[Samba] Kerberos enc type [xx] failed

Ephi Dror ephi at agami.com
Fri Jun 17 21:09:10 GMT 2005

Hi All,

Little update:

After installing kerberos 1.3.3 recompiling samba against those
libs/include the problem went away!!

I am a little unclear regarding what really needed to be put in

At the moment I have them as  suggested by Dimitri
>  default_tkt_enctypes = des-cbc-crc des-cbc-md5
>  default_tgs_enctypes = des-cbc-crc des-cbc-md5

So I don't understand what those defaults do, why put any default, and
why encryption type that is not put in there should have a problem.

Also, if I do need to list all supported etypes, what are they?

What are all possible etypes that windows 200x using?

And one more question. Does Kerberos has important files similar to
secrets.tdb that are kept even after reboot and where does Kerberos keep

Thanks again for the wonderful support in this complicated issue,


-----Original Message-----
From: Andrew Bartlett [mailto:abartlet at samba.org] 
Sent: Tuesday, June 14, 2005 8:03 PM
To: Ephi Dror
Cc: samba at lists.samba.org
Subject: RE: [Samba] Kerberos enc type [xx] failed

On Tue, 2005-06-14 at 19:04 -0700, Ephi Dror wrote:
> Hi Andrew,
> I upgraded krb5 libs to 1.3.3 and now the error became "Decrypt 
> integrity check failed".

Just checking, have you rebuilt Samba against the new libs/headers?

We detect the older libs, and do workarounds that you don't want any

Also, how did you upgrade the kerberos libs.  I meant to say in my
original mail that it is known to be a very painful process, so I wonder
if the libs you installed are the ones you are using.  Check what
configure said, and what ldd says. 

Andrew Bartlett

Andrew Bartlett
Samba Developer, SuSE Labs, Novell Inc.        http://suse.de
Authentication Developer, Samba Team           http://samba.org
Student Network Administrator, Hawker College  http://hawkerc.net

More information about the samba mailing list