[22286] in Kerberos
RE: Fedora2/Apache2 and Key Version Error
daemon@ATHENA.MIT.EDU (Scott Moseman)
Thu Aug 26 17:20:35 2004
From: "Scott Moseman" <smoseman@novolink.net>
To: "'Nebergall, Christopher'" <cneberg@sandia.gov>, <kerberos@mit.edu>
Date: Thu, 26 Aug 2004 10:20:54 -0500
Message-ID: <005001c48b80$4840d660$0b41bcd0@novolink.net>
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit
In-Reply-To: <16F54D8E44BBEE4BBBDB5EFB3AEEB86D0102EF83@es06snlnt.sandia.gov>
Errors-To: kerberos-bounces@mit.edu
We blew away all service accounts in AD (2003) and removed all of
the keytab files on the Fedora2 box. Re-created two accounts for
host and http, re-created two keytabs for host and http, and moved
them onto the Fedora2/Apache2 box.
We used kutil to put both tickets into the /etc/krb5.keytab file.
We used kinit and verified -my- account and both service accounts.
All of them authenticated just fine.
Using KerbTray, we do get the HTTP ticket from Apache2 now, but we
get: (Key version number for principal in key table is incorrect).
Thanks,
Scott Moseman
-----Original Message-----
From: Nebergall, Christopher [mailto:cneberg@sandia.gov]
Sent: Wednesday, August 25, 2004 3:52 PM
To: 'Scott Moseman'; kerberos@MIT.EDU
Subject: RE: Fedora2/Apache2 and Key Version Error
gss_accept_sec_context() failed: Miscellaneous failure
> (Key version number for principal in key table is incorrect)
The key in your keytab file does not match the key that the Active
Directory
has for the server principal or you have changed the key multiple times
recently IE is using an older version of the key which it will cache
till it
expires.
-Christopher
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos