] [NEW] Init script dependency error: krb5-kdc starts before slapd

2010-09-30 Thread Russ Allbery
init script orderings break different things for different people. What really needs to happen is that one or the other (or preferrably both) services need to be robust against the other service not yet being initialized. -- Russ Allbery (r...@debian.org) http://www.eyrie.org

Re: [Bug 652433] Re: Init script dependency error: krb5-kdc starts before slapd

2010-09-30 Thread Russ Allbery
on single machines, in which case you may have an LDAP replica and a KDC on the same host. The LDAP replica then needs to do a GSSAPI authentication to the master for replication, which requires access to the KDC. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Init

[Bug 625651] Re: package libkadm5clnt6 1.7dfsg~beta3-1ubuntu0.6 failed to install/upgrade:

2010-08-27 Thread Russ Allbery
This looks to me more like something that's seriously wrong with your system rather than a problem with the package: Setting up libkadm5clnt6 (1.7dfsg~beta3-1ubuntu0.6) ... dpkg (subprocess): unable to execute installed post-installation script: Exec format error The postinst script for

Re: [Bug 571572] Re: krb5 prefers the reverse pointer no matter what for locating service tickets.

2010-04-29 Thread Russ Allbery
keytab. This all happened back in 2007 for us. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- krb5 prefers the reverse pointer no matter what for locating service tickets. https://bugs.launchpad.net/bugs/571572 You received this bug notification because you

Re: [Bug 571572] Re: krb5 prefers the reverse pointer no matter what for locating service tickets.

2010-04-29 Thread Russ Allbery
consistent is if you have a web service that uses DNS-based load-balancing. That's where we ran into that issue. The public name is a CNAME that points to the least-loaded host (which is dynamically discovered by the DNS server). -- Russ Allbery (r...@debian.org) http

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-13 Thread Russ Allbery
or forwardable tickets are more.) -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ? https://bugs.launchpad.net/bugs/369575 You received this bug notification because you are a member of Ubuntu Server Team, which

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-13 Thread Russ Allbery
that to Heimdal, since it would be rather convenient at times. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ? https://bugs.launchpad.net/bugs/369575 You received this bug notification because you

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-11 Thread Russ Allbery
with this setting, surely the same mechanism could be used to override the PAM configuration as well. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ? https://bugs.launchpad.net/bugs/369575 You received this bug

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-01 Thread Russ Allbery
., and log on to a system account. Fixing Debian Bug#330882 (and in general not creating real shells for system users) would remove a lot of my concern. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Why is /usr/share/pam-configs/krb5 specifying minimum_uid

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-31 Thread Russ Allbery
of Kerberos-authenticated and non-Kerberos users, distinguish by UID, and mind the silent Kerberos authentication failure when handling the UNIX login. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Why is /usr/share/pam-configs/krb5 specifying minimum_uid

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-30 Thread Russ Allbery
. At the moment, therefore, I think it's unlikely there will be any changes for lucid if they're waiting on me to initiate the work. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ? https://bugs.launchpad.net/bugs

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-30 Thread Russ Allbery
accounts have valid shells by default. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ? https://bugs.launchpad.net/bugs/369575 You received this bug notification because you are a member of Ubuntu Server

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-30 Thread Russ Allbery
the defaults, I believe changes to the defaults are just automatically applied (although Steve would know better than I). And krb5.conf normally isn't updated once written and I don't think it could be updated with this particular type of change. -- Russ Allbery (r...@debian.org

[Bug 536930] Re: Password changing fails when krb5 pam-config is not first

2010-03-10 Thread Russ Allbery
The problem is in passing use_authtok to pam_krb5. Comparatively, try_first_pass/use_first_pass/nothing at least allows the Current Kerberos password: prompt to come up. This was fixed in 4.0-1. The fix would need to be backported to karmic. -- Russ Allbery (r...@debian.org) http

Re: [Bug 512110] [NEW] gssd regression, Program lacks support for encryption type

2010-01-24 Thread Russ Allbery
. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- gssd regression, Program lacks support for encryption type https://bugs.launchpad.net/bugs/512110 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in ubuntu

[Bug 476069] Re: segfault

2010-01-18 Thread Russ Allbery
The best theory that I have about this bug is that it's related to some sort of failure in the NSS lookups for the current user, resulting in the ticket cache permissions not being changed, but I can't entirely reconcile this with the debugging messages you're seeing. I think progress on this bug

Re: [Bug 476069] Re: segfault

2009-11-05 Thread Russ Allbery
logged by the PAM module before returning to the process. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- segfault https://bugs.launchpad.net/bugs/476069 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5

Re: [Bug 476069] Re: segfault

2009-11-05 Thread Russ Allbery
be a file with a name like /tmp/krb5cc_1000_DBzGt12076 representing the user's ticket cache. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- segfault https://bugs.launchpad.net/bugs/476069 You received this bug notification because you are a member of Ubuntu

Re: [Bug 476069] Re: segfault

2009-11-05 Thread Russ Allbery
mode 600? -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- segfault https://bugs.launchpad.net/bugs/476069 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in ubuntu. -- Ubuntu-server-bugs mailing list

Re: [Bug 374819] Re: Missing dependency on update-inetd and other issues

2009-05-18 Thread Russ Allbery
and register with doc-base krb5-doc no longer has a postinst to call install-docs because doc-base now uses triggers to handle that. This is probably just that Ubuntu's Lintian is a bit out of date. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Missing

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2009-04-29 Thread Russ Allbery
, login can time out and leave you in a situation where you can't log in as root. Maybe it would make sense to leave minimum_uid for /etc/krb5.conf but set ignore_root in the profile to eliminate the worst of the problem of not having minimum_uid set. -- Russ Allbery (r...@debian.org

[Bug 368153] Re: Kerberos, NFS4 and autofs issue

2009-04-28 Thread Russ Allbery
Yeah, that sounds like a bug in the NFS userspace portions to me. The way that I understand this is supposed to work is that the NFS Kerberos support is divided into two components: a userspace daemon that finds the user's ticket cache, grabs credentials where necessary, and loads them into the

Re: [Bug 368153] Re: Kerberos, NFS4 and autofs issue

2009-04-28 Thread Russ Allbery
whatever it happens to find. If autofs happens later, after the PAM authentication has successfully completed, this temporary ticket cache of course no longer exists and therefore the mount cannot be done. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- Kerberos, NFS4

[Bug 368153] Re: Kerberos, NFS4 and autofs issue

2009-04-27 Thread Russ Allbery
I'm not sure what package this is a problem with, but I can say with some certainty that it isn't kerberos-configs. This package only provides the krb5.conf configuration to find the KDCs and do other library initialization. This sounds like a bug in the NFS v4 userspace processes, if I

Re: [Bug 355151] Re: suarez

2009-04-04 Thread Russ Allbery
realm? I suspect this is the same as #296719, which was fixed in 1.22. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- suarez https://bugs.launchpad.net/bugs/355151 You received this bug notification because you are a member of Ubuntu Server Team, which

Re: [Bug 341432] [NEW] package libkrb5-dev 1.6.dfsg.4~beta1-3 failed to install/upgrade: failed to delete `/usr/lib/libkrb5support.so.dpkg-tmp': Read-only file system

2009-03-11 Thread Russ Allbery
on, but probably at the dpkg layer rather than at the level of the krb5 package. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- package libkrb5-dev 1.6.dfsg.4~beta1-3 failed to install/upgrade: failed to delete `/usr/lib/libkrb5support.so.dpkg-tmp': Read-only

[Bug 296719] Re: kerberos-configs fails to configure if dnsdomainname fails

2009-01-21 Thread Russ Allbery
1.22 has been synced to jaunty, so following the process for proposing an intrepid update: This bug causes users who do not have a valid local hostname to fail to install krb5-config. krb5-config is a dependency of many other packages and recommendation for all Kerberos software packages. The

Re: [Bug 309339] Re: kadmind will not listen on IPv6 ports

2008-12-19 Thread Russ Allbery
bad it will be. (kpasswd is likely to be the hardest problem, since it's UDP, but you may not care about it.) -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- kadmind will not listen on IPv6 ports https://bugs.launchpad.net/bugs/309339 You received this bug

Re: [Bug 309339] [NEW] kadmind will not listen on IPv6 ports

2008-12-18 Thread Russ Allbery
sockaddr_in rather than sockaddr_in6, used to bind to the kerberos-adm port, and the code that uses it is: I believe that's correct and upstream does not (yet, at least) support the kadmin protocol over IPv6. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- kadmind

[Bug 159357] Re: Improper format of Kerberos configuration file

2008-07-14 Thread Russ Allbery
This is fixed in the 1.6.dfsg.3-1 Debian release: * If krb5-config/default_realm isn't set, use EXAMPLE.COM as the realm so that the kdc.conf will at least be syntactically valid (but will still require editing). (Closes: #474741) -- Improper format of Kerberos configuration file

[Bug 72599] Re: Option no-addresses spelled wrong in man krb.conf (/usr/share/man/man5/krb5.conf.5.gz)

2008-07-14 Thread Russ Allbery
I'm not sure when it changed, but the current code matches the documentation. noaddresses is the correct option, and the default is true. -- Option no-addresses spelled wrong in man krb.conf (/usr/share/man/man5/krb5.conf.5.gz) https://bugs.launchpad.net/bugs/72599 You received this bug

[Bug 44402] Re: krb5-admin-server fails during install

2008-07-14 Thread Russ Allbery
The package is behaving as intended from my perspective. I don't think it's sane to automatically create a new realm on package installation. You may want to do something else, like initialize from an existing realm or create a realm that doesn't match the local realm for testing. In fact, given

[Bug 116745] Re: kerberos requires users to list themselves in .k5login

2008-07-14 Thread Russ Allbery
This is the intended behavior of Kerberos. So far as I know, it has always worked this way. I have never seen logins succeed if you have an empty .k5login file. I suspect something else was going on when you thought this used to work (such as having the .k5login file not be readable for some