Linux NFS development
 help / color / mirror / Atom feed
* Problems with kerberos auth  - possibly against ADS - since nfs-utils-1.2.3
@ 2011-08-03 23:21 NeilBrown
  2011-08-04  0:51 ` Kevin Coffman
  0 siblings, 1 reply; 11+ messages in thread
From: NeilBrown @ 2011-08-03 23:21 UTC (permalink / raw)
  To: linux-nfs


Hi, 
 I have some reports of problems with kerberos auth in openSUSE 11.4 (using
 1.2.3) which can be fixed by using the openSUSE 11.3 version of rpc.gssd
 (from 1.2.1).

https://bugzilla.novell.com/show_bug.cgi?id=614293

 The important difference seems to be the list of enc_types used in
 limit_krb5_enctypes.

 In 1.2.1 this list is hard coded in the rpc.gssd to 1,3,2 (I think).
 In 1.2.3 this list is taken from the kernel where is it hard coded
  to  18,17,16,23,3,1,2.
 When I patch the 11.4 code to use the old enctype list, it works perfectly.

 So presumably it ends up negotiating one of those other enc_types and
 gets confused by it.

 I'll try to get a comparative tcp dump to see if that helps, but
 if anyone has any idea what the problem might be I'd love to hear
 suggestions.

 The systems are running a 2.6.37 kernel in case that might make a difference.

Thanks,
NeilBrown

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2011-08-23 19:48 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-08-03 23:21 Problems with kerberos auth - possibly against ADS - since nfs-utils-1.2.3 NeilBrown
2011-08-04  0:51 ` Kevin Coffman
2011-08-04  1:13   ` NeilBrown
2011-08-04  2:57     ` Kevin Coffman
2011-08-11  5:42       ` NeilBrown
2011-08-11 14:06         ` Kevin Coffman
2011-08-18  9:19           ` NeilBrown
2011-08-18 16:43             ` J. Bruce Fields
2011-08-23  0:16               ` NeilBrown
2011-08-23  0:41                 ` Kevin Coffman
2011-08-23 19:48                 ` J. Bruce Fields

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox