Your message dated Mon, 16 Jul 2018 17:11:20 -0400
with message-id <[email protected]>
and subject line Closing as unreproduced
has caused the Debian Bug report #669127,
regarding libpam-krb5: kerberos authentication against Active Directory server 
fails after upgrade to testing
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
669127: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=669127
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libpam-krb5
Version: 4.3-1
Severity: normal


After today's upgrade to testing, my users cannot authenticate against
ADS anymore. I'm getting:

Apr 17 17:20:40 vpn-gw-int openvpn[11840]: pam_krb5(openvpn-krb5:auth): 
pam_sm_authenticate: entry (0x0)
Apr 17 17:20:40 vpn-gw-int openvpn[11840]: pam_krb5(openvpn-krb5:auth): (user 
tsteiner) attempting authentication as [email protected]
Apr 17 17:20:40 vpn-gw-int openvpn[11840]: pam_krb5(openvpn-krb5:auth): (user 
tsteiner) credential verification failed: KDC has no support for encryption type
Apr 17 17:20:40 vpn-gw-int openvpn[11840]: pam_krb5(openvpn-krb5:auth): 
authentication failure; logname=tsteiner uid=0 euid=0 tty= ruser= rhost=
Apr 17 17:20:40 vpn-gw-int openvpn[11840]: pam_krb5(openvpn-krb5:auth): 
pam_sm_authenticate: exit (failure)

"credential verification failed: KDC has no support for encryption type"

# klist -ke /etc/krb5.keytab
Keytab name: FILE:/etc/krb5.keytab 
KVNO Principal
---- --------------------------------------------------------------------------
   1 host/[email protected] (des-cbc-crc) 
   1 host/[email protected] (des-cbc-crc) 
   1 openvpn-krb5/[email protected] (des-cbc-crc) 
   1 host/[email protected] (des-cbc-crc) 
   1 openvpn-krb5/[email protected] (des-cbc-crc) 

This used to work with libpam-krb5_4.3-1_i386.deb 

-- System Information:
Debian Release: 6.0.4
  APT prefers stable
  APT policy: (990, 'stable'), (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 3.3.0 (SMP w/4 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/bash

Versions of packages libpam-krb5 depends on:
ii  krb5-config           2.2                Configuration files for Kerberos V
ii  libc6                 2.13-27            Embedded GNU C Library: Shared lib
ii  libkrb5-3             1.10+dfsg~beta1-2  MIT Kerberos runtime libraries
ii  libpam-runtime        1.1.1-6.1+squeeze1 Runtime support for the PAM librar
ii  libpam0g              1.1.1-6.1+squeeze1 Pluggable Authentication Modules l

libpam-krb5 recommends no packages.

libpam-krb5 suggests no packages.

-- no debconf information



--- End Message ---
--- Begin Message ---

The original poster was unable to provide enough info to reproduce.
Thanks for your attempt and I'm sorry we didn't have a better resolution
here.

--Sam

--- End Message ---

Reply via email to