[Samba] ads_sasl_spnego_krb5_bind failed: Program lacks support for encryption type [SEC=UNCLASSIFIED]
Dale Schroeder
dale at BriannasSaladDressing.com
Wed Feb 17 06:49:25 MST 2010
> Reply to list/user gets me again! Anyway, we are at 2008 functional level,
> so I don't think our domain is even accepting DES. It looks like Debian has
> a fix in libkrb5 that has another two days in sid, then will be migrated to
> Squeeze.
That's the best news I've had in days. I noticed that the original
reporter of the bug had success with
1.8 alpha1-6, and the version soon to be in squeeze is already beyond
that at alpha 1-7.
> I think that will fix the problem (crossing fingers)
As am I.
> as RC4-HMAC is
> listed as an acceptable encryption type and the bug in kerberos was dropping
> the entire ecnryption request if DES was one of the encryption types. I
> think the fix now only drops the DES encryption types out of the available
> list. So in my krb5.conf.NETBIOSNAME example above, if the DCs don't like
> RC4-HMAC, then I'm out of luck as it won't try DES even though it is listed.
>
> Thanks for the reply.
>
> Robert LeBlanc
> Life Sciences& Undergraduate Education Computer Support
> Brigham Young University
>
Many thanks to Sam Hartman, Steve Langasek, Christian Perrier, and all
the other individuals who got
this fix expedited.
Dale
More information about the samba
mailing list