JiscMail Logo
Email discussion lists for the UK Education and Research communities

Help for MOONSHOT-DEV Archives


MOONSHOT-DEV Archives

MOONSHOT-DEV Archives


MOONSHOT-DEV@JISCMAIL.AC.UK


View:

Message:

[

First

|

Previous

|

Next

|

Last

]

By Topic:

[

First

|

Previous

|

Next

|

Last

]

By Author:

[

First

|

Previous

|

Next

|

Last

]

Font:

Proportional Font

LISTSERV Archives

LISTSERV Archives

MOONSHOT-DEV Home

MOONSHOT-DEV Home

MOONSHOT-DEV  September 2014

MOONSHOT-DEV September 2014

Options

Subscribe or Unsubscribe

Subscribe or Unsubscribe

Log In

Log In

Get Password

Get Password

Subject:

Re: SSP logs

From:

Stefan Paetow <[log in to unmask]>

Date:

Tue, 30 Sep 2014 13:44:38 +0000

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (39 lines)

Hi Luke,

Funny you should mention that... I was going to suggest that perhaps the common errors be logged in the security or audit event logs, which technically only the Administrators (local or domain) should have access to. Adam pointed out that this may lead to discovery of user information if not done carefully.

But if we only log the message, i.e. the data as below, that might be useful already. Adam suggested that perhaps we should provide a version of the SSP in these situations in which it logs prolifically which may be useful in tracking problems down quickly. 

Unfortunately in this case, CSC are still having issues. Now the 'hostname', 'hostname -a' and 'hostname -f' commands all return the same, so the GSS name sent by the host should be correct, but they're still having no joy. I'm trying to obtain the raw SSH logs as spat out by putty to see what's received and what's passed along. The user in question has entries in the Credential Manager for *both* names for the host, so it should've picked up at least one of the credentials.

I'll continue to investigate and see if we can resolve this. :-/


Stefan Paetow
Moonshot Industry & Research Liaison Coordinator
t: +44 (0)1235 822 125

Janet, the UK’s research and education network.


On 30 Sep 2014, at 13:56, Luke Howard <[log in to unmask]> wrote:

> Maybe if this is a common error, it could be caught and surfaced by some other more visible mechanism (I'm a bit out of touch with logging on Windows).
> 
> On 30 Sep 2014, at 4:10 am, Kevin Wasserman <[log in to unmask]> wrote:
> 
>> The error you're getting is here:
>> 
>> 		<Data>EAP-SSP (0680.0824)GsspInitSecContext: EAP ISC returned 00090000.7dbaa11a Flags 00000016(00000016)</Data>
>> 
>> 00090000 is the 'major code' which translates to GSS_S_DEFECTIVE_TOKEN.
>> 7dbaa11a is the 'minor code' which translates to GSS_EAP_WRONG_ACCEPTOR_NAME. So on the client, Putty is specifying a different service name from what the server actually advertises; they have to match. The SSP never tries to get the real credentials because it's failing earlier in the process.
>> 
>> -Kevin Wasserman


Janet(UK) is a trading name of Jisc Collections and Janet Limited, a 
not-for-profit company which is registered in England under No. 2881024 
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Oxford, Didcot, Oxfordshire. OX11 0SG. VAT No. 614944238

Top of Message | Previous Page | Permalink

JiscMail Tools


RSS Feeds and Sharing


Advanced Options


Archives

April 2024
March 2022
December 2021
October 2021
September 2021
August 2021
June 2021
April 2021
February 2021
January 2021
December 2020
November 2020
October 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
December 2019
November 2019
October 2019
September 2019
July 2019
June 2019
May 2019
April 2019
March 2019
February 2019
January 2019
December 2018
November 2018
April 2018
February 2018
January 2018
December 2017
November 2017
September 2017
August 2017
July 2017
June 2017
May 2017
April 2017
February 2017
January 2017
December 2016
October 2016
September 2016
August 2016
June 2016
April 2016
March 2016
February 2016
January 2016
December 2015
November 2015
October 2015
August 2015
July 2015
May 2015
April 2015
March 2015
February 2015
January 2015
December 2014
November 2014
October 2014
September 2014
August 2014
July 2014
June 2014
May 2014
April 2014
March 2014
February 2014
January 2014
December 2013
November 2013
October 2013
September 2013
August 2013
July 2013


JiscMail is a Jisc service.

View our service policies at https://www.jiscmail.ac.uk/policyandsecurity/ and Jisc's privacy policy at https://www.jisc.ac.uk/website/privacy-notice

For help and support help@jisc.ac.uk

Secured by F-Secure Anti-Virus CataList Email List Search Powered by the LISTSERV Email List Manager