TGS-REQ failed with INVALID TGS OPTION after using krb5-1.3.1 + patch for cross-referral

Lara Adianto m1r4cle_26 at yahoo.com
Sun May 30 08:48:13 EDT 2004


Hi,

I have a strange problem. 
I was able to authenticate win2k machine to MIT KDC
(krb5-1.3.2) but since I need to apply the patch from
u of michingan to resolve the cross-realm referral
issue, I switch to krb5-1.3.1 (the patch is for
krb5-1.3.1).

However after uncompressing the file, applying the
patch, building and installing it successfully, I
encountered a TGS-REQ error when the win2k tried to
authenticate to the MIT krb5-1.3.1 KDC. The AS-REQ
seems okay. 
Anyway, the log file says:
May 30 20:39:46 kerberos.adianto.com
krb5kdc[838](info): TGS_REQ (7 etypes {23 -133 -128 3
1 24 -135}) 192.168.168.94: INVALID TGS OPTIONS:
authtime 1085920786, lara at ADIANTO.COM for
host/testw2k8.adianto.com at ADIANTO.COM, KDC can't
fulfill requested option

I didn't change any configuration made by ksetup in
the win2k machine as well as my krb5.conf & kdc.conf
file.

What's the possible cause this of this problem ? 

Regards,
Lara

=====
------------------------------------------------------------------------------------ 
La vie, voyez-vous, ca n'est jamais si bon ni si mauvais qu'on croit
                                                                        - Guy de Maupassant -
------------------------------------------------------------------------------------


	
		
__________________________________
Do you Yahoo!?
Friends.  Fun.  Try the all-new Yahoo! Messenger.
http://messenger.yahoo.com/ 


More information about the Kerberos mailing list