Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-8168689

JDK fails to decrypt Kerberos AES256 ticket when it comes from trusted DC

XMLWordPrintable


      Decryption of AES256 fails when using
      R28.3.10-9-170826-1.6.0_115-20160324-1349-windows-x86_64 and client ticket is
      coming from a trusted domain. Same setup works for RC4HMAC encryption

      Customer has implemented Kerberos SSO for multiple domains on Weblogic Server
      10.3.6 and it is running on Windows 2008 R2 64 bit.

      When service ticket presented by client comes from same AD Domain as the one
      JDK is authenticating against, it works for every possible encryption.

      If service ticket, is presented by a client that has been logged to a trusted
      domain, it works for RC4HMAC but not for AES256.


            coffeys Sean Coffey
            shadowbug Shadow Bug
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: