[30677] in Kerberos

home help back first fref pref prev next nref lref last post

Prob: failed to verify krb5 credentials: Server not found in Kerb

daemon@ATHENA.MIT.EDU (slaindevil@kabelmail.de)
Tue Feb 3 15:34:19 2009

From: "slaindevil@kabelmail.de" <slaindevil@kabelmail.de>
To: <kerberos@mit.edu>
Date: Tue, 03 Feb 2009 14:28:05
Message-ID: <100407D902030D1C0599@kabelmail.de>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hey guys,

I am short before dispairing :(

Maybe someone has time and likes to help me? :)

I am trying to set up kerberos to authenticate a
TWiki running on Unix against an Windows Server 2003 Active Directory...

I configured the krb5.conf like this:

[logging]
 ...

[libdefaults]
 default_realm = SRV.TEST.LAN
 dns_lookup_realm = false
 dns_lookup_kdc = false
 ticket_lifetime = 24000
 forwardable = yes

[realms]
 SRV.TEST.LAN = {
  kdc = location.srv.test.lan:88
  admin_server =  location.srv.test.lan:749
  default_domain = SRV.TEST.LAN
 }

[domain_realm]
 .test.lan = SRV.TEST.LAN
 test.lan = SRV.TEST.LAN

[appdefaults]
 pam = {
   debug = false
   ticket_lifetime = 24000
   renew_lifetime = 36000
   forwardable = true
   krb4_convert = false
 }

When I use "kinit" everything works fine. With every valid login I get a ticket...


Then I created the keytab file, set with a valid user and password for
the service: HTTP/wiki.test.lan:8080@SRV.TEST.LAN

http://wiki.test.lan:8080/bin is the url I type into the browser...

When I use "kinit" with the keytab and HTTP/wiki.test.lan:8080 everything works fine... I get a ticket...

Now I wanna setup the twiki to use kerberos to authenticate with...
The httpd.conf for the "bin" directory at http://wiki.test.lan:8080/ is like following:
Order Deny,Allow
Allow from all
   
AuthType Kerberos
KrbAuthRealms SRV.TEST.LAN
KrbServiceName HTTP
Krb5Keytab /etc/http.keytab
KrbMethodNegotiate on
KrbMethodK5Passwd on
Require valid-user

When I browse to "http://wiki.srv.lan:8080/bin" the login box prompts...
I enter a valid login, but the box stays...

In the log it says:
failed to verify krb5 credentials: Server not found in Kerberos database

What is wrong? Can someone help me?! :(

Greets,


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post