allow_weak_enctypes=false and AFS

Russ Allbery rra at
Wed Jan 20 13:37:57 EST 2010

Greg Hudson <ghudson at> writes:

> I am having trouble reproducing this problem using kvno.  In the Debian
> bug report, a reference is made to "the kdc log saying that the
> principal simply doesn't exist."  But from the code and my experiments,
> you get a "KDC has no support for encryption type" message in both the
> log and on the client.  That message could probably be improved on, at
> least in the log, but I feel like I'm not testing the right thing.

Hm, I can't duplicate it either.  I get the right error message from kvno
and in the KDC log even on a 1.4 KDC.

aklog bombs out on the error message, but as I mentioned to Thomas, that's
a problem with aklog that we can fix there, not a problem with the
Kerberos libraries.

Russ Allbery (rra at             <>

More information about the krbdev mailing list