Your message dated Mon, 18 Jul 2016 09:50:41 +0000
with message-id <e1bp5cd-0003sw...@franck.debian.org>
and subject line Bug#815579: fixed in libapache-mod-auth-kerb 5.4-2.3
has caused the Debian Bug report #815579,
regarding libapache2-mod-auth-kerb: "Request is a replay"-error from KDC
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
815579: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=815579
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: libapache2-mod-auth-kerb
Version: 5.4-2.2
Severity: grave
Justification: renders package unusable


When attempting to authenticate using GSS-API the server sometimes responds 
with a 401 error (which it shouldn't, as the user data is correct). Meanwhile, 
the apache log fills very rapidly with several "Request is a replay" messages:

[Sat Feb 20 21:09:11.537822 2016] [auth_kerb:error] [pid 21422] [client] 
gss_accept_sec_context() failed: Unspecified GSS failure.  Minor code may 
provide more information (, Request is a replay)
[Sat Feb 20 21:09:11.538313 2016] [auth_kerb:error] [pid 21422] [client] 
gss_accept_sec_context() failed: Unspecified GSS failure.  Minor code may 
provide more information (, Request is a replay)
[Sat Feb 20 21:09:11.538806 2016] [auth_kerb:error] [pid 21422] [client] 
gss_accept_sec_context() failed: Unspecified GSS failure.  Minor code may 
provide more information (, Request is a replay)
[Sat Feb 20 21:09:11.539292 2016] [auth_kerb:error] [pid 21422] [client] 
gss_accept_sec_context() failed: Unspecified GSS failure.  Minor code may 
provide more information (, Request is a replay)
[Sat Feb 20 21:09:11.539779 2016] [auth_kerb:error] [pid 21422] [client] 
gss_accept_sec_context() failed: Unspecified GSS failure.  Minor code may 
provide more information (, Request is a replay)
[Sat Feb 20 21:09:11.540296 2016] [auth_kerb:error] [pid 21422] [client] 
gss_accept_sec_context() failed: Unspecified GSS failure.  Minor code may 
provide more information (, Request is a replay)

The issue seems to be related to mod_auth_kerb-5.4-delegation.patch. It does 
not occur when building without this patch. This is a regression from wheezy.

-- System Information:
Debian Release: 8.3
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.4.0-itk01 (SMP w/24 CPU cores)
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages libapache2-mod-auth-kerb depends on:
ii  apache2-bin [apache2-api-20120211]  2.4.10-10+deb8u4
ii  krb5-config                         2.3
ii  libc6                               2.19-18+deb8u3
ii  libcomerr2                          1.42.12-1.1
ii  libgssapi-krb5-2                    1.12.1+dfsg-19+deb8u2
ii  libk5crypto3                        1.12.1+dfsg-19+deb8u2
ii  libkrb5-3                           1.12.1+dfsg-19+deb8u2

libapache2-mod-auth-kerb recommends no packages.

libapache2-mod-auth-kerb suggests no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: libapache-mod-auth-kerb
Source-Version: 5.4-2.3

We believe that the bug you reported is fixed in the latest version of
libapache-mod-auth-kerb, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 815...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Timo Aaltonen <tjaal...@debian.org> (supplier of updated 
libapache-mod-auth-kerb package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 18 Jul 2016 11:53:13 +0300
Source: libapache-mod-auth-kerb
Binary: libapache2-mod-auth-kerb
Architecture: source
Version: 5.4-2.3
Distribution: unstable
Urgency: medium
Maintainer: Ghe Rivero <g...@debian.org>
Changed-By: Timo Aaltonen <tjaal...@debian.org>
Description:
 libapache2-mod-auth-kerb - apache2 module for Kerberos authentication
Closes: 815579
Changes:
 libapache-mod-auth-kerb (5.4-2.3) unstable; urgency=medium
 .
   * Don't apply the delegation patch, it can break gssapi auth. (Closes:
     #815579)
Checksums-Sha1:
 5830e75ffb44e169f2baec0c6c536f562777aebf 1833 
libapache-mod-auth-kerb_5.4-2.3.dsc
 10a5e8adbc4d00843e42bc5f07678a3118533fb0 51547 
libapache-mod-auth-kerb_5.4-2.3.diff.gz
Checksums-Sha256:
 8f2138003efd0eb72929c9a121669a2d21d2f43c50216f8dac80369753b11d24 1833 
libapache-mod-auth-kerb_5.4-2.3.dsc
 58ec0c9b5fe9e7ba6bd576cd591714bc2f8f71d3c495589931de65fe40151f7f 51547 
libapache-mod-auth-kerb_5.4-2.3.diff.gz
Files:
 acc9d45b18bd289b8cbd09b9e13f70a7 1833 net optional 
libapache-mod-auth-kerb_5.4-2.3.dsc
 b906e9b7b81b3f0594fa8ecfa3354738 51547 net optional 
libapache-mod-auth-kerb_5.4-2.3.diff.gz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJXjJloAAoJEMtwMWWoiYTcvTIP/3lY4WQ0k0lCESdpRCaDLPLi
wqRs+L67PDHelygumfZ+9/suDyCtwmjTcm+7oGEm/nOiYA1DB+TUWFUrQuR9SW+S
+34l06zlFylTrPulLBpXc95DHW0G4vdV2VHAMtXflwOIGVLcdS5fywxZFFjcsA3R
JDKDP8RDN0yOqePGEuK3R0X81E1K0FR66VOBAqPgy7uFrxuoNf4RlFuawwhYK3T1
r+1U3RL58phDdzZL+/XrdYbpjW09+dHHB5IEE2QL2RwThi5nCLu/ByI0mXNhyfDh
2OcvRSQjQhFbfeMkjGGQ95S6fv5YdXDP6Z7bsAB4l7LZ26Gj9N/h7Pt+F86locte
pRgmo6UmQH97mGNdVom8Z5WNVrTFIjqX/p5p/OSXqsskojGIdAGOsGsZtJOBCncJ
W/xVKcTxOC7iODVhv8tzo5RjJ9ilvt3py75f4a9CPkddROgRcITzMdxAGUCmtMLh
AZcrA9H2XaGZPOXUg0+4nZedZoxT6GwYZB6Nz0oOUvEuK92Hrf3OZYnCOtU272R7
OnfTyn1Qbu4WrMAvwAxcwmsotH7oe1TqQc/hbsmye+sNHr822FhPbtbkNLp08Db8
B5AXgRT7tQyTso/Ui/sSy9sQN4WG6XzVS9uOfq/3nzhlLJhLQACprtG4FXxy0COY
7x9nPzwltCGn7LEK2N7C
=95Fx
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to