[Samba] Kerberos enc type [xx] failed

Ephi Dror ephi at agami.com
Fri Jun 17 21:09:10 GMT 2005


Hi All,

Little update:

After installing kerberos 1.3.3 recompiling samba against those
libs/include the problem went away!!

I am a little unclear regarding what really needed to be put in
krb5.conf

At the moment I have them as  suggested by Dimitri
>  default_tkt_enctypes = des-cbc-crc des-cbc-md5
>  default_tgs_enctypes = des-cbc-crc des-cbc-md5

So I don't understand what those defaults do, why put any default, and
why encryption type that is not put in there should have a problem.

Also, if I do need to list all supported etypes, what are they?

What are all possible etypes that windows 200x using?

And one more question. Does Kerberos has important files similar to
secrets.tdb that are kept even after reboot and where does Kerberos keep
them.

Thanks again for the wonderful support in this complicated issue,

Cheers,
Ephi


-----Original Message-----
From: Andrew Bartlett [mailto:abartlet at samba.org] 
Sent: Tuesday, June 14, 2005 8:03 PM
To: Ephi Dror
Cc: samba at lists.samba.org
Subject: RE: [Samba] Kerberos enc type [xx] failed

On Tue, 2005-06-14 at 19:04 -0700, Ephi Dror wrote:
> Hi Andrew,
> 
> I upgraded krb5 libs to 1.3.3 and now the error became "Decrypt 
> integrity check failed".

Just checking, have you rebuilt Samba against the new libs/headers?

We detect the older libs, and do workarounds that you don't want any
more.  

Also, how did you upgrade the kerberos libs.  I meant to say in my
original mail that it is known to be a very painful process, so I wonder
if the libs you installed are the ones you are using.  Check what
configure said, and what ldd says. 

Andrew Bartlett

-- 
Andrew Bartlett
http://samba.org/~abartlet/
Samba Developer, SuSE Labs, Novell Inc.        http://suse.de
Authentication Developer, Samba Team           http://samba.org
Student Network Administrator, Hawker College  http://hawkerc.net


More information about the samba mailing list