[Samba] ads_sasl_spnego_krb5_bind failed: Program lacks support for encryption type [SEC=UNCLASSIFIED]

Dale Schroeder dale at BriannasSaladDressing.com
Wed Feb 17 06:49:25 MST 2010

> Reply to list/user gets me again! Anyway, we are at 2008 functional level,
> so I don't think our domain is even accepting DES. It looks like Debian has
> a fix in libkrb5 that has another two days in sid, then will be migrated to
> Squeeze.
That's the best news I've had in days.  I noticed that the original 
reporter of the bug had success with
1.8 alpha1-6, and the version soon to be in squeeze is already beyond 
that at alpha 1-7.
> I think that will fix the problem (crossing fingers)
As am I.
>   as RC4-HMAC is
> listed as an acceptable encryption type and the bug in kerberos was dropping
> the entire ecnryption request if DES was one of the encryption types. I
> think the fix now only drops the DES encryption types out of the available
> list. So in my krb5.conf.NETBIOSNAME example above, if the DCs don't like
> RC4-HMAC, then I'm out of luck as it won't try DES even though it is listed.
> Thanks for the reply.
> Robert LeBlanc
> Life Sciences&  Undergraduate Education Computer Support
> Brigham Young University
Many thanks to Sam Hartman, Steve Langasek, Christian Perrier, and all 
the other individuals who got
this fix expedited.


