[20371] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: ConstrainedDelegation and MSLSA

daemon@ATHENA.MIT.EDU (Greg Hudson)
Wed Jun 8 00:32:41 2022

Message-ID: <da84f368-c115-cca5-2f4e-2e78f43e6b54@mit.edu>
Date: Wed, 8 Jun 2022 00:31:35 -0400
MIME-Version: 1.0
Content-Language: en-US
To: Scot McKinley <scot.mckinley@oracle.com>, krbdev@mit.edu
From: Greg Hudson <ghudson@mit.edu>
In-Reply-To: <b7d868f3-cfd4-41d1-d31d-6802bc2af2d1@oracle.com>
Content-Type: text/plain; charset="utf-8"
Errors-To: krbdev-bounces@mit.edu
Content-Transfer-Encoding: 8bit

On 6/6/22 14:28, Scot McKinley wrote:
> Hi all, we are experiencing a problem in using MIT KerberosForWindow's
> (KfW) MSLSA in conjunction with ConstrainedDelegation.  We are receiving
> the generic error:
> 
> krb5_cc_get_principal(clt) failure (-1765328243)

This is KRB5_CC_NOTFOUND, "Matching credential not found".

You can set the environment variable KRB5_TRACE to a filename to
hopefully find out what principal the library is looking for in the cache.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev


home help back first fref pref prev next nref lref last post