[Fwd: Re: AD MIT Interoperability rc4-hmac]

rousset denis.rousset at cea.fr
Mon Feb 16 04:13:54 EST 2004



KDC MIT 1.3.1(same pb with 1.3.2beta), and yes, the user principal in
the MIT KDC have a key of type RC4-HMAC. (It work without preauth attribute)

Denis Rousset

Jeffrey Altman a écrit:

 > Which version of MIT Kerberos is the KDC?
 >
 > And more importantly, does the user principal in the MIT KDC have a key
 > of type RC4-HMAC associated with it?
 >
 > Jeffrey Altman
 >
 >
 > rousset wrote:
 >
 >> Hello,
 >>
 >> I have established a trust relationship between Active Directory and
 >> MIT Kerberos realm, mapped principals, and can successfully logon to
 >> a Win2k workstation using a Kerberos principal. This is right with
 >> attribute "PRE-AUTH required" enabled and encryption des-cbc-crc, or
 >> md5.
 >> But I'd like to set rc4-hmac as default encryption on MIT principals.
 >> It fails with "Additionnal Pre-authentication required" log on MIT's
 >> side if pre-auth is enabled
 >> (Work if pre-auth disabled)
 >>
 >>
 >> Thanks
 >> Denis
 >>
 >>
 >>
 >>
 >> ________________________________________________
 >> Kerberos mailing list           Kerberos at mit.edu
 >> https://mailman.mit.edu/mailman/listinfo/kerberos
 >>
 >
 >






More information about the Kerberos mailing list