Kerberos - TCP client wants 1195725856 bytes, cap is 1048572Creating keytabs and service principal namesAuthenticate with Kerberos to a CIFS share provided by OpenSolarisAuthenticating Windows 7 against MIT Kerberos 5Linking Linux MIT Kerberos with a Windows 2003 Active DirectoryActive Directory: Thunderbird LDAP autocompletion not working with Kerberos authnginx emerg error with type_hashIs this Kerberos/AD setup possible?Kerberos SSH/PAM login like ADKerberos MaxTokenSizewindows-ubuntu-bash + hypervisor winrm + ansible - Server not found in Kerberos database

Multi tool use
Multi tool use

Does the EU Common Fisheries Policy cover British Overseas Territories?

You look catfish vs You look like a catfish

Binary Numbers Magic Trick

What is the range of this combined function?

Modify locally tikzset

Why do Ichisongas hate elephants and hippos?

Illegal assignment from SObject to Contact

Electric guitar: why such heavy pots?

Single Colour Mastermind Problem

If Earth is tilted, why is Polaris always above the same spot?

Was it really necessary for the Lunar Module to have 2 stages?

What's the polite way to say "I need to urinate"?

Does jamais mean always or never in this context?

"ne paelici suspectaretur" (Tacitus)

Where does the labelling of extrinsic semiconductors as "n" and "p" come from?

Why is the origin of “threshold” uncertain?

Why does nature favour the Laplacian?

Why does Bran Stark feel that Jon Snow "needs to know" about his lineage?

How to creep the reader out with what seems like a normal person?

Sci-fi novel series with instant travel between planets through gates. A river runs through the gates

What are the spoon bit of a spoon and fork bit of a fork called?

Weird result in complex limit

When and why did journal article titles become descriptive, rather than creatively allusive?

Feels like I am getting dragged in office politics



Kerberos - TCP client wants 1195725856 bytes, cap is 1048572


Creating keytabs and service principal namesAuthenticate with Kerberos to a CIFS share provided by OpenSolarisAuthenticating Windows 7 against MIT Kerberos 5Linking Linux MIT Kerberos with a Windows 2003 Active DirectoryActive Directory: Thunderbird LDAP autocompletion not working with Kerberos authnginx emerg error with type_hashIs this Kerberos/AD setup possible?Kerberos SSH/PAM login like ADKerberos MaxTokenSizewindows-ubuntu-bash + hypervisor winrm + ansible - Server not found in Kerberos database






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















I'm having some difficulties debugging this error. I'm running nginx as an api gateway built to make a sub-request to kerberos whenever an endpoint gets called using the SPNEGO method. But whenever I attempt to make a requests with TGS ticket in the header I get the error TCP client 192.168.112.4.51658 wants 1195725856 bytes, cap is 1048572 then the connection closes.



I've tried printf "xffxffxffxff" | netcat krb_address 88 and it triggers the above error and if an instance of xff is removed then no error.



What I'm struggling with figuring out is:



  1. What exactly is the message being sent to kerberos that is breaking the cap constraint?

  2. What kind of configuration changes need to be made to meet the cap requirement?

I've never worked with nginx and kerberos before so not sure of any better questions I could be asking other then the basics.



Some insight into previous experience with this error or perhaps some additional techniques I could use to uncover some more insights into what is causing the error would be very much appreciated!










share|improve this question




























    1















    I'm having some difficulties debugging this error. I'm running nginx as an api gateway built to make a sub-request to kerberos whenever an endpoint gets called using the SPNEGO method. But whenever I attempt to make a requests with TGS ticket in the header I get the error TCP client 192.168.112.4.51658 wants 1195725856 bytes, cap is 1048572 then the connection closes.



    I've tried printf "xffxffxffxff" | netcat krb_address 88 and it triggers the above error and if an instance of xff is removed then no error.



    What I'm struggling with figuring out is:



    1. What exactly is the message being sent to kerberos that is breaking the cap constraint?

    2. What kind of configuration changes need to be made to meet the cap requirement?

    I've never worked with nginx and kerberos before so not sure of any better questions I could be asking other then the basics.



    Some insight into previous experience with this error or perhaps some additional techniques I could use to uncover some more insights into what is causing the error would be very much appreciated!










    share|improve this question
























      1












      1








      1


      1






      I'm having some difficulties debugging this error. I'm running nginx as an api gateway built to make a sub-request to kerberos whenever an endpoint gets called using the SPNEGO method. But whenever I attempt to make a requests with TGS ticket in the header I get the error TCP client 192.168.112.4.51658 wants 1195725856 bytes, cap is 1048572 then the connection closes.



      I've tried printf "xffxffxffxff" | netcat krb_address 88 and it triggers the above error and if an instance of xff is removed then no error.



      What I'm struggling with figuring out is:



      1. What exactly is the message being sent to kerberos that is breaking the cap constraint?

      2. What kind of configuration changes need to be made to meet the cap requirement?

      I've never worked with nginx and kerberos before so not sure of any better questions I could be asking other then the basics.



      Some insight into previous experience with this error or perhaps some additional techniques I could use to uncover some more insights into what is causing the error would be very much appreciated!










      share|improve this question














      I'm having some difficulties debugging this error. I'm running nginx as an api gateway built to make a sub-request to kerberos whenever an endpoint gets called using the SPNEGO method. But whenever I attempt to make a requests with TGS ticket in the header I get the error TCP client 192.168.112.4.51658 wants 1195725856 bytes, cap is 1048572 then the connection closes.



      I've tried printf "xffxffxffxff" | netcat krb_address 88 and it triggers the above error and if an instance of xff is removed then no error.



      What I'm struggling with figuring out is:



      1. What exactly is the message being sent to kerberos that is breaking the cap constraint?

      2. What kind of configuration changes need to be made to meet the cap requirement?

      I've never worked with nginx and kerberos before so not sure of any better questions I could be asking other then the basics.



      Some insight into previous experience with this error or perhaps some additional techniques I could use to uncover some more insights into what is causing the error would be very much appreciated!







      nginx tcp kerberos spnego






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Apr 21 at 18:30









      KenpachiKenpachi

      62




      62




















          1 Answer
          1






          active

          oldest

          votes


















          1














          That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



          The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



          I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?






          share|improve this answer























            Your Answer








            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "2"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f963989%2fkerberos-tcp-client-wants-1195725856-bytes-cap-is-1048572%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            1














            That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



            The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



            I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?






            share|improve this answer



























              1














              That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



              The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



              I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?






              share|improve this answer

























                1












                1








                1







                That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



                The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



                I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?






                share|improve this answer













                That's a protocol mismatch; at some point you're sending an HTTP request when the Kerberos server is expecting something else.



                The giveaway here is the number shown in the error, 1195725856. Converted to hexadecimal, that's 47 45 54 20. Converted to ASCII, it is G, E, T, space, or the first four characters of an HTTP GET request. That is unlikely to be a coincindence.



                I'm not very familiar with Kerberos, but a little research suggests that one possible cause is that you may have left out the --enable-http option to the kdc service?







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Apr 22 at 23:46









                Harry JohnstonHarry Johnston

                3,97012040




                3,97012040



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f963989%2fkerberos-tcp-client-wants-1195725856-bytes-cap-is-1048572%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    3UbLPwbZ9whPBbWqqxwo
                    5F 2E,2e8 MCZWwuXicYLHyRyPJ95NsSY1yoHUG7,CnEzV,BX w3,hb

                    Popular posts from this blog

                    RemoteApp sporadic failureWindows 2008 RemoteAPP client disconnects within a matter of minutesWhat is the minimum version of RDP supported by Server 2012 RDS?How to configure a Remoteapp server to increase stabilityMicrosoft RemoteApp Active SessionRDWeb TS connection broken for some users post RemoteApp certificate changeRemote Desktop Licensing, RemoteAPPRDS 2012 R2 some users are not able to logon after changed date and time on Connection BrokersWhat happens during Remote Desktop logon, and is there any logging?After installing RDS on WinServer 2016 I still can only connect with two users?RD Connection via RDGW to Session host is not connecting

                    Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                    Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020