[25033] in Kerberos

home help back first fref pref prev next nref lref last post

AW: GSS-API error: No Kerberos SSPI credentials available

daemon@ATHENA.MIT.EDU (Barbat, Calin)
Wed Nov 30 02:44:37 2005

Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Date: Wed, 30 Nov 2005 08:43:48 +0100
Message-ID: <60DE0C5FDA5A594EAB0F71425A0A3CEF03B8E5@exc-mch01.mch.osram.de>
From: "Barbat, Calin" <c.barbat@osram.de>
To: "Sensei" <senseiwa@mac.com>, <kerberos@mit.edu>
Content-Transfer-Encoding: 8bit
Errors-To: kerberos-bounces@mit.edu

Hi,

yes, SSO works well for me. Some colleague is experiencing that error message.

You are right, SAP uses an AD account, which is then exported to a keytab using ktpass. Which gives an entry like you said: <service>/f.q.d.n@REALM where REALM = AD domain in uppercase (in Windows).

Best regards

Calin

-----Ursprüngliche Nachricht-----
Von: kerberos-bounces@MIT.EDU [mailto:kerberos-bounces@MIT.EDU] Im Auftrag von Sensei
Gesendet: Dienstag, 29. November 2005 20:49
An: kerberos@MIT.EDU
Betreff: Re: GSS-API error: No Kerberos SSPI credentials available

On 2005-11-29 09:35:05 +0100, c.barbat@osram.de ("Barbat, Calin") said:

> Hello Juan,
> 
> did you find as solution to the problem below? It's the one you 
> mentioned in your post to the kerberos mailing list a while ago - I 
> cite you here:
> 
> I have implemented an SSO solution with kerberos5, SNC, Active 
> Directory 2K3 with SAP(Unix Server). It Works fine, but I found an 
> error in some clients that I want to investigate.
> 
> Some days, in the morning (note: users don't close the windows 
> sessions at the end of work-day, they block-out their computers), when 
> users try to connect to SAP, they receive the following client error 
> (in the SAP client log):

I do not know SAP, I use other softwares, but I give my 2 cents, it might help you.

Does SAP need principals in the keytab file like

host/hostname@REALM
service/hostname@REALM (like  ldap/ldap.mydomain.com/MYDOMAIN.COM).

You said SSO works right?

--
Sensei <senseiwa@mac.com>

Part of the inhumanity of the computer is that, once it is competently programmed and working smoothly, it is completely honest. (Isaac Asimov)

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post