Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

A rolling disk gathers no MOS.


devel / comp.protocols.kerberos / Re: kadmin not working after server migration, but kdc works

SubjectAuthor
o Re: kadmin not working after server migration, but kdc worksGreg Hudson

1
Re: kadmin not working after server migration, but kdc works

<mailman.97.1663688654.8148.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=296&group=comp.protocols.kerberos#296

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: ghud...@mit.edu (Greg Hudson)
Newsgroups: comp.protocols.kerberos
Subject: Re: kadmin not working after server migration, but kdc works
Date: Tue, 20 Sep 2022 11:43:40 -0400
Organization: TNet Consulting
Lines: 16
Message-ID: <mailman.97.1663688654.8148.kerberos@mit.edu>
References: <YynL5A9eZog8XQNu@pc220518.home.grep.be>
<03a01502-744e-d72f-d8b5-bff5e2980826@mit.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="9605"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Thunderbird/91.9.1
To: Wouter Verhelst <w@uter.be>, kerberos@mit.edu
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=d/bVT0h6UiHTOYfYyLI3hBUS/qMYL7JPlVrKnzWqd/tDD/3yZPW4i4AIwiT/5BByw8aUd18CY95BlnvY/TBFOb4DoykHnSTUdLs9oT8NOsqv0T9VooQ8WiQcnIiZgJpqP5gfIYwBQZvHvqtFumKQZGmxc35zx7O3sxsUJvSpdEQHQxRucfQqyNyBeJLOo6WcsgQ5OHYPa+Qf+URwIi4dmyn/Rot7TFzE6/tVLyHEzH8JBaUyEeI+n+FvRYIfSlsayeWJ65TMLCIrDGhUCfz4uayhOHnWwVaAGN9XpcpW6qGRomc0FgIRMOtTDoXUw+FIGXgh1YQWyyY8FL5oRlUXFw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=K0gVMQrsFwav9Oiqmh6eoS35Lzg2j4kOOyXgxihfxDI=;
b=JVvgKEeAror4qug2pwGSNsyasW0CeNllalLFnBc/7cw24CLnADnD8ksOmSSVFKKH/ttvvwfVw4zmN7eu1Em0CB7tkqnfh29mXm2LxYMr6YJglFdf4mChFgVHhboOxm14Zu4Ihx2KQgFbGXUbebgT3htrsFkxuCDEikV1hD66dnTPudBKcb2jU3L80DwFP3bjlGxg8oUUFZ/0PL/DA4bMlYfG6ELLS+SfS/6GTN2LiVve+bZz4WpSknP0PnK2uQMKgeKtAiWD+40Ae8QCs72jkaNgWfPglCGP/tfEfjYwx0yMRXX3TscGj/VRHfJcbbosnzxyxcYmpQWZ3XYDuX9X8Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
18.9.28.11) smtp.rcpttodomain=mit.edu smtp.mailfrom=mit.edu; dmarc=pass
(p=none sp=none pct=100) action=none header.from=mit.edu; dkim=pass
(signature was verified) header.d=mit.edu; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mit.edu; s=selector2;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=K0gVMQrsFwav9Oiqmh6eoS35Lzg2j4kOOyXgxihfxDI=;
b=RSSapJKEHzRi3/ZEG/W+iDZPe6PoMyP+dfFPH+6yx5qCWqBaIgoXIy9ZHkEGBiiDRr6hSxw4e0yUvvtis5/m9tdXRvTNbkse9gFMfEIAgVDQ1QTXTP7Jnuiod+CymfB03sVvFHeEnzVFXVylGgHnaRZk/0lCoOD6o+m87gLz84M=
Authentication-Results: spf=pass (sender IP is 18.9.28.11)
smtp.mailfrom=mit.edu; dkim=pass (signature was verified)
header.d=mit.edu;dmarc=pass action=none header.from=mit.edu;
Received-SPF: Pass (protection.outlook.com: domain of mit.edu designates
18.9.28.11 as permitted sender) receiver=protection.outlook.com;
client-ip=18.9.28.11; helo=outgoing.mit.edu; pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mit.edu; s=outgoing;
t=1663688625; bh=K0gVMQrsFwav9Oiqmh6eoS35Lzg2j4kOOyXgxihfxDI=;
h=Date:Subject:To:References:From:In-Reply-To;
b=noDf1/jRfPXa2tAtVANilJxdJtV9Px97ny/q4DQCffYjkReWly8c7DRiF44CiFKzX
pYStiWys8fu98le31ylrLkuHOzAm5nwiT40yqSI6ubhAuuJm3Z8cz+LKHpQXIuPXO7
TPFvyyLTOJdVxFxQsA0ftN34Ra9kkcwL0PUFe58kVAWcERbr/FqVYf/f+pODLMMTfN
/F7uDCo22Xfo9W9gvTaaCEQFM+9IZ2Qyg2XQrTKRLuzQaJkmPnBKd69naT9v/CK3Ss
fEXdnkTqKA0WEloVdCgXMutOIDZaDjGdnt98aMuLmV3yRHGM1KIFO5g8g5VzwtBI2G
pXhRirun6yczA==
Content-Language: en-US
In-Reply-To: <YynL5A9eZog8XQNu@pc220518.home.grep.be>
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: CO1NAM11FT113:EE_|BYAPR01MB4199:EE_
X-MS-Office365-Filtering-Correlation-Id: 06cb2186-96ed-4340-b105-08da9b1ee800
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: HPRanKjtg+Z57e4jlSEf2Dhsi/aOF3N8aCrGEQvM6sK3kGx1IMntH+oSvaiiCyoSa0EvrzuS5hUqXH0h3qe5qs7gPoqQWykFnsh7H1L+/NSQcARdsRtIFINjkIWRnCs2Bl1ghu7E4Ka0LAsA81x1hLjPreQ3mN6rRxO389IIMK2rDbLE1jweB1Pt23JG6fJ9KFJmlVjvNurmDBe5mF7VU8izv5E+IJNRjVUWbMnASlUF2W9M63/djhMJBnXfzLlOwKTs9s0byNiPqJI4IBwqNXKl81gIC0+3G0Kp1M6yFaDqJjNHomJyv78xmQjXPa3qxOPYtT31uiwLGx6E2OPQbekgu6DXlVw2CBuSTzfLVBYJOoEhzyqXB6vTcvU1KAUdAgOXhoVnWGqJRv2ye8d5nRe5Atb9tvWwkNtWcxA4icRlK2ZdcRTNzM3xr9Wj614bBB4WM+DhKS69Fc2iwixfPGtUNOmzFUZxJpz7tnDWiCznKf07tYUz5AfBCyug1xCSfozS5SLpu9GGl5l+fyxcmqRlQxvtaJebMHEI4mCaaWHVzyGt1wSqEpstc7suubAAxo5dy7RTWudNikRD9DKEAXjb78teDm+3SV8H8gdmE6rNe2DPTfxGYG1A6uaXQRK260jg/Noxkwmc0wBksEz28YW84stfQz/4Y/7XMdFp4rKIkkdP/X79b1Qq9B4CXzynz0ScTEUuJusbYFXcX/EK60uUaznW/2hbsVAeO9sjLL8IEQHav3Td+f800oOU6TX1Mvtkq0Eoep3A+3VHcgk4HKbULyB4S2An1gVfYgu6otkH4HptaDGxS0HA7LQA2W3reZfhtpv5DLn2PlUuElTkkTJchlEuntdVNhnZNBc3pyxnnTXikeBE0DpS6riE1xqXzfuzWB4gZUbltUBm9TTZpg==
X-Forefront-Antispam-Report: CIP:18.9.28.11; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:CAL; SFV:NSPM; H:outgoing.mit.edu; PTR:outgoing-auth-1.mit.edu; CAT:NONE;
SFS:(13230022)(4636009)(346002)(376002)(136003)(396003)(39860400002)(451199015)(356005)(31686004)(83380400001)(26005)(2616005)(956004)(336012)(426003)(7696005)(2906002)(53546011)(6666004)(966005)(478600001)(31696002)(6706004)(6636002)(786003)(316002)(70586007)(68406010)(86362001)(8676002)(4744005)(5660300002)(75432002)(36756003)(781001)(43740500002);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Sep 2022 15:43:46.5499 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 06cb2186-96ed-4340-b105-08da9b1ee800
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: CO1NAM11FT113.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR01MB4199
X-OriginatorOrg: mit.edu
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <03a01502-744e-d72f-d8b5-bff5e2980826@mit.edu>
X-Mailman-Original-References: <YynL5A9eZog8XQNu@pc220518.home.grep.be>
 by: Greg Hudson - Tue, 20 Sep 2022 15:43 UTC

On 9/20/22 10:19, Wouter Verhelst wrote:
> I can log in to the server; "kinit" works just fine. However, kadmind
> refuses to start, and when I run "kadmin.local", I get:
>
> root@lounge ~ # kadmin.local
> Authenticating as principal root/admin@GREP.BE with password.
> kadmin.local: Required parameters in kdc.conf missing while initializing kadmin.local interface

This is one of our worst error messages (see
https://krbdev.mit.edu/rt/Ticket/Display.html?id=8247 ).

>From experience, this probably means you have a single-DES enctype
listed in supported_enctypes and are using release 1.18. (In 1.17 or
previous the enctype would be recognized; in 1.19 or later the library
would ignore the enctype rather than failing out.) Remove the
single-DES enctype and kadmind should start working again.

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor