Hi Luke,
Funny you should mention that... I was going to suggest that perhaps the common errors be logged in the security or audit event logs, which technically only the Administrators (local or domain) should have access to. Adam pointed out that this may lead to discovery of user information if not done carefully.
But if we only log the message, i.e. the data as below, that might be useful already. Adam suggested that perhaps we should provide a version of the SSP in these situations in which it logs prolifically which may be useful in tracking problems down quickly.
Unfortunately in this case, CSC are still having issues. Now the 'hostname', 'hostname -a' and 'hostname -f' commands all return the same, so the GSS name sent by the host should be correct, but they're still having no joy. I'm trying to obtain the raw SSH logs as spat out by putty to see what's received and what's passed along. The user in question has entries in the Credential Manager for *both* names for the host, so it should've picked up at least one of the credentials.
I'll continue to investigate and see if we can resolve this. :-/
Stefan Paetow
Moonshot Industry & Research Liaison Coordinator
t: +44 (0)1235 822 125
Janet, the UK’s research and education network.
On 30 Sep 2014, at 13:56, Luke Howard <[log in to unmask]> wrote:
> Maybe if this is a common error, it could be caught and surfaced by some other more visible mechanism (I'm a bit out of touch with logging on Windows).
>
> On 30 Sep 2014, at 4:10 am, Kevin Wasserman <[log in to unmask]> wrote:
>
>> The error you're getting is here:
>>
>> <Data>EAP-SSP (0680.0824)GsspInitSecContext: EAP ISC returned 00090000.7dbaa11a Flags 00000016(00000016)</Data>
>>
>> 00090000 is the 'major code' which translates to GSS_S_DEFECTIVE_TOKEN.
>> 7dbaa11a is the 'minor code' which translates to GSS_EAP_WRONG_ACCEPTOR_NAME. So on the client, Putty is specifying a different service name from what the server actually advertises; they have to match. The SSP never tries to get the real credentials because it's failing earlier in the process.
>>
>> -Kevin Wasserman
Janet(UK) is a trading name of Jisc Collections and Janet Limited, a
not-for-profit company which is registered in England under No. 2881024
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238
|