Kadmin compatibility

Derek Yarnell derek at umiacs.umd.edu
Fri Jun 17 17:38:25 EDT 2011


On 6/17/11 5:33 PM, Tom Yu wrote:
> Derek Yarnell <derek at umiacs.umd.edu> writes:
> 
>> So currently we have a RHEL4 krb5-server-1.3.4-62.el4_8.2 kadmind
>> running. The new RHEL6 krb5-workstation-1.9-9.el6 kadmin client can not
>> connect to the kadmind server,
> 
>> kadmind[5009](Notice): Authentication attempt failed: x.x.x.x, GSS-API
>> error strings are:
>> kadmind[5009](Notice): Authentication attempt failed: x.x.x.x, GSS-API
>> error strings are:
>> kadmind[5009](Notice):     Incorrect channel bindings were supplied
>> kadmind[5009](Notice):     Incorrect channel bindings were supplied
>> kadmind[5009](Notice):     No error
>> kadmind[5009](Notice):     No error
>> kadmind[5009](Notice):    GSS-API error strings complete.
>> kadmind[5009](Notice):    GSS-API error strings complete.
> 
> This is probably a known bug that is a side effect of some IPv6
> changes to the RPC library in the krb5-1.9 release.  It should be
> fixed in the upcoming krb5-1.9.2 release.
> 
>     http://krbdev.mit.edu/rt/Ticket/Display.html?id=6920
> 

Thanks Tim for the idea, though it work.

Thanks Tom for the note, now to hopefully get Red Hat to patch this in a
timely manor.

-- 
---
Derek T. Yarnell
University of Maryland
Institute for Advanced Computer Studies



More information about the Kerberos mailing list