[22227] in Kerberos
Integrated Windows Login: No principal in keytab matches desired name
daemon@ATHENA.MIT.EDU (Timo Fuchs)
Wed Aug 18 15:33:18 2004
From: Timo Fuchs <fuechsle@cs.tu-berlin.de>
Date: 17 Aug 2004 08:05:28 GMT
Message-ID: <cfse88$f61$1@news.cs.tu-berlin.de>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
Hi,
I am trying to set up an integrated windows login scenario using apache
and mod_auth_gss_krb5 (http://modgssapache.sourceforge.net) according
to http://www.onlamp.com/pub/a/onlamp/2003/09/11/kerberos.html?page=1.
However, Apache cannot authenticate:
-- snip ---
gss_acquire_cred() failed: No principal in keytab matches desired name:
--- snap ---
- I have created a User and a Computer for the remote machine where
Apache is running (in the Active Directory)
- I have created a service principle for HTTP/apachehost@MYDOMAIN using
setspn.exe
- I have created the keytab using ktpass.exe and mapped the service
principle to the above user.
- I have added a forward and a reverse entry in the DNS running on the
ADS Server with the same name as used in the service principle.
The Apache host also uses this DNS.
- I have checked that both the w2k Server and the Apache server resolve
the host names correctly, forwards and backwards.
What else could be wrong? What more could I check?
Cheers,
Timo
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos