[36750] in Kerberos

home help back first fref pref prev next nref lref last post

RE: Wrong principal in request error on gss_accept_sec_context()

daemon@ATHENA.MIT.EDU (Xie, Hugh)
Tue Feb 3 14:15:37 2015

Date: Tue, 03 Feb 2015 19:15:17 +0000
From: "Xie, Hugh" <hugh.xie@bankofamerica.com>
In-reply-to: <54B89850.4020002@mit.edu>
To: Greg Hudson <ghudson@mit.edu>, "'<kerberos@mit.edu>'" <Kerberos@mit.edu>
Message-id: <7E270C3427928E499F189C5636C52CDC45CD2F52@smtp_mail.bankofamerica.com>
MIME-version: 1.0
Content-language: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

It has nothing to do with keytabs. The problem seems to go away once we use setspn to create the SPN under the same unix account in AD. The spn mapping does exists from host->HTTP, so in theory we should not have to create SPN. Anyway, I need to raise this question to Microsoft unless you know other resource for looking at AD/Mit KRB5.

-----Original Message-----
From: Greg Hudson [mailto:ghudson@mit.edu] 
Sent: Thursday, January 15, 2015 11:49 PM
To: Xie, Hugh; '<kerberos@mit.edu>'
Subject: Re: Wrong principal in request error on gss_accept_sec_context()

On 01/15/2015 05:18 PM, Xie, Hugh wrote:
> I upgrade the version of krb5 lib to version 1.13. Got more specific error:
> Request ticket server HTTP/ 
> host2.site123.baml.com@COMMON.BANKOFAMERICA.COM kvno 15 enctype 
> rc4-hmac found in keytab but cannot decrypt ticket
>
> Any idea?

Whatever procedure you are using to generate the keytab entry is not generating the same key as the one present on the KDC.

I am not personally very familiar with creating keytabs for use with Active Directory KDCs, but I know a lot of people use msktutil for that purpose, rather than ktutil.

----------------------------------------------------------------------
This message, and any attachments, is for the intended recipient(s) only, may contain information that is privileged, confidential and/or proprietary and subject to important terms and conditions available at http://www.bankofamerica.com/emaildisclaimer.   If you are not the intended recipient, please delete this message.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post