problem with pam_krb5 4.2-1

Russ Allbery rra at stanford.edu
Fri May 14 18:37:12 EDT 2010


Rohit Kumar Mehta <rohitm at engr.uconn.edu> writes:

> I think the best (and most secure) practice would be to regenerate all
> the keytabs and the trust, so I'll tackle it next week.

Okay, yes, that's true.  :)

I suspect that the problem is that the intermediate KDC is rejecting the
cross-realm authentication because the cross-realm ticket is DES.

-- 
Russ Allbery (rra at stanford.edu)             <http://www.eyrie.org/~eagle/>



More information about the Kerberos mailing list