CANT_FIND_CLIENT_KEY

Russ Allbery rra at stanford.edu
Tue Mar 30 17:46:24 EDT 2010


Matt Zagrabelny <mzagrabe at d.umn.edu> writes:

> Thanks for the quick help, Russ. Still the same problem, though.

> # grep -B1 allow_weak_crypto /etc/krb5.conf
> [libdefaults]
>     allow_weak_crypto = true

> # /etc/init.d/krb5-kdc restart

> % telnet blah...

> AS_REQ (1 etypes {1}) 10.25.1.14: CANT_FIND_CLIENT_KEY:
> mzagrabe at D.UMN.EDU for krbtgt/D.UMN.EDU at D.UMN.EDU, KDC has no support
> for encryption type

> Any other ideas?

You need it on the client in addition to the server.

-- 
Russ Allbery (rra at stanford.edu)             <http://www.eyrie.org/~eagle/>



More information about the Kerberos mailing list