View Issue Details

IDProjectCategoryView StatusLast Update
0006922Kali Linux[All Projects] Kali Package Bugpublic2021-06-30 08:49
ReporterRoseDeSable Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status newResolutionopen 
Product Versionkali-dev 
Target VersionFixed in Version 
Summary0006922: Kerberos doesn't work for squid
DescriptionHello,
 after the last distribution-upgrade this days my squid has problems to take a kerberos-service-ticket for the proxy in the lan. The Authentication Task is correctly started:

 ├─3079 (negotiate_kerberos_auth) -d -s HTTP/<lan.proxy>@realm

In wireshark I see, that the receiving of the initialization ticket is ok. But the debug-log show me , that problems with the gssapi exist.

2020/12/10 09:32:22.687 kid1| 11,5| peer_proxy_negotiate_auth.cc(522) peer_proxy_negotiate_auth: Creating credential cache for userid@realm
2020/12/10 09:32:22.687 kid1| 11,5| peer_proxy_negotiate_auth.cc(539) peer_proxy_negotiate_auth: Import gss name
2020/12/10 09:32:22.687 kid1| 11,5| peer_proxy_negotiate_auth.cc(546) peer_proxy_negotiate_auth: Initialize gss security context
2020/12/10 09:32:22.687 kid1| 11,5| peer_proxy_negotiate_auth.cc(177) check_gss_err: gss_init_sec_context()failed: Unspecified GSS failure. Minor code may provide more information. SPNEGO cannot find mechanisms to negotiate.

The test-program negotiate_kerberos_auth_test correctly gives me a token for the proxy.

Bye
Rose

Activities

RoseDeSable

2021-02-04 07:55

reporter   ~0014197

Because the problem also further exists in squid 4.13-1+b1, I opened an issue in the developers page https://bugs.squid-cache.org/show_bug.cgi?id=5103

Issue History

Date Modified Username Field Change
2020-12-10 10:41 RoseDeSable New Issue
2021-02-04 07:55 RoseDeSable Note Added: 0014197
2021-06-30 08:49 g0tmi1k Priority high => normal