Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

A bug in the hand is better than one as yet undetected.


devel / comp.protocols.kerberos / Re: kadmin not working after server migration, but kdc works

SubjectAuthor
o Re: kadmin not working after server migration, but kdc worksRuss Allbery

1
Re: kadmin not working after server migration, but kdc works

<mailman.99.1663703853.8148.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=298&group=comp.protocols.kerberos#298

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: eag...@eyrie.org (Russ Allbery)
Newsgroups: comp.protocols.kerberos
Subject: Re: kadmin not working after server migration, but kdc works
Date: Tue, 20 Sep 2022 12:56:51 -0700
Organization: The Eyrie
Lines: 18
Message-ID: <mailman.99.1663703853.8148.kerberos@mit.edu>
References: <YynL5A9eZog8XQNu@pc220518.home.grep.be>
<03a01502-744e-d72f-d8b5-bff5e2980826@mit.edu>
<Yyn8l/Qed7tgqZqU@pc220518.home.grep.be>
<871qs5yg3g.fsf@hope.eyrie.org>
Mime-Version: 1.0
Content-Type: text/plain
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="27007"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux)
Cc: Greg Hudson <ghudson@mit.edu>, <kerberos@mit.edu>
To: Wouter Verhelst <w@uter.be>
Authentication-Results: mit.edu;
dmarc=none (p=none dis=none) header.from=eyrie.org
Authentication-Results: mit.edu; arc=pass smtp.remote-ip=18.7.73.16
ARC-Seal: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1663703851; cv=pass;
b=bHc+pqB1IGT0zXYvrn4AnCwqlgtFPNv1CM7joePDzhNvhc4lsE+V2lDIm1ECSCvRl7fjR/8piALy29WlShZ0f2HKmiINyzJ44TNa8X57nMEKMl8pBq4Af5dAjotAQkRe/HdQHvWqVPftkJPBLmyVG2YncLyRVYY5Itx3AxJS5MFPU+vdzmXAoDJ4VeS/xMH0DKpN75CmeFV9HyHUxKCapiLp9KAn+zC8lhst3azPjX+oDgHy3Fp/lq7c/7WaHWGmB55K302OxIrC8dzqfX40QUb3lhHiNC4w3Mw7+dwMaD92/m1mj1yMVjq6Lb7gTSVyQKbLXMRExlkIKuv/nmI3NA==
ARC-Message-Signature: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1663703851;
c=relaxed/relaxed; bh=D7iCBKWqtHLJcTEJVWP2QMy9c7/unK+Ocvsanhw/aRw=;
h=DKIM-Signature:From:To:Subject:Date:Message-ID:MIME-Version;
b=MSCL/aCJXvCjHf1aK0ALOU2WsPqMT8LAMUEeFpTtlshBR6LK39EK8PU8fK7moltOs90mEEdIiuBD3cSj2M4WoW/5hTsekM9YWv4/4lEC8bM/ZnmkMKkb0vJEvwsEIuMPUX8lPzJq+lVcQO2twC6I2lg6GM8+0hudVp4i0NAtZlSDizllRfLLv/Ce8mlvUhuGFg68icO2loBPKEHT1jn+B9GoO9QqP9PEqL2S6fm7uw1PXKJVpZbB8jiiiht2U4LlimNwocvZT/C5V04AKB6xHxbv86dNz5cu5bPYmwJsuVfo6hUvBbhrC1k9RhmFyqRE+j5S8hw1BaPs2QK2VK+atQ==
ARC-Authentication-Results: i=2; mit.edu; dkim=pass (1024-bit key)
header.d=mitprod.onmicrosoft.com header.i=@mitprod.onmicrosoft.com
header.b=R1XTKPE8
Authentication-Results: mit.edu;
dkim=pass (1024-bit key) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.b=R1XTKPE8
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=Ne1elhQLkQtxtCuUwbKpk1ogX3MACLTum7wfEc0uLJ78Y25RwWmoHEj1LY3sf+/9n21JqNW9A/a5utfQLPLZfxART0HT5c2R3b/3aAX3SCUDU83IepUIrzvp9sohKxWKlkNuo5Fp6f28/Mibkyi17BcVEzH2H/KKfRC+N4Nazfup6vf8hVb/9mtGKpe73ZAsxoF+1wfp1OaoiZ899eQIaBSy8RkSqcV4CZS5iqJ8sU+In8a60q2awIPLl365i/DcyIp4xyPYF8IlDGUi8Y83tm1BiI4PrOTCshuCGUJpww/wWml8p99CUg83BmaH91ggBijHhGJz7jdnyTit1oRfbQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=D7iCBKWqtHLJcTEJVWP2QMy9c7/unK+Ocvsanhw/aRw=;
b=iKHuhsLiSzOdKO9lpm4AvnY6mKanvIZGqjo52X0xFWdQTe7E7H+EGCwOI4bon6e9C6lAussAYl4KxSoHw5fcDaVz9wBYcw+xqqCNxWHta5hnkMYVrS5r2MsyoqlNtXyKalFhbEd55wpgu02rY34c24eR5sruAIqMPHd7Jx7ad+uomnCBHv9C0qxLO/UnTW6A7mmoogzsFs3H0fq5YwsRiFDcEviJe6j7m39lgnQU9J+lfiat/qAZFJW4xuee2NTJqts5yco00CrSVrPOLC1uCi0wZVrnwIeXvZiw5J9TXZmGRhCB+6swoSEHWhXjXyrrZgzc8T5zDbSyM0hePN7V4w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
166.84.7.159) smtp.rcpttodomain=mit.edu smtp.mailfrom=eyrie.org;
dmarc=bestguesspass action=none header.from=eyrie.org; dkim=none (message not
signed); arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=D7iCBKWqtHLJcTEJVWP2QMy9c7/unK+Ocvsanhw/aRw=;
b=R1XTKPE80ucd66OU2SdUK8D9bUW2kLuHgc3c9iPNBUDktxDqjBSH1j6rLLHyH/x8ejSXwOUDnJYWYAcaMzDY+Y4AZ4YVoPqi2SyP1FDkhCpMZocZ/WVEYcCkqXKPup0B2WWZJtDA61ktPYeswjm5FDG7oziNGimMiHd0ZvbrhKQ=
Authentication-Results: spf=pass (sender IP is 166.84.7.159)
smtp.mailfrom=eyrie.org; dkim=none (message not signed)
header.d=none;dmarc=bestguesspass action=none header.from=eyrie.org;
Received-SPF: Pass (protection.outlook.com: domain of eyrie.org designates
166.84.7.159 as permitted sender) receiver=protection.outlook.com;
client-ip=166.84.7.159; helo=haven.eyrie.org; pr=C
In-Reply-To: <Yyn8l/Qed7tgqZqU@pc220518.home.grep.be> (Wouter Verhelst's
message of "Tue, 20 Sep 2022 19:47:03 +0200")
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: BL02EPF0000C408:EE_|DM5PR0101MB2988:EE_
X-MS-Office365-Filtering-Correlation-Id: 118373a7-32d2-438a-4639-08da9b424ddd
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: saLxPHkD9gXhjLMkeOxPYPzXC4ApxPxjwIiwuSctGWDmX4inbV8k7pgcL9AsUDWkspQMBhX0swJ9oAp1PILis8dyVDei4PzI5/jVKWe6Q4CE823brVjQZj2YzuxAw8E/eRUPEs4OH85zad6OW3wMKmrUSmHYQdjaZM23KV4ar2EUq84uJIfB+eYMg72tAxUQhFR57OdTTQ9ecpNcoM1r9MwkPguE5QImDfTzIzRFGcUMHyfKV8qM+wEUJqnif3DnXZb95QKkiiAp5i+/U9SLqJEJZQNeVieITJZmQYMRimP3yCGS0lCLD3y5EhxBStWhuHpCxU0iKH6UFb8JAdCwbATTyrNIAmE9upzj4NM2jFWx77XaL81GCMkOh5XjmEyfjPRo+I4jpDreiYqCxtgSscJqBNwUJxfGBUy+Taef4xNtIMnHDuZEV1//QD1I0iyxmUEFNTlNFTDMFGpsOTXJmklmjmco78U7gJuH2TWxuvO7n5tnEywtGqPjMECkFPEqYNwUW9NYbqCbP125xMQZVA7HWquc/xJKXeH7OotsI2dbJFY036z2WfPoQSNWen0INthsq/qfoFJ4onYvYZxXQf+Awk83RPinrKWia1r+4TVwCGs9nGC5ouZX3IKtyJyiYmf5rACkQlmw8EavgpEr22oOoH/rPOIAoRHtEIHwCthk7b4iD0O7RLbh9QG09ex0ozTg2cNLDHGNorO/elhknya2cAdniT3AVCiIKL/RAq84rtlHE7DejbYPu3IgX5N9
X-Forefront-Antispam-Report: CIP:166.84.7.159; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:haven.eyrie.org; PTR:haven.eyrie.org; CAT:NONE;
SFS:(13230022)(4636009)(346002)(376002)(396003)(136003)(39860400002)(451199015)(4744005)(2906002)(786003)(42186006)(316002)(426003)(6862004)(8676002)(4326008)(5660300002)(70586007)(68406010)(86362001)(6266002)(336012)(356005)(7636003)(7596003)(498600001)(26005)(83380400001)(36916002)(781001);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Sep 2022 19:57:10.0652 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 118373a7-32d2-438a-4639-08da9b424ddd
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: BL02EPF0000C408.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR0101MB2988
X-OriginatorOrg: mitprod.onmicrosoft.com
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <871qs5yg3g.fsf@hope.eyrie.org>
X-Mailman-Original-References: <YynL5A9eZog8XQNu@pc220518.home.grep.be>
<03a01502-744e-d72f-d8b5-bff5e2980826@mit.edu>
<Yyn8l/Qed7tgqZqU@pc220518.home.grep.be>
 by: Russ Allbery - Tue, 20 Sep 2022 19:56 UTC

Wouter Verhelst <w@uter.be> writes:
> On Tue, Sep 20, 2022 at 11:43:40AM -0400, Greg Hudson wrote:

>> From experience, this probably means you have a single-DES enctype
>> listed in supported_enctypes and are using release 1.18. (In 1.17 or
>> previous the enctype would be recognized; in 1.19 or later the library
>> would ignore the enctype rather than failing out.) Remove the
>> single-DES enctype and kadmind should start working again.

> So, supported_enctypes is not even in the krb5.conf file; I assume that
> means it then reverts to defaults?

That's your krb5.conf, but the error message is about your kdc.conf
(/etc/krb5kdc/kdc.conf). It has its own separate supported_enctypes
setting.

--
Russ Allbery (eagle@eyrie.org) <https://www.eyrie.org/~eagle/>

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor