>>>>> "Donn" == Donn Cave <[EMAIL PROTECTED]> writes:

    Donn> Quoth [EMAIL PROTECTED] (Digant Kasundra):
    Donn> | Well, for some reason, I'm not getting good results.  getting a ticket with
    Donn> | kinit on the heimdal side works great if I specify a password.  But when
    Donn> | using a keytab, it will only work if I tell it manually what encryption 
type
    Donn> | to use, even though ktutil identifies the enc type correctly when listing
    Donn> | the keys in that keytab.
    Donn> |
    Donn> | I think this is the major contributor to my gssapi bind failing on 
openldap.

    Donn> The way I remember it, Heimdal looks for different keywords in the
    Donn> /etc/krb5.conf configuration file.  I forget which is whose, but ours
    Donn> now looks like

Heimdal is default_etypes; the rest are MIT config values.

But please don't specify any of the above.  None of them should be
needed with even moderately recent versions of the code in a correctly
configured realm.

________________________________________________
Kerberos mailing list           [EMAIL PROTECTED]
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to