Hello! It seems, like openSuSE 12.3 and its KDE PIM does not have GSSAPI working. Server (omega) is openSuSE 11.3 with MIT Kerberos and cyrus IMAP onboard. Client (lena, 192.168.0.10) is openSuSE 12.3 without any additional repositories (ships with KDE 4.10.5 form repo-update). Client cannot access IMAP server with GSSAPI authentication. KMail is configured to use no encryption and auth with SASL GSSAPI. Kerberos tickets are obtained by sssd daemon on OS login. Old clients, residing on openSuSE 11.4 have the same configuration of KMail (no encryption and SASL GSSAPI authentication). Config works fine there. Server-side logs: --8<------------------------------ Jul 18 10:16:31 omega imap[1997]: accepted connection Jul 18 10:16:31 omega imap[1997]: badlogin: lena.domain.com [192.168.0.10] GSSAPI [SASL(0): successful result: ] Jul 18 10:16:32 omega imaps[9538]: EOF in SSL_accept() -> fail Jul 18 10:16:32 omega imaps[9538]: imaps TLS negotiation failed: lena.domain.com [192.168.0.10] Jul 18 10:16:32 omega imaps[9538]: Fatal error: tls_start_servertls() failed --8<------------------------------ Please, note, that KMail also tries to access imaps, while encryption is set to none. Client have successfully initialized its KRB tickets: --8<------------------------------ Ticket cache: FILE:/tmp/krb5cc_1000_gTuuxZ Default principal: pavel@INTERNAL.DOMAIN.COM Valid starting Expires Service principal 07/18/13 09:52:51 07/18/13 19:52:51 krbtgt/INTERNAL.DOMAIN.COM@INTERNAL.DOMAIN.COM renew until 07/19/13 09:52:51 07/18/13 09:58:36 07/18/13 19:52:51 imap/omega.domain.com@ renew until 07/19/13 09:52:51 07/18/13 09:58:36 07/18/13 19:52:51 imap/omega.domain.com@INTERNAL.DOMAIN.COM renew until 07/19/13 09:52:51 --8<------------------------------ Best regards, Pavel Baranchikov Thursday 18 July 2013 -- To unsubscribe, e-mail: opensuse-kde+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-kde+owner@opensuse.org