[22227] in Kerberos

home help back first fref pref prev next nref lref last post

Integrated Windows Login: No principal in keytab matches desired name

daemon@ATHENA.MIT.EDU (Timo Fuchs)
Wed Aug 18 15:33:18 2004

From: Timo Fuchs <fuechsle@cs.tu-berlin.de>
Date: 17 Aug 2004 08:05:28 GMT
Message-ID: <cfse88$f61$1@news.cs.tu-berlin.de>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

Hi,

I am trying to set up an integrated windows login scenario using apache
and mod_auth_gss_krb5 (http://modgssapache.sourceforge.net) according
to http://www.onlamp.com/pub/a/onlamp/2003/09/11/kerberos.html?page=1.

However, Apache cannot authenticate:
-- snip ---
gss_acquire_cred() failed: No principal in keytab matches desired name:
--- snap ---

- I have created a User and a Computer for the remote machine where
  Apache is running (in the Active Directory)
- I have created a service principle for HTTP/apachehost@MYDOMAIN using
  setspn.exe
- I have created the keytab using ktpass.exe and mapped the service
  principle to the above user.
- I have added a forward and a reverse entry in the DNS running on the
  ADS Server with the same name as used in the service principle.
  The Apache host also uses this DNS.
- I have checked that both the w2k Server and the Apache server resolve
  the host names correctly, forwards and backwards.

What else could be wrong? What more could I check?

Cheers,
Timo
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post