[22646] in Kerberos
Re: WindowsXP/Solaris : incorrect key version number
daemon@ATHENA.MIT.EDU (Tyson Oswald)
Wed Oct 6 15:45:01 2004
From: oswaldt@ameritech.net (Tyson Oswald)
Date: 6 Oct 2004 12:22:17 -0700
Message-ID: <89e9a6c3.0410061122.47871ccf@posting.google.com>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
Jacques,
I ran into a simlar issue with going form Solaris to Windows AD.
ktpass increments the ktnvo every time tyou run it against an account,
and will create your keytab with the ktvno. On our servers the
account created always started with 4. Make sure that your keytab is
the most recent generated, and that you don't have multiple prinicpals
in your keytab on the serve with different ktvno numbers.
Tyson
Jacques.Lebastard@evidian.com (Jacques Lebastard) wrote in message news:<416403E0.2070308@evidian.com>...
> Hi there,
>
> a few days ago, I succeeded in running a SSPI/GSS-API client/server
> program between an XP workstation and a Solaris server. The server's
> keytab was generated using Windows 'ktpass' tool.
>
> I generated another keytab file using the same tool (with the same
> parameters) and installed that keytab file on the server.
>
> Now, the server claims it cannot accept the token :
> gss_accept_sec_context: Invalid credential was supplied
> gss_accept_sec_context: Key version number for principal in key table is
> incorrect
>
> I tried to generate another keytab file using the -kvno 1 option but to
> no avail.
>
> What did I miss ?
> --
> Mr. Jacques LEBASTARD mailto:jacques.lebastard@evidian.com
> EVIDIAN S.A. www.evidian.com
> Rue Jean Jaurès Tel: +33 1 30 80 77 86
> F-78340 LES CLAYES SOUS BOIS Fax: +33 1 30 80 77 99
>
>
>
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos