Re: Decrypt integrity check failed

2006-07-10 Thread Marcus Watts
"Richard E. Silverman" <[EMAIL PROTECTED]> writes: ... > Check the key version number: > > # klist -k /etc/krb5.keytab > Keytab name: FILE:/etc/krb5.keytab > KVNO Principal > > -- > 14 host/[EMAIL PROTECTED] > > $ kvn

Re: Decrypt integrity check failed

2006-07-10 Thread Richard E. Silverman
> "jonr" == jonr <[EMAIL PROTECTED]> writes: jonr> Quoting "Richard E. Silverman" <[EMAIL PROTECTED]>: >> > "jonr" == jonr <[EMAIL PROTECTED]> writes: >> jonr> I have a slave kdc and am trying to get the master to kprop the jonr> db to the slave. I continually get th

Re: keytab wrecks login

2006-07-10 Thread Richard E. Silverman
> Debian Sarge > MIT Kerberos packages (1.3.6) > > I am clearly not understanding something about how kerberos operates. > If I add a principal to a keytab, I can no longer log in with a > password? Right: ktadd randomizes the key and increments the key version number. Instead, use "ktut

keytab wrecks login

2006-07-10 Thread Ron Peterson
Debian Sarge MIT Kerberos packages (1.3.6) I am clearly not understanding something about how kerberos operates. If I add a principal to a keytab, I can no longer log in with a password? ...password is working here... 1045# kadmin -p network/admin Authenticating as principal network/admin with pa

Re: Decrypt integrity check failed

2006-07-10 Thread jonr
Quoting "Richard E. Silverman" <[EMAIL PROTECTED]>: > > "jonr" == jonr <[EMAIL PROTECTED]> writes: > > jonr> I have a slave kdc and am trying to get the master to kprop the > jonr> db to the slave. I continually get this error: kprop: Decrypt > jonr> integrity check failed while

KERBEROS product

2006-07-10 Thread Sabine . DELAITRE
Dear contact, I send you this email in order to know if it is possible to have a specific contact in order to validate the data we collected about your product kerberos helping identity management. We are doing a study on IMS in the framework of FIDIS www.fidis.net and the stage aiming at vali

Re: Decrypt integrity check failed

2006-07-10 Thread Richard E. Silverman
> "jonr" == jonr <[EMAIL PROTECTED]> writes: jonr> I have a slave kdc and am trying to get the master to kprop the jonr> db to the slave. I continually get this error: kprop: Decrypt jonr> integrity check failed while getting initial ticket >> From what I have read it is a

Decrypt integrity check failed

2006-07-10 Thread jonr
I have a slave kdc and am trying to get the master to kprop the db to the slave. I continually get this error: kprop: Decrypt integrity check failed while getting initial ticket >From what I have read it is a wrong password for one of the hosts in the database. I have removed from the DB both of

Re: Getting list of supported enctypes

2006-07-10 Thread Love Hörnquist Åstrand
Arati Desai <[EMAIL PROTECTED]> writes: > Hi All, > > Can someone point me to list of supported enctypes > with heimdal? > > I am using heimdal 0.7 as kerberos client with my > application. I need to publish the list of supported > enctypes. I could not find them in the README. > > This command g

Use of clock_skew option on Client side krb5.conf file

2006-07-10 Thread sandypossible
Hi all, I have a query regaqrding specifying the clock_skew in the client side ( kerberos client) krb5.conf file. As I understand, the maximum allowable time skew is determined by KDC. Please let me know whether my understanding is correct. I want to understand the use of specifying the clock_sk