From owner-freebsd-stable@FreeBSD.ORG Tue Oct 7 14:57:02 2008 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 930ED1065689 for ; Tue, 7 Oct 2008 14:57:02 +0000 (UTC) (envelope-from mike@sentex.net) Received: from smarthost1.sentex.ca (smarthost1.sentex.ca [64.7.153.18]) by mx1.freebsd.org (Postfix) with ESMTP id 43D4D8FC0A for ; Tue, 7 Oct 2008 14:57:02 +0000 (UTC) (envelope-from mike@sentex.net) Received: from lava.sentex.ca (pyroxene.sentex.ca [199.212.134.18]) by smarthost1.sentex.ca (8.14.3/8.14.3) with ESMTP id m97Euo9w071623; Tue, 7 Oct 2008 10:56:50 -0400 (EDT) (envelope-from mike@sentex.net) Received: from mdt-xp.sentex.net (simeon.sentex.ca [192.168.43.27]) by lava.sentex.ca (8.13.8/8.13.3) with ESMTP id m97Eun8J064681 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 7 Oct 2008 10:56:50 -0400 (EDT) (envelope-from mike@sentex.net) Message-Id: <200810071456.m97Eun8J064681@lava.sentex.ca> X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9 Date: Tue, 07 Oct 2008 10:56:50 -0400 To: Galen Sampson , Gunnar Flygt , FreeBSD Stable From: Mike Tancsa In-Reply-To: <48EA820F.1030109@gmail.com> References: <20081006140255.GA74575@sr.se> <48EA820F.1030109@gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed X-Scanned-By: MIMEDefang 2.64 on 64.7.153.18 Cc: Subject: Re: Possibility of backporting of Heimdal 1.1 X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 07 Oct 2008 14:57:02 -0000 At 05:24 PM 10/6/2008, Galen Sampson wrote: >I would like to second that. The heimdal in 7.0 is quite old. It >is in fact inoperable with an mit kerberos realm when using >ssh. The byte order is incorrect such that you get MIC checksum >failures. After much googling (not documented in the krb5.conf man >page or handbook) I found that a fix was added in the heimdal in >7.0, but defaults to the old incompatible byte order. The heimdal >in current uses the correct byte order by default. For those having >the this issue with freebsd 7.0 the fix is adding the following >lines to /etc/krb5.conf: > >[gssapi] >correct_des3_mic = host/*@SOME.REALM > >Gunnar Flygt wrote: >>Is there any possibility that heimdal 1.1 that works beautifully in >>Current will be backported to FreeBSD-7.x? >> >>Gunnar Flygt >>Sveriges Radio Teknik/IT I think someone mentioned the possibility of post 7.1R. But not 100% sure ---Mike