[27549] in Kerberos
Re: Bizzare problem with authenticating a service principal with AD
daemon@ATHENA.MIT.EDU (Tom Yu)
Sun Mar 11 22:47:40 2007
To: Jason Testart <jatestart@cs.uwaterloo.ca>
From: Tom Yu <tlyu@mit.edu>
Date: Sun, 11 Mar 2007 22:47:25 -0400
In-Reply-To: <45F4B82D.8020604@cs.uwaterloo.ca> (Jason Testart's message of
"Sun, 11 Mar 2007 22:17:17 -0400")
Message-ID: <ldvd53fw536.fsf@cathode-dark-space.mit.edu>
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
>>>>> "Jason" == Jason Testart <jatestart@cs.uwaterloo.ca> writes:
Jason> I'm trying to get pam_krb5 working with an Active Directory domain. It
Jason> works when I don't have a krb5.keytab file but it doesn't when I do,
Jason> since the verification of the TGT using the service principal fails with
Jason> an error: "Key table entry not found". The keytab file is simple as it
Jason> only contains the "host" service principal for the Ubuntu Linux box that
Jason> I am testing with.
Jason> So, I figured I screwed-up somehow with the generation of the keytab
Jason> file using ktpass.exe. However, I don't think I did. When I run "klist
Jason> -k", copy the principal name from the output, and paste that principal
Jason> name to the end of "kinit -k", I still get the error:
Jason> kinit(v5): Key table entry not found while getting initial credentials
Do your key version numbers match?
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos