krb5-1.8 fails to verify MS PAC Checksum when AES 256 is used causing sshd to fail

Tom Yu tlyu at MIT.EDU
Thu Jul 1 18:04:59 EDT 2010

Luke Howard <lukeh at> writes:

>> Thanks for the quick response of a patch. I applied the patch to 1.8 for testing
>> with some changes to replace the "for" with an if and while loop. See attached patch
>> with some additional debuging output added.
> Again untested, but see attached, replaces previous patch.

Could you please inline your patches as plain text?  Our mailing list
software can strip out some attachments, and that appears to have
happened here.  (Doug, you may have seen it anyway because you were
directly copied by Luke.)

More information about the krbdev mailing list