Issue with kvno

2015-05-26 Thread vishal
Hi, I see an issue with kvno with kerberos version 1.7 where linux server is sending the kvno to trusted domain as 4294967295 while it gets this as 255 from home domain. Is this an known issue? Thanks, Vishal Kerberos mailing list

Re: Issue with kvno

2015-05-28 Thread vishal
Hi, I did not get any answer for my query: " Hi, I see an issue with kvno with kerberos version 1.7 where linux server is sending the kvno to trusted domain as 4294967295 while it gets this as 255 from home domain. Is this an known issue? Thanks, Vishal" On Tue, May 26, 2015 a

Re: Issue with kvno

2015-05-29 Thread vishal
-DCs-td23528.html Should I try this fix? Thanks, Vishal On Fri, May 29, 2015 at 9:17 AM, Greg Hudson wrote: > Vishal found issue #7092 (worked around in 1.10.1) which may provide > some clues: > > http://krbdev.mit.edu/rt/Ticket/Display.html?id=7092 > http://mailman.mi

Re: Issue with kvno

2015-05-29 Thread vishal
, 2015 at 11:16 AM, vishal wrote: > Hi Greg, > > Thanks for reply. Let me explain this issue in detail: > > 1. Windows version is 2008r2 as domain controller. > > 2. We get the ticket in TGS-RESP with kvno 255, this TGS-REQ was sent for > krbtgt for trusted domain from lin

Re: Issue with kvno

2015-05-29 Thread vishal
It should be -1, wirehark shows as ff. What do you mean by not easily portable? I would do just do: + FIELDOF_OPT(krb5_enc_data, int32, kvno, 1, 1), Would it have any side effect? On Fri, May 29, 2015 at 11:21 AM, Greg Hudson wrote: > On 05/29/2015 02:16 PM, vishal wrote: > > 1

Re: Issue with kvno

2015-05-29 Thread vishal
So this fix works fine. I tried it ..it sends ff to trusted domain. is it safe to do this fix? can you please reply. On Fri, May 29, 2015 at 11:31 AM, vishal wrote: > It should be -1, wirehark shows as ff. > > What do you mean by not easily portable? > > I would do just do:

Re: Issue with kvno

2015-05-29 Thread vishal
yes. > > On 05/29/2015 05:27 PM, vishal wrote: > > So this fix works fine. I tried it ..it sends ff to trusted domain. > > > > is it safe to do this fix? can you please reply. > > > > On Fri, May 29, 2015 at 11:31 AM, vishal > <mailto:vicky.r...@gmail.com>>

Re: Issue with kvno

2015-05-29 Thread vishal
be there in ticket? I hope it is clear. On Fri, May 29, 2015 at 5:20 PM, Benjamin Kaduk wrote: > On Fri, 29 May 2015, vishal wrote: > > > can someone please reply to this as well just for my understaning: > > > > why do i see kvno in ticket only when i create new t

end of key table reached error

2015-10-29 Thread vishal
Hi, We are getting below error during session setup: GSS-API error calling gss_accept_sec_context: -1765328202 (End of key table reached) What can be probable reason for this? Thanks, Vishal Kerberos mailing list Kerberos@mit.edu

Re: end of key table reached error

2015-10-30 Thread vishal
I think there is some issue with keytab file , I see multiple kvno in keytab i.e 74 & 75. Is it practical?We have 1.7 release. On Thu, Oct 29, 2015 at 3:40 PM, Greg Hudson wrote: > On 10/29/2015 04:14 PM, vishal wrote: > > GSS-API error calling gss_accept_sec_context: -176532820

Decrypt integrity check failed

2017-11-13 Thread vishal
ehave like it? --Vishal Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos