f



Key table entry not found-this time with Heimdal

Hello,

this is the same setup like in my previous post from this month,but this
time I'm using heimdal-clients.I have removed all of the MIT packages that I
have installed: krb5-user,krb5-clients.

I have Virtual Network configured to use Kerberos authentication.The
setup is as follows:
Windows Server 2008 Standard SP2 (DC,DNS) (FQDN) labserver.lab.com;
Debian Linux 5.0(lenny) (WebServer-Apache) (FQDN) debian.lab.com;
Windows XP Prof. (client) (FQDN) zdravko.lab.com;

[Windows Server 2008 Settings]

They are in the DNS lookup zone.I create one test user account for
accessing the client machine under given

domain(lab.com).The user name is "zdravko1" and its password never
expires,and it's not going to be prompted for

changing.After that I create one "dummy" user which will be used for
SPN(service principal name mapping to it).It's called

"http" and the same flags are used as in "zdravko1":

-User cannot change password;
-Password never expires;
-This account supports AES 256 bit encryption;

I continued with creating the keytab file:

c:\>ktpass /princ HTTP/debian.lab.com@LAB.COM <http://lab.com/> /mapuser
http@LAB.COM
/pass Debian26 /crypto AES256-SHA1 /ptype KRB5_NT_PRINCIPAL /out http.keytab

Keytab version: 0x502
keysize 78 HTTP/debian.lab.com@LAB.COM <http://lab.com/> ptype 1
(KRB5_NT_PRINCIPAL) vno 3 etype 0x12 (AES256-SHA1) keylength 32 (0x......)

The keytab is successfully created and I have checked it with the
following command:c:\>setspn -L http->I have the service

principal name:HTTP/debian.lab.com registered to it.
I copy the "http.keytab" file via pscp to the Debian box in
/etc/apache2/keytab/ directory.

[Debian 5.0 Settings]

In /etc/hosts file in Debian I've deleted the "127.0.0.1" line and
replaced it with:"192.168.100.103 debian.lab.com debian";
192.168.100.103 is the linux box's IP.

In /etc/resolf.conf file I have made the following changes:
domain lab.com
search lab.com
nameserver 192.168.100.102
192.168.100.102 is the DNS's IP.

The packages versions are the following:
heimdal-clients:1.2.dfsg.1-2.1;
libapache2-mod-auth-kerb:5.3-5;

The following lines will be from /etc/krb5.conf :

[libdefaults]
default_realm = LAB.COM <http://lab.com/>
default_tgs_enctypes = aes256-cts-hmac-sha1-96
default_tkt_enctypes = aes256-cts-hmac-sha1-96
permitted_enctypes = aes256-cts-hmac-sha1-96

[realms]
LAB.COM <http://lab.com/> = {
kdc = 192.168.100.102
admin_server = 192.168.100.102
}

[domain_realm]
..lab.com = LAB.COM <http://lab.com/>
lab.com = LAB.COM <http://lab.com/>

[login]
krb4_convert = true
krb4_get_tickets = false

The following lines will be from /etc/apache2/sites-enabled/000-default

<VirtualHost *:80>
      ServerAdmin webmaster@localhost

      DocumentRoot
<Directory /var/www/>
AuthType Kerberos
KrbMethodNegotiate on
KrbMethodK5Passwd off
KrbAuthRealms LAB.COM <http://lab.com/>
Krb5Keytab /etc/apache2/keytab/http.keytab
KrbVerifyKDC on
KrbServiceName Any
AuthName "Kerberos Login"
Require valid-user
Options FollowSymLinks
AllowOverride None
</Directory>

I did testing in Debian with the "kinit","klist -v" :

*[debian:/]kinit zdravko1*
zdravko1@LAB.COM' S password:Debian26
*[debian:/]klist*
Credentials cache: FILE:/tmp/krb5cc_0
       Principal: zdravko1@LAB.COM

 Issued           Expires          Principal
Aug 27 11:53:02  Aug 27 21:53:01  krbtgt/LAB.COM
<http://lab.com/>@LAB.COM<http://lab.com/>
*[debian:/]klist -v*
Credentials cashe: FILE:/tmp/krb5cc_0
       Principal: zdravko1@LAB.COM
   Cache version: 4

Server: krbtgt/LAB.COM <http://lab.com/>@LAB.COM <http://lab.com/>
Client: zdravko1@LAB.COM
Ticket etype: aes256-cts-hmac-sha1-96, kvno 2(why is this 2,when upon
creation with the "ktpass" command,the kvno was 3 ?!?)
Ticket length: 977
Auth time:  Aug 27 12:06:34 2010
End time:   Aug 27 22:06:24 2010
Ticket flags: initial,pre-authenticated
Addresses: addressless



I'm logged in as root,the keytab file is readable by root,so is the
apache process.After I log into my client machine(XP)
with the "zdravko1" user,I setup the IExplorer using the Achim's
tutorial http://www.grolmsnet.de/kerbtut/<http://www.grolmsnet.de/kerbtut/).The>
The
error that is
occurring when I try to access http://debian.lab.com is Authorization
Required(401).
The kerbtray activated on my client shows that the tickets that are
received from the server are encrypted with ArcFour(RC4)
encryption and that the etype=0.
Nothing matches with my setup.There is no trace of AES256-SHA1
encryption mechanism.The Apache /var/log/apache2/error.log
writes the following lines:

[debug]src/mod_auth_kerb.c(1579):[client 192.168.100.126]
kerb_authenticate_user entered with user (NULL) and auth_type
Kerberos
[debug]mod_deflate.c(615):[client 192.168.100.126] Zlib: Compressed
594 to 399 : URL /
[debug]src/mod_auth_kerb.c(1579): [client 192.168.100.126]
kerb_authenticate_user entered with user (NULL) and auth_type
Kerberos
[debug]src/mod_auth_kerb.c(1407): [client 192.168.100.126] Verifying
client data using KRB5 GSS-API
[debug]src/mod_auth_kerb.c(1423): [client 192.168.100.126]
Verification returned code 851968
[error] [client 192.168.100.126] gss_accept_sec_context() failed:
Unspecified GSS failure. Minor code may provide more
information (Key table entry not found)
[debug]mod_deflate.c(615):[client 192.168.100.126] Zlib:Compressed 594
to 399 : URL /

So...I have two questions:

Why does the TGT have key version number(kvno) different from the
keytab file that I created 2!=3....and
Is this the reason for the above output from the error.log?



Regards.
0
dita.bt (2)
8/30/2010 10:15:49 AM
comp.protocols.kerberos 5541 articles. 1 followers. jwinius (31) is leader. Post Follow

0 Replies
619 Views

Similar Articles

[PageSpeed] 54

Reply:

Similar Artilces:

kerberos and Windows 2008R2
Hello Kerberos List, I'm trying to set a Kerberos ticket between a Unix and a Windows 2008 R2 se= rver. I've created a user on windows and used the ktpass to generate the Kerberos= keytab: C:\Windows\System32\ktpass princ host/jc1lqaldap.testdomain.com@TESTDOMAIN.= COM mapuser TESTDOMAIN\host_jc1lqaldap -crypto DES-CBC-MD5 -pass * -ptype K= RB5_NT_PRINCIPAL out c:\nis_data\host_jc1lqaldap.keytab I did make sure that "User Kerberos DES encryption types for this account" = was checked. First I was getting: root@jc1lqaldap:/etc# kinit -V -k -t /etc/krb5.keytab -c /tmp/krb5cc_0 host= /jc1lqaldap.testdomain.com kinit: KDC has no support for encryption type while getting initial credent= ials So I've checked "Do not require Kerberos preauthentication" and I get: root@jc1lqaldap:/etc# kinit -V -k -t /etc/krb5.keytab -c /tmp/krb5cc_0 host= /jc1lqaldap.testdomain.com kinit: Key table entry not found while getting initial credentials Where should that key table entry be located ? I cannot go forward with this. Is there a way to get more verbose logging s= o I can troubleshoot this. Klist root@jc1lqaldap:/etc# klist -ke -t /etc/krb5.keytab Keytab name: WRFILE:/etc/krb5.keytab KVNO Timestamp Principal ---- ----------------- ----------------------------------------------------= ---- 12 12/31/69 19:00:00 host/jc1lqaldap.testdomain.com@TESTDOMAIN.COM (DES c= bc mode with RSA-MD5) Cat /etc/krb5.conf [logging] default =3D FILE...

Problem with kerberos working correct due to 2 Domains gss_accept_sec_context() failed: Unspecified GSS failure. Minor code may provide more information (, Key table entry not found)
Hi guys, I'm working about 3 days at this problem and I can't fix it and now I have no more ideas: Customers environment: Windowsdomain with DC where all Users are: contoso.local Sless11 for Webapplication is in a domain: contoso.lan (this is not a Windowsdomain - just the server is configured for this And thats the problem. I don't know - how to manage these two domains. URL to access to the Webapplication is: When I now try to access from a Windowsmachine wich is in the Domain contoso.local at URL http://sless11.contoso.lan/webapp there comes a 401 from the apach...

Key table entry not found
Hello, I'm setting up a test KDC running on Solaris 9. The version I'm running is 5.1.3.1. I have successfully installed and setup my KDC server. I have tested it out on RH9 and everything is working there, as in being authenticated and such. I'm now trying to get kerberos authentication to work on another Solaris 9 box. But am running into problems. On the Solaris 9 box I have modified the pam.conf file to kerberos, copied the krb5.conf file from my kdc and ran kadmin as follows kadmin - admin/admin : ktadd host/machine_name.domain : quit When I t...

Key table entry not found #3
Hi the list, I have two servers. One hosting a kerberos master and ldap master (server.lan) , one other hosting a kerberos slave and ldap replica (replica.lan). Kerberos is used by ldap for authentication SASL/GSSAPI. The kerberos realm is SERVER.LAN. All was running. But since some time, i get error messages with ldapsearch command. With the debug activated, i get the following message of ldapsearch: server:~ admin$ldapsearch -d 1 -b cn=mounts,dc=server,dc=lan .... res_errno: 80, res_error:<SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Key table entry not found)>, res_matched:<> .... (Remark : As information i provide the entire debug at the end of this message) Because of the message "keytable entry not found", i tried to use kadmin and check if principle with root exists. But by using kadmin i get now this message : server:~ admin$ kadmin -proot@SERVER.LAN Couldn't open log file /var/log/krb5kdc/kadmin.log: Permission denied Authenticating as principalroot@SERVER.LAN with password. Password forroot@SERVER.LAN: kadmin: Communication failure with server while initializing kadmin interface server:~ admin$ I check the logfile owner, group owner, and permission. Then i compared with one other kerberos server. Permission and owner was different. I set permission identically. But nothing was changed. With kadmin.local i checked androot@SERVER.LAN exists in the list. ...

key table entry not found #2
Hello , I have Virtual Network configured to use Kerberos authentication.The setup is as follows: Windows Server 2008 Standard SP2 (DC,DNS) (FQDN) labserver.lab.com; Debian Linux 5.0(lenny) (WebServer-Apache) (FQDN) debian.lab.com; Windows XP Prof. (client) (FQDN) zdravko.lab.com; They are in the DNS lookup zone.I create one test user account for accessing the client machine under given domain(lab.com).The user name is "achimtest1" and its password never expires,and it's not going to be prompted for changing.After that I create one "dummy" user which will be used for SPN(service principal name mapping to it).It's called "http-test" and the same flags are used as in "achimtest1" user + one more:"This account supports AES 256 bit encryption".I continued with creating the keytab file: c:\>ktpass /princ HTTP/debian.lab.com@LAB.COM /mapuser http-test@lab.com/pass Debian26 /crypto AES256-SHA1 /ptype KRB5_NT_SRV_HST /out http-test.keytab the keytab is successfully created and I have checked it with the following command:c:\>setspn -L http-test->I have the service principal name:HTTP/ debian.lab.com registered to it.I copy the "http-test.keytab" file via pscp to the Debian box in /etc/apache2/keytab/ directory.In /etc/hosts file in Debian I've deleted "127.0.0.1" line and replaced it with:"192.168.100.103 debian.lab.com debian";192.168.100.103 is the linux box's IP. In /etc/resolf...

gss-server: Key table entry not found
Hi, I cannot get gss-server worked. I have tried adding (using addprinc and ktadd) different combinations of name/host (klist -k confirms the successful addition) but still getting the same error: key table entry not found. Can you please tell me what entry it is looking for and how to resolve the problem? If you need any information about my system in order to help, kindly let me know. Thanks in advance. Regards, David. ...

kprop: Key table entry not found while getting initial ticket
I try to take good notes so that I can reproduce my problems and successes. This week is the first time I have ever touched kerberos. I am using Red Hat ES3 and the default rpms. The short of it: kdb5_util dump /var/kerberos/krb5kdc/dump kprop -f /var/kerberos/krb5kdc/dump mail.eamc.net kprop: Key table entry not found while getting initial ticket Now what? My guess is that I am not asking for the correct ticket for kpropd. A normal inetd.conf entry would be: krb5_prop stream tcp nowait root /usr/kerberos/sbin/kpropd kpropd My thinking is that the second kpropd is my principal. Howeve...

aklog:Key table entry not found while getting AFS tickets
I an trying to automatically obtain the AFS tokens upon login on a Mac 10.2.6 system. I have successfully configured the kerberos v5 and the OpenAFS 1.2.10 clients. I can login with kerberos and successfully verify its ticket with the klist command. I can also execute klog, obtain an AFS token and sucessfully access my AFS space. However, if I login with kerberos and try to execute "aklog", I receive the following messages: aklog: Couldn't get asu.edu AFS tickets: aklog:Key table entry not found while getting AFS tickets Any ideas on how to resolve this problem? Thanks! Jame...

kinit: Key table entry not found while getting initial credentials
Hi Kerberos experts, could anyone help me in addressing this issue since I am a T-O-T-A-L newbie in Kerberos. I have to retrieve kerberos credential in Solaris 5.8 (SEAM 1.0.1) using a windows2003 Active Directory as KDC, and I am compelled to use the credential of a user different from Solaris' user. Let's say I work with user appadm on Solaris and user domuser@resource.corp in AD. AD administrator generated a keytab for my Solaris user in this way: Ktpass -princ kerberos/domuser.resource.corp@RESOURCE.CORP -mapuser domuser -pass [passwd of domuser] -out domuser.keytab and gave me the domuser.keytab file. I configured krb5.conf and stored the content of this keytab file in /etc/krb5/krb5.keytab via ktutil: ktutil: rkt domuser.keytab ktutil: l slot KVNO Principal ---- ---- -------------------------------------------------------------------------- 1 4 kerberos/domuser.resource.corp@RESOURCE.CORP ktutil: wkt /etc/krb5/krb5.keytab ktutil: q Now I think my krb5.conf is correct since I am able to get a TGT via kinit in this way: kinit kerberos/domuser.resource.corp@RESOURCE.CORP then I enter domuser's password and with klist I can see the TGT. But I need to obtain the credentials without entering a password since the kinit command has to be put in the startup script of an application. So I tried this: appadm 99% kinit -k kerberos/domuser.resource.corp@RESOURCE.CORP kinit: Key table entry not found while getting initial credentials :-S ...nothing us...

kinit: Key table entry not found while getting initial credentials #2
Hello newsgroup, We followed the instructions on http://grolmsnet.de/kerbtut/ kinit -k -t /etc/apache2/httpotrskeytab OTRS/ server.test.local@TEST.LOCAL produces the following error: kinit: Key table entry not found while getting initial credentials we are using mit kerberos 1.9.1 on sles10 we created the keytabfile on windows 2008 r2 server with the following command: ktpass -princ OTRS/server.test.local@TEST.LOCAL -mapuser httpotrs@TEST.LOCAL -crypto RC4-HMAC-NT -ptype KRB5_NT_PRINCIPAL -pass secretpassword -out c:\temp\httpotrskeytab we copied the file to the linux server to /etc/apache2 directory manual ticket creation works fine: server:/ # kinit OTRS/server.test.local Password for OTRS/server.test.local@TEST.LOCAL: server:/ # klist Ticket cache: FILE:/tmp/krb5cc_0 Default principal: OTRS/server.test.local@TEST.LOCAL Valid starting Expires Service principal 06/07/11 13:40:15 06/07/11 23:40:15 krbtgt/TEST.LOCAL@TEST.LOCAL renew until 06/08/11 13:40:15 server:/ # kvno OTRS/server.test.local@TEST.LOCAL OTRS/server.test.local@TEST.LOCAL: kvno =3D 11 any ideas what went wrong with our installation? G=FCnter g� <guenter.huerkamp@gmail.com> writes: > Hello newsgroup, > > We followed the instructions on http://grolmsnet.de/kerbtut/ > > > kinit -k -t /etc/apache2/httpotrskeytab OTRS/ > server.test.local@TEST.LOCAL > produces the following error: > kinit: Key table entry not found while getting initial credenti...

"Key table entry not found while verifying ticket for server"
This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig07FDE7C699B5FF20AD258797 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Just added a new system tonight to our Kerberos realm, and was getting the following error when ksu'ing: "ksu: Key table entry not found while verifying ticket for server" Tried Googling for the error to no avail; what is the meaning of this error and how do I clear it? Best Wishes - Peter --=20 Peter_Losher@isc.org | ISC | OpenPGP 0xE8048D08 | "The bits must flow" --------------enig07FDE7C699B5FF20AD258797 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (Darwin) iD8DBQFGtXWzPtVx9OgEjQgRAve6AJ97hWoo/FDyvCC27oHOamy1UiN6TQCfbcjm 8b550EYBPn8jKX8rHMDtmME= =znqF -----END PGP SIGNATURE----- --------------enig07FDE7C699B5FF20AD258797-- ...

ssh gssapi-with-mic and "Key table entry not found"
Hi, I'm trying to get ssh working using gssapi-with-mic authentication. I have about 40 machines running CentOS 5.7. (My bigger goal is to use NFSv4 mounts with "krb5p" security. All these machines mount the same NFSv4 share (think home directories) so my users need to be able to forward their TGT around.) What I'm ultimately running into is sshd complaining "Key table entry not found" on *most* of the servers---a random handful work, and I can't figure out how the working ones are different. So, here's an example: I'm trying to ssh from "lnxsvr3" to "lnxsvr11" using gssapi-with-mic authentication. Here's the output of trying to ssh: [matt@lnxsvr3 ~]$ ssh -v -o"PreferredAuthentications gssapi-with-mic" lnxsvr11 OpenSSH_4.3p2, OpenSSL 0.9.8e-fips-rhel5 01 Jul 2008 debug1: Reading configuration data /etc/ssh/ssh_config debug1: Applying options for * debug1: Connecting to lnxsvr11 [192.168.187.67] port 22. debug1: Connection established. debug1: identity file /mnt/home/matt/.ssh/identity type -1 debug1: identity file /mnt/home/matt/.ssh/id_rsa type 1 debug1: identity file /mnt/home/matt/.ssh/id_dsa type -1 debug1: loaded 3 keys debug1: Remote protocol version 2.0, remote software version OpenSSH_4.3 debug1: match: OpenSSH_4.3 pat OpenSSH* debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version st...

replacing Heimdal with MIT Kerberos, and Kerberos key attributes in LDAP back-end
Hi all Since we are migrating from Debian to RedHat, we are considering replacing our Heimdal Kerberos server (with LDAP back-end) with an MIT Kerberos server (again with LDAP back-end) since RedHat packages are only available for MIT Kerberos. In order to make this migration/upgrade as transparent as possible for our users, we want to convert all the necessary info in the Heimdal back-end to the MIT back-end. Are there any pointers available for this kind of operation? E.g. things like conversion tables mapping the corresponding Kerberos-specific LDAP attributes? Or even scripts? I'm especially looking at the Kerberos key attributes, i.e. - Heimdal: krb5Key - MIT: krbPrincipalKey Is it possible to convert the former into the latter? Is there any code available for this operation? If not, we would have to require all our users to change their passwords at the same time, which is not very feasible. Thanks in advance Bart ...

[rfc-dist] RFC 4567 on Key Management Extensions for Session Description Protocol (SDP) and Real Time Streaming Protocol (RTSP)
A new Request for Comments is now available in online RFC libraries. RFC 4567 Title: Key Management Extensions for Session Description Protocol (SDP) and Real Time Streaming Protocol (RTSP) Author: J. Arkko, F. Lindholm, M. Naslund, K. Norrman, E. Carrara Status: Standards Track Date: July 2006 Mailbox: jari.arkko@ericsson.com, fredrik.lindholm@ericsson.com, mats.naslund@ericsson.com, karl.norrman@ericsson.com, carrara@kth.se Pages: 30 Characters: 67693 Updates/Obsoletes/SeeAlso: None I-D Tag: draft-ietf-mmusic-kmgmt-ext-15.txt URL: http://www.rfc-editor.org/rfc/rfc4567.txt This document defines general extensions for Session Description Protocol (SDP) and Real Time Streaming Protocol (RTSP) to carry messages, as specified by a key management protocol, in order to secure the media. These extensions are presented as a framework, to be used by one or more key management protocols. As such, their use is meaningful only when complemented by an appropriate key management protocol. General guidelines are also given on how the framework should be used together with SIP and RTSP. The usage with the Multimedia Internet KEYing (MIKEY) key management protocol is a...

BUG #1055: no keys in inherited table with primary key when inserting into inheriting table
The following bug has been logged online: Bug reference: 1055 Logged by: Agri Email address: agri@desnol.ru PostgreSQL version: 7.4 Operating system: PC-linux-gnu Description: no keys in inherited table with primary key when inserting into inheriting table Details: let me desribe a bug in the term of sql commands: create table first (id int primary key ); create table second (f2 int) inherits (first); create table third (ref_id int); alter table third add constraint third_ref_first foreign key (ref_id) references first; insert int...

Tying up Port Login table entries with Port Table Entries in CISCO SNMP
In a monitoring app I am writing I plan on using SNMP to obtain for each port on an MDS9000 CISCO switch the remote host WWN and remote port WWN, with the aim of producing a table as follows: Port Port Remote Remote No WWN Host WWN Port WWN 1 a.b.c d.e.f g.h.i 2 j.k.l - - <-- not connected 3 m.n.o p.q.r s.t.u ::::::::::::::::::::::::::::: I _thought_ this information could be obtained by referring to a couple of tables in CISCO-FC-FE-MIB: * The Port table, which is .1.3.6.1.4...

Why isn't table A always key-preserved if equijoined to the key of table B?
Hi, It seems to me table A should always be key-preserved if equijoined to the key of table B, but Oracle seems to disagree. Example: SQL> create table jvd_t1 (c1 number, c2 number,c3 number); Table created. SQL> create table jvd_t2 (d1 number, d2 number); Table created. SQL> alter table jvd_t2 add primary key (d1); Table altered. *********** the following update works: SQL> update (select t1.*,t2.* 2 from jvd_t1 t1,jvd_t2 t2 3 where c1 = d1 ) 4 set c2=d2; 0 rows updated. ******* but this update does not: SQL> update (select t1.*,t2.* 2 from jvd_t1 t1,jvd_...

Member Key found in Fact Table but not in Dimension
I have a problem with the data in my Cubes in Analsyis Services. When I try to process the cubes I get the following error: "A member with key 'XXX' was found in the fact table but was not found in the level 'XXX' of the dimension 'XXX'" I have narrowed it down to the way the data is entered into the Relational Database Table for example instead of typing 'Inventory' the word is '=CCnventory' (this is due to hitting the apostrophe key before typing in the word) Has anyone come across this problem? Has anyone been able to solve it? Please adv...

TABLES TABLES TABLES
How would you best describe to a retiscent SAS student that the concept of TABLES isn't limited to SQL? This came up during a discussion on table lookup methods - and lookup tables in particular (I mean, lookup tables pre- date SQL). Even SAS data sets are referred to as tables. This made the student apoplectic. Words of wisdom most welcome!!! Thanks, Howard sasbum@AOL.COM wrote: >How would you best describe to a retiscent SAS student that the concept of >TABLES isn't limited to SQL? This came up during a discussion on table >lookup methods - and lookup tables in partic...

Libaries not found when compile SASL with Heimdal Kerberos 5.
Hi, I keep failing to compile Cyrus-sasl 2.1.18 with Kerberos 5 libraries (Heimdal) in FreeBSD 5.2.1. The Heimdal Kerberos 5 libaries I found is located at /usr/lib: # find / -name "lib*gssa*" /usr/lib/libgssapi.a /usr/lib/libgssapi_p.a /usr/lib/libgssapi.so.7 /usr/lib/libgssapi.so The configuration options to build SASL is: #!/usr/local/bin/bash LDFLAGS="-L /usr/lib" ../configure -prefix=/usr/local/encap/sasl-2.1.18 --disable-sample --without-dbli b --without-pam --without-des --disable-des --with-openssl=/usr/local --with-sas lauthd=/var/run --disable-checkapop --disable-cram --disable-digest --disable-ot p --disable-anon --enable-plain --enable-login --enable-gssapi --with-plugindir =/usr/local/lib/sasl2 The configuration found the gssapi.h header files but is not able to find the libaries which are locaed at /usr/lib. ..... configure: WARNING: The system type is not recognized. If you believe that Cyber Safe GSSAPI works on this platform, please update the configure script^M checking gssapi.h usability... yes^M checking gssapi.h presence... yes^M checking for gssapi.h... yes^M checking for res_search in -lresolv... no^M checking for gss_unwrap in -lgssapi... no^M checking for gss_unwrap in -lgssapi_krb5... no^M checking for csf_gss_acq_user in -lgss... no^M checking for csf_gss_acq_user in -lgss... no^M checking for gss_unwrap in -lgss... no^M configure: WARNING: Disabling GSSAPI - no library^M checking...

Time Stamped entries and Time Zones
Currently I am working for a company with our computer located in our corporate headquarters in Edina MN. We have 15 sales locations in 5 states (Minnesota, Iowa, Nebraska, Missouri and Kansas). We have a very simple time-clock system. Run a program, press a function key that says you are clocking in (or out) and the program captures the date and time of this entry. A sales person in Nebraska can look at notes on a prospective customer and see that 5 minutes ago a call was placed from our call center in Minnesota to this customer and an appointment was setup for that after...

multiple entries in lis of tables for long tables
I have a number of tables that span more than a page. My list of table ends up showing one entry for each page of these long tables. how do i avoid this and have only one entry for a single table, irrespective of the number of pages it spans? bonzee@gmail.com wrote: > I have a number of tables that span more than a page. My list of table > ends up showing one entry for each page of these long tables. how do i > avoid this and have only one entry for a single table, irrespective of > the number of pages it spans? > use .... \caption{text} .... \endfirsthead .... \caption[]{...

SQL Select from table with partial key from other table
Hi, i have two tables with equal columns Column1, Column2, Column3,... In the first table all columns are filled with data. In the second table only some of the colums are filled. Now i want to find the records in the first table which are matching the partially defines records in the second table example: FirstTable column1 column2 column3 A B 1 A B 2 A C 1 SecondTable column1 column2 column3 A B NULL A C NULL The result should in this case all record from FirstTable SecondTable column1 column2 column3 A NULL NULL In this case also all columns should be returned SecondTable column1 column2 column3 A B NULL Now only the first and the second record from the FirstTable should be returned. My problem is to define a performant sql select. TIA, Soeren Soeren Muehlbauer wrote: > Hi, > > i have two tables with equal columns > > Column1, Column2, Column3,... > > In the first table all columns are filled with data. In the second > table only some of the colums are filled. Now i want to find the > records in the first table which are matching the partially defines > records in the second table > > > example: > > FirstTable > > column1 column2 column3 > A B 1 > A B 2 > A C 1 > > > SecondTable > > column1...

[rfc-dist] RFC 5764 on Datagram Transport Layer Security (DTLS) Extension to Establish Keys for the Secure Real-time Transport Protocol (SRTP)
A new Request for Comments is now available in online RFC libraries. RFC 5764 Title: Datagram Transport Layer Security (DTLS) Extension to Establish Keys for the Secure Real-time Transport Protocol (SRTP) Author: D. McGrew, E. Rescorla Status: Standards Track Stream: IETF Date: May 2010 Mailbox: mcgrew@cisco.com, ekr@rtfm.com Pages: 26 Characters: 60590 Updates/Obsoletes/SeeAlso: None ...

Web resources about - Key table entry not found-this time with Heimdal - comp.protocols.kerberos

A Chinese Boy Found This 3000-Year-Old Sword While Washing His Hands In A River
In July, a Chinese boy a rusty sword out of a river in east China’s Jiangsu province.

Found this old pic. That’s me during my college days, down...
Found this old pic. That’s me during my college days, down in DC protesting the first war with Iraq.

"People, people this isn't even my dog, I found this picture on fascistbook, stole it, and decided to ...
... to think they have a superior intelligence or something, for pointing out the obvious. Keep in mind, I never told a single soul to like this, ...

Fable Legends still nowhere to be found this year, even the beta
So, Fable Legends , guys. Where is it? Initially it was slated as a Fall 2015 title, but the beta is nowhere to be found, much less the finished ...

Privacy Activists Just Found This Creepy Tracking Device on Their Car
This week, privacy experts and advocates from around the world gathered in Valenica, Spain to meet and discuss how to combat government surveillance. ...

Mom Says She Found This Goo in Her Toddler's Juice
An Illinois mom was going to give the juice to her 2-year-old when she found the slimy substance.

Vic Gundotra – Google+ - Found this sitting outside the hotel in Tokyo. Who knows…
Found this sitting outside the hotel in Tokyo. Who knows what this is?

My friend and her mom just rented a car at the Fort Lauderdale–Hollywood airport and found this in the ...
Imgur is home to the web's most popular image content, curated in real time by a dedicated community through commenting, voting and sharing. ...

Watch Gandalf Battle The Balrog In This Found Lord of the Rings Footage
More than 35 years after the film's original release, two clips of lost footage that were cut from Ralph Bakshi's animated Lord of the Rings ...

A solution to the NYC St. Patrick’s Day Parade debacle should be found this year - IrishCentral.com
The Irish Voice newspaper focuses news with an Irish-American pespective, and is published in New York City. IrishCentral.com features stories ...

Resources last updated: 3/10/2016 1:37:13 PM