PKINIT with PA-PK-AS-REQ_OLD fails with ASN1_CHECK_TLEN:wrong tag

2017-02-01 Thread Jacques Henry
Hello, I am using kinit (krb5-1.15) from an Ubuntu 14.04 64bits using a smartcard in a PINPAD reader. The KDC is an Active Directory Windows 2012 R2. If I enter the PIN code correctly the first time, it works like a charm. However if I try again (after a kdestroy) by entering a wrong PIN the fir

Re: PKINIT with PA-PK-AS-REQ_OLD fails with ASN1_CHECK_TLEN:wrong tag

2017-02-02 Thread Jacques Henry
> > 1. The old draft9 support isn't intended to be used as a wrong-PIN > fallback; it is only there for interoperability with old PKINIT > implementations. It might be time to remove that support, since Windows > Server 2003 hit the end of its extended support life in 2015. > When talking to the