Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 5844] New: Kerberos decoding of AS-REP doesn't happen auto

Date: Mon, 18 Apr 2011 11:54:31 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5844

           Summary: Kerberos decoding of AS-REP doesn't happen
                    automatically on Windows 7 computer
           Product: Wireshark
           Version: 1.4.5
          Platform: x86
        OS/Version: Windows 7
            Status: NEW
          Severity: Major
          Priority: Medium
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: g.hassler@xxxxxxxxxxxxx


Build Information:
Version 1.4.3 (SVN Rev 35482 from /trunk-1.4)

Copyright 1998-2011 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (32-bit) with GTK+ 2.16.6, with GLib 2.22.4, with WinPcap (version
unknown), with libz 1.2.3, without POSIX capabilities, without libpcre, with
SMI
0.4.8, with c-ares 1.7.1, with Lua 5.1, without Python, with GnuTLS 2.8.5, with
Gcrypt 1.4.5, with MIT Kerberos, with GeoIP, with PortAudio V19-devel (built
Jan 11 2011), with AirPcap.

Running on Windows XP Service Pack 2, build 2600, with WinPcap version 4.1.2
(packet.dll version 4.1.0.2001), based on libpcap version 1.0 branch 1_0_rel0b
(20091008), GnuTLS 2.8.5, Gcrypt 1.4.5, without AirPcap.

Built using Microsoft Visual C++ 9.0 build 30729
Wireshark is Open Source Software released under the GNU General Public
License.

Check the man page and http://www.wireshark.org for more information.
--
When we run a packet capture of kerberos messages, the AS-REP message fails to
decode. We can only decode it when we manually select to decode the packet. The
interesting item is that when the same caputre is opened up using the same
installation of Wireshark on a Windows XP computer, it is decoded
automatically.

Another problem occurs for the AS-REQ and AS-REP are not decoded when the
following steps are performed.

1. Enter kerberos in the filter
2. Select Apply.
3. Select Save As from the File pull-down menu.
4. Select the "Display Only" radio buttion
5. Open newly created file in Wireshark. 
6. None of the packets can be decoded anymore

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.