### Verification Done Noble ###
See attached verification-noble.txt for details on the Ubuntu setup (as
described in setup.md).
wesley@n1:~$ apt policy krb5-user
krb5-user:
Installed: 1.20.1-6ubuntu2.8
Candidate: 1.20.1-6ubuntu2.8
Version table:
*** 1.20.1-6ubuntu2.8 100
100 http://archive.ubuntu.com/ubuntu noble-proposed/universe amd64
Packages
100 /var/lib/dpkg/status
1.20.1-6ubuntu2.7 500
500 http://archive.ubuntu.com/ubuntu noble-updates/universe amd64
Packages
500 http://security.ubuntu.com/ubuntu noble-security/universe amd64
Packages
1.20.1-6ubuntu2 500
500 http://archive.ubuntu.com/ubuntu noble/universe amd64 Packages
wesley@n1:~$ sudo KRB5_TRACE=/dev/stderr kinit -V -X
X509_user_identity='PKCS11:' [email protected]
Using default cache: /tmp/krb5cc_0
Using principal: [email protected]
PA Option X509_user_identity = PKCS11:
[9105] 1785858201.393932: Getting initial credentials for [email protected]
[9105] 1785858201.393934: Sending unauthenticated request
[9105] 1785858201.393935: Sending request (175 bytes) to TEST.SE
[9105] 1785858201.393936: Initiating TCP connection to stream 10.167.27.2:88
[9105] 1785858201.393937: Sending TCP request to stream 10.167.27.2:88
[9105] 1785858201.393938: Received answer (260 bytes) from stream 10.167.27.2:88
[9105] 1785858201.393939: Terminating TCP connection to stream 10.167.27.2:88
[9105] 1785858201.393940: Response was from primary KDC
[9105] 1785858201.393941: Received error from KDC: -1765328359/Additional
pre-authentication required
[9105] 1785858201.393944: Preauthenticating using KDC method data
[9105] 1785858201.393945: Processing preauth types: PA-PK-AS-REQ (16),
PA-PK-AS-REP_OLD (15), PA-ETYPE-INFO2 (19), 111, PA-ENC-TIMESTAMP (2)
[9105] 1785858201.393946: Selected etype info: etype aes256-cts, salt
"TEST.SEwesley", params ""
[9105] 1785858201.393947: PKINIT loading identity PKCS11:
[9105] 1785858201.393948: PKINIT opening PKCS#11 module "opensc-pkcs11.so"
[9105] 1785858202.070137: PKINIT PKCS#11 slotid 0 token Users
[9105] 1785858202.070138: PKINIT opening PKCS#11 module "opensc-pkcs11.so"
[9105] 1785858202.070139: PKINIT PKCS#11 slotid 0 token Users
Users PIN:
[9105] 1785858205.363251: PKINIT loading CA certs and CRLs from FILE
/etc/sssd/pki/sssd_auth_ca_db.pem
[9105] 1785858205.363252: PKINIT client computed checksums:
B0A0E9D2C013C8991B2215218163434C9857B344
DABD9A5C878240DEEF84192CC2047DC4F42C0220ECB1318CA018E7C489856D5C
[9105] 1785858205.363254: PKINIT client making DH request
[9105] 1785858205.363255: PKINIT chain cert #0:
/DC=se/DC=test/CN=Users/CN=Wesley D. Hershberger
[9105] 1785858205.363256: Preauth module pkinit (16) (real) returned: 0/Success
[9105] 1785858205.363257: Produced preauth for next request: PA-PK-AS-REQ (16)
[9105] 1785858205.363258: Sending request (3457 bytes) to TEST.SE
[9105] 1785858205.363259: Initiating TCP connection to stream 10.167.27.2:88
[9105] 1785858205.363260: Sending TCP request to stream 10.167.27.2:88
[9105] 1785858205.363261: Received answer (4140 bytes) from stream
10.167.27.2:88
[9105] 1785858205.363262: Terminating TCP connection to stream 10.167.27.2:88
[9105] 1785858205.363263: Response was from primary KDC
[9105] 1785858205.363264: Processing preauth types: PA-PK-AS-REP (17)
[9105] 1785858205.363265: PKINIT client verified DH reply
[9105] 1785858205.363266: PKINIT client config accepts KDC dNSName SAN
win-64up1dm1tnf.test.se
[9105] 1785858205.363267: PKINIT client found 2 SANs (0 princs, 0 UPNs, 1 DNS
names) in certificate /CN=WIN-64UP1DM1TNF.test.se
[9105] 1785858205.363268: PKINIT client found dNSName SAN in KDC cert:
WIN-64UP1DM1TNF.test.se
[9105] 1785858205.363269: PKINIT client matched KDC hostname
WIN-64UP1DM1TNF.test.se against dNSName SAN; EKU check still required
[9105] 1785858205.363270: PKINIT found acceptable EKU and digitalSignature KU
[9105] 1785858205.363271: PKINIT client found acceptable EKU in KDC cert
[9105] 1785858205.363272: PKINIT client used octetstring2key to compute reply
key aes256-cts/3350
[9105] 1785858205.363273: Preauth module pkinit (17) (real) returned: 0/Success
[9105] 1785858205.363274: Produced preauth for next request: (empty)
[9105] 1785858205.363275: AS key determined by preauth: aes256-cts/3350
[9105] 1785858205.363276: Decrypted AS reply; session key is: aes256-cts/F754
[9105] 1785858205.363277: FAST negotiation: unavailable
[9105] 1785858205.363278: Resolving unique ccache of type MEMORY
[9105] 1785858205.363279: Initializing MEMORY:44Ebtet with default princ
[email protected]
[9105] 1785858205.363280: Storing config in MEMORY:44Ebtet for
krbtgt/[email protected]: pa_type: 16
[9105] 1785858205.363281: Storing [email protected] ->
krb5_ccache_conf_data/pa_type/krbtgt\/TEST.SE\@TEST.SE@X-CACHECONF: in
MEMORY:44Ebtet
[9105] 1785858205.363282: Storing config in MEMORY:44Ebtet for
krbtgt/[email protected]: pa_config_data: {"X509_user_identity":"PKCS11:"}
[9105] 1785858205.363283: Storing [email protected] ->
krb5_ccache_conf_data/pa_config_data/krbtgt\/TEST.SE\@TEST.SE@X-CACHECONF: in
MEMORY:44Ebtet
[9105] 1785858205.363284: Storing [email protected] -> krbtgt/[email protected] in
MEMORY:44Ebtet
[9105] 1785858205.363285: Moving ccache MEMORY:44Ebtet to FILE:/tmp/krb5cc_0
[9105] 1785858205.363286: Destroying ccache MEMORY:44Ebtet
Authenticated to Kerberos v5
### Verification Done Noble ###
** Attachment added: "verification-noble.txt"
https://bugs.launchpad.net/ubuntu/+source/krb5/+bug/2161440/+attachment/5989439/+files/verification-noble.txt
** Tags removed: verification-needed-noble
** Tags added: verification-done-noble
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2161440
Title:
Smartcard auth with Windows Server 2025 fails with "Checksum must be
included"
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/krb5/+bug/2161440/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs