Bug#421622: libsasl2-modules-gssapi-mit: GSSAPI keytabs not working

Rickard Gustavsson gustavsson.rickard at telia.com
Mon Apr 30 15:55:03 UTC 2007


Package: libsasl2-modules-gssapi-mit
Version: 2.1.22.dfsg1-8
Severity: important


Separate keytabs för kerberos service keys no longer works. 
You have to use a world readable /etc/krb5.keytab for all services on the system. This is a serious security hazard. 
It worked fine in Sarge with libsasl2-modules-gssapi-heimdal

-- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.18-4-686
Locale: LANG=sv_SE.UTF-8, LC_CTYPE=sv_SE.UTF-8 (charmap=UTF-8)

Versions of packages libsasl2-modules-gssapi-mit depends on:
ii  libc6    2.3.6.ds1-13                    GNU C Library: Shared libraries
ii  libcomer 1.39+1.40-WIP-2006.11.14+dfsg-2 common error description library
ii  libkrb53 1.4.4-7etch1                    MIT Kerberos runtime libraries
ii  libsasl2 2.1.22.dfsg1-8                  Pluggable Authentication Modules f

libsasl2-modules-gssapi-mit recommends no packages.

-- no debconf information




More information about the Pkg-cyrus-sasl2-debian-devel mailing list