[squid-users] Kerberos authentication problem - squid 3.4.11

Ludovit Koren ludovit.koren at gmail.com
Wed Feb 11 15:09:31 UTC 2015


>>>>> Markus Moeller <huaraz at moeller.plus.com> writes:

    > Hi Ludovit,
    >  Which Kerberos library version do you use ?    Is it possible that
    > the encryption types don't match ?  I saw in your first email the
    > following:

It is standard Heimdal library on FreeBSD:
# kinit --version
kinit (Heimdal 1.5.2)
Copyright 1995-2011 Kungliga Tekniska Högskolan
Send bug-reports to heimdal-bugs at h5l.org

FreeBSD 10.1-STABLE #1 r275861

    > Your klist shows a HTTP ticket for arcfour

    > Server: HTTP/squid1.mdpt.local at MDPT.LOCAL
    > Client: HTTP/squid1.mdpt.local at MDPT.LOCAL
    > Ticket etype: arcfour-hmac-md5, kvno 8
    > Ticket length: 1090
    > Auth time:  Feb  9 14:55:18 2015
    > Start time: Feb  9 14:55:20 2015
    > End time:   Feb 10 00:55:18 2015
    > Ticket flags: enc-pa-rep, pre-authent
    > Addresses: addressless

    > but the keytab has aes128.

    > # ktutil -k /etc/krb5.keytab list
    > /etc/krb5.keytab:

    > Vno  Type                     Principal                          Aliases
    >  8  aes128-cts-hmac-sha1-96  HTTP/squid1.mdpt.local at MDPT.LOCAL


You are right... I tried to find out how to change it. Is it option on
KDC server? I am not able to find anything relevant. 


lk


More information about the squid-users mailing list