[27560] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Bizzare problem with authenticating a service principal with AD

daemon@ATHENA.MIT.EDU (Tom Yu)
Mon Mar 12 12:29:38 2007

To: Jason Testart <jatestart@cs.uwaterloo.ca>
From: Tom Yu <tlyu@mit.edu>
Date: Mon, 12 Mar 2007 12:29:08 -0400
In-Reply-To: <45F4E706.1010400@cs.uwaterloo.ca> (Jason Testart's message of
	"Mon, 12 Mar 2007 01:37:10 -0400")
Message-ID: <ldv3b4abf3f.fsf@cathode-dark-space.mit.edu>
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

>>>>> "Jason" == Jason Testart <jatestart@cs.uwaterloo.ca> writes:

Jason> So I just recreated the keytab with the different enctype.  Now when I 
Jason> kinit, I get either:

Jason>    kinit(v5): Password incorrect while getting initial credentials

Jason> or

Jason>    kinit(v5): Preauthentication failed while getting initial credentials

Jason> depending if the "require preauth" is set for the account in AD.

What version of Windows is running on the AD server?  One problem I
think I've seen is that in some recent versions of Windows, AD uses a
different salt for the password than the usual principal-name salt.
(AD stores the actual password, rather than a key.)  I thought this
should only be a problem if you're typing a password into an MIT krb5
ktutil or similar keytab tool, but I think ktpass may have the same
problem.

In one case I encountered, I think the reason was that AD was using
the NetBIOS name for the server instead of its FQDN to create the
"principal name" for the salt.  Does the server in question have a
hostname which is longer than 14 or 15 (I can't remember the exact
number) characters?

---Tom
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post