Kerberos - TCP client wants 1195725856 bytes, cap is 1048572Creating keytabs and service principal namesAuthenticate with Kerberos to a CIFS share provided by OpenSolarisAuthenticating Windows 7 against MIT Kerberos 5Linking Linux MIT Kerberos with a Windows 2003 Active DirectoryActive Directory: Thunderbird LDAP autocompletion not working with Kerberos authnginx emerg error with type_hashIs this Kerberos/AD setup possible?Kerberos SSH/PAM login like ADKerberos MaxTokenSizewindows-ubuntu-bash + hypervisor winrm + ansible - Server not found in Kerberos database

Does the EU Common Fisheries Policy cover British Overseas Territories?

You look catfish vs You look like a catfish

Binary Numbers Magic Trick

What is the range of this combined function?

Modify locally tikzset

Why do Ichisongas hate elephants and hippos?

Illegal assignment from SObject to Contact

Electric guitar: why such heavy pots?

Single Colour Mastermind Problem

If Earth is tilted, why is Polaris always above the same spot?

Was it really necessary for the Lunar Module to have 2 stages?

What's the polite way to say "I need to urinate"?

Does jamais mean always or never in this context?

"ne paelici suspectaretur" (Tacitus)

Where does the labelling of extrinsic semiconductors as "n" and "p" come from?

Why is the origin of “threshold” uncertain?

Why does nature favour the Laplacian?

Why does Bran Stark feel that Jon Snow "needs to know" about his lineage?

How to creep the reader out with what seems like a normal person?

Sci-fi novel series with instant travel between planets through gates. A river runs through the gates

What are the spoon bit of a spoon and fork bit of a fork called?

Weird result in complex limit

When and why did journal article titles become descriptive, rather than creatively allusive?

Feels like I am getting dragged in office politics



Kerberos - TCP client wants 1195725856 bytes, cap is 1048572


Creating keytabs and service principal namesAuthenticate with Kerberos to a CIFS share provided by OpenSolarisAuthenticating Windows 7 against MIT Kerberos 5Linking Linux MIT Kerberos with a Windows 2003 Active DirectoryActive Directory: Thunderbird LDAP autocompletion not working with Kerberos authnginx emerg error with type_hashIs this Kerberos/AD setup possible?Kerberos SSH/PAM login like ADKerberos MaxTokenSizewindows-ubuntu-bash + hypervisor winrm + ansible - Server not found in Kerberos database






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















I'm having some difficulties debugging this error. I'm running nginx as an api gateway built to make a sub-request to kerberos whenever an endpoint gets called using the SPNEGO method. But whenever I attempt to make a requests with TGS ticket in the header I get the error TCP client 192.168.112.4.51658 wants 1195725856 bytes, cap is 1048572 then the connection closes.



I've tried printf "xffxffxffxff" | netcat krb_address 88 and it triggers the above error and if an instance of xff is removed then no error.



What I'm struggling with figuring out is:



  1. What exactly is the message being sent to kerberos that is breaking the cap constraint?

  2. What kind of configuration changes need to be made to meet the cap requirement?

I've never worked with nginx and kerberos before so not sure of any better questions I could be asking other then the basics.



Some insight into previous experience with this error or perhaps some additional techniques I could use to uncover some more insights into what is causing the error would be very much appreciated!










share|improve this question




























    1















    I'm having some difficulties debugging this error. I'm running nginx as an api gateway built to make a sub-request to kerberos whenever an endpoint gets called using the SPNEGO method. But whenever I attempt to make a requests with TGS ticket in the header I get the error TCP client 192.168.112.4.51658 wants 1195725856 bytes, cap is 1048572 then the connection closes.



    I've tried printf "xffxffxffxff" | netcat krb_address 88 and it triggers the above error and if an instance of xff is removed then no error.



    What I'm struggling with figuring out is:



    1. What exactly is the message being sent to kerberos that is breaking the cap constraint?

    2. What kind of configuration changes need to be made to meet the cap requirement?

    I've never worked with nginx and kerberos before so not sure of any better questions I could be asking other then the basics.



    Some insight into previous experience with this error or perhaps some additional techniques I could use to uncover some more insights into what is causing the error would be very much appreciated!










    share|improve this question
























      1












      1








      1


      1






      I'm having some difficulties debugging this error. I'm running nginx as an api gateway built to make a sub-request to kerberos whenever an endpoint gets called using the SPNEGO method. But whenever I attempt to make a requests with TGS ticket in the header I get the error TCP client 192.168.112.4.51658 wants 1195725856 bytes, cap is 1048572 then the connection closes.



      I've tried printf "xffxffxffxff" | netcat krb_address 88 and it triggers the above error and if an instance of xff is removed then no error.



      What I'm struggling with figuring out is:



      1. What exactly is the message being sent to kerberos that is breaking the cap constraint?

      2. What kind of configuration changes need to be made to meet the cap requirement?

      I've never worked with nginx and kerberos before so not sure of any better questions I could be asking other then the basics.



      Some insight into previous experience with this error or perhaps some additional techniques I could use to uncover some more insights into what is causing the error would be very much appreciated!










      share|improve this question














      I'm having some difficulties debugging this error. I'm running nginx as an api gateway built to make a sub-request to kerberos whenever an endpoint gets called using the SPNEGO method. But whenever I attempt to make a requests with TGS ticket in the header I get the error TCP client 192.168.112.4.51658 wants 1195725856 bytes, cap is 1048572 then the connection closes.



      I've tried printf "xffxffxffxff" | netcat krb_address 88 and it triggers the above error and if an instance of xff is removed then no error.



      What I'm struggling with figuring out is:



      1. What exactly is the message being sent to kerberos that is breaking the cap constraint?

      2. What kind of configuration changes need to be made to meet the cap requirement?

      I've never worked with nginx and kerberos before so not sure of any better questions I could be asking other then the basics.



      Some insight into previous experience with this error or perhaps some additional techniques I could use to uncover some more insights into what is causing the error would be very much appreciated!







      nginx tcp kerberos spnego






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Apr 21 at 18:30









      KenpachiKenpachi

      62




      62




















          1 Answer
          1






          active

          oldest

          votes


















          1














          That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



          The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



          I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?






          share|improve this answer























            Your Answer








            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "2"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f963989%2fkerberos-tcp-client-wants-1195725856-bytes-cap-is-1048572%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            1














            That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



            The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



            I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?






            share|improve this answer



























              1














              That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



              The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



              I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?






              share|improve this answer

























                1












                1








                1







                That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



                The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



                I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?






                share|improve this answer













                That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



                The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



                I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Apr 22 at 23:46









                Harry JohnstonHarry Johnston

                3,97012040




                3,97012040



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f963989%2fkerberos-tcp-client-wants-1195725856-bytes-cap-is-1048572%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Wikipedia:Vital articles Мазмуну Biography - Өмүр баян Philosophy and psychology - Философия жана психология Religion - Дин Social sciences - Коомдук илимдер Language and literature - Тил жана адабият Science - Илим Technology - Технология Arts and recreation - Искусство жана эс алуу History and geography - Тарых жана география Навигация менюсу

                    Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                    Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070