Univention Bugzilla – Bug 46266
KDC check fails due to "Record Mark" option in network package
Last modified: 2020-07-03 20:53:01 CEST
The KDC diagnostic check tries to communicate with the KDC. In one case, the KDC returned a "Record Mark" option in the answer: https://tools.ietf.org/html/draft-ietf-tpix-tcpopt-00#section-6 Unfortunately, our check throws an error in this case.
Created attachment 9381 [details] testsystem-tcpdump.pcap Test system tcpdump which is OK, recorded via tcpdump -i lo -p -s 0 -n -w testsystem-tcpdump.pcap
Looking at both traces I see the "Record Mark" in both cases, but in the testsystem-tcpdump I see that a second AS-REQ is sent which doesn't show this field. Looking at the code of umc/python/diagnostic/plugins/22_kdc_service.py I see a comment that the author already detected problems with pyasn1 0.1.9-2 (UCS 4.3). Maybe that's related?
This issue has been filed against UCS 4.2. UCS 4.2 is out of maintenance and many UCS components have changed in later releases. Thus, this issue is now being closed. If this issue still occurs in newer UCS versions, please use "Clone this bug" or reopen it and update the UCS version. In this case please provide detailed information on how this issue is affecting you.