[OpenAFS-devel] Suggestions to avoid troubling using Kerberos 5 with OpenAFS

Sam Hartman hartmans@mekinok.com
11 Nov 2001 01:40:52 -0500


    Jim> Cause: aklog is fetching a AFS service key of the wrong
    Jim> encryption type ; it stuffs the 8-byte session key into to
    Jim> Kernel's KTC -- however, unless this is a DES-CBC-CRC32 key ;
    Jim> it will fail to do what needs to happen.

At least in the 1.2.2 version of the krb524 library I have (and which
aklog uses), the library forces getting a ENCTYPE_DES_CBC_CRC ticket.
It would be interesting if you can reproduce your problem against
stock Kerberos 1.2.2 rather than the Redhat version.