Cisco Bug: CSCui93535 - Kerberos SASL does not use DNS name in Name-type:Service Host in TGS req
Apr 15, 2020
- Cisco ASA 5500-X Series Firewalls
Known Affected Releases
7.1(2.60) 8.1 8.2 8.4 8.6(0) 9.1(2) 9.8(2) 9.8(3)
Symptom: ASA does not use DNS to resolve name of the LDAP server for Kerberos SASL. This causes Kerberos queries to fail. The output of 'debug ldap 255' will show debugs and a line specifically indicating "Server = " where the value is blank. Example:  Performing SASL authentication for administrator to 172.18.124.200  Server supports the following SASL methods: GSSAPI GSS-SPNEGO EXTERNAL DIGEST-MD5  hostname = 172.18.124.200 DNS: get global group DefaultDNS handle 2ac691b DNS: get global group DefaultDNS handle 2ac691b  getsimple:4001 [CN=administrator,CN=Users,DC=cisco,DC=com]  Server Name = DNS: get global group DefaultDNS handle 2ac691b  SASL authentication start with mechanism GSSAPI for administrator  SASL authentication start for administrator returned code (-1) generic failure  SASL authentication for administrator with mechanism GSSAPI rejected  Failed to bind as administrator returned code (-1) Can't contact LDAP server Conditions: ASA is configured with LDAP AAA server with Kerberos SASL and the server host is configured as FQDN.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases