Interoperability of Solaris 9 SEAM and MIT Kerberos on Cisco IOS

From: Debbie Tropiano (debbie@icus.com)
Date: Mon Jun 24 2002 - 12:06:54 EDT


Folks -
                                          
We have a Solaris 9 system with SEAM (Sun's version of Kerberos)
configured and running as the KDC. We also have a Cisco router
with MIT Kerberos, and want to authenticate against the Solaris 9
KDC server, but keep getting errors on the Sun system such as:
  
Jun 24 07:32:28 sol9.xxxxx.xxxxxx.xxx krb5kdc[1904](info): AS_REQ
10.7.1.11(88): ISSUE: authtime 1024921948, jcl@NDL.MSN for
krbtgt/NDL.MSN@NDL.MSN
Jun 24 07:32:28 sol9.xxxxx.xxxxxx.xxx krb5kdc[1904](info): TGS_REQ
10.7.1.11(88): PROCESS_TGS: authtime 0, jcl@NDL.MSN for
host/cygnus-eth0.xxxxx.xxxxxx.xxx@NDL.MSN, KDC has no support for checksum
type

(I've X'd out our domain for confidentiality reasons.)

Is it possible to authenticate with MIT Kerberos clients against
a SEAM KDC server? Does this appear to be a configuration error?
Or a limitation of SEAM?

We're just getting started with Kerberos/SEAM, so please be gentle. :-)

Thanks for any help,
Debbie

-- 
+== Debbie Tropiano ==  Mommy to Nathan 8/17/95 & ^Sara^ 10/25/00-11/7/00 ==+
|	God shows His opposition to cancer and birth defects, not by        |
|	eliminating them or making them happen only to bad people (He       |
|	can't do that), but by summoning forth friends and neighbors to     |
|	ease the burden and to fill the emptiness.  -- Harold S. Kushner    |
+== debbie@icus.com  =============  URL http://www.icus.com/personal.html ==+
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers


This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:24:30 EDT