[38165] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Fwd: Authentication issues using cyrus-sasl from librdkafka on

daemon@ATHENA.MIT.EDU (Ken Hornstein)
Fri Jan 12 14:55:11 2018

Message-Id: <201801121954.w0CJsXLL024322@hedwig.cmf.nrl.navy.mil>
From: Ken Hornstein <kenh@cmf.nrl.navy.mil>
To: Marcel Gutsche <mail@marcelgutsche.de>
In-Reply-To: <CANXUXjm4n_kN9UybF=V1ZZFMpmn2RJOb8J8o_ywZM7vqfZRoiA@mail.gmail.com>
MIME-Version: 1.0
Date: Fri, 12 Jan 2018 14:54:32 -0500
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

>I have a hard time troubleshooting an error. I posted the issue
>already here (https://github.com/edenhill/librdkafka/issues/1630) and
>here (https://github.com/cyrusimap/cyrus-sasl/issues/501), but to no
>avail.

It might be helpful to describe what the underlying Kerberos implementation
is on the server side.  The key error is "Matching credential not found";
you can ignore everything else.

I know nothing about kafka, in terms of who is a client or server, but ...
you posted this config file snippet:

'sasl.kerberos.service.name': 'kafka',
'sasl.kerberos.principal': 'user@principal,
'sasl.kerberos.keytab': keytab_file,

Are you sure 'user@principal' is correct?  If that's on the server side,
that would strike me as unlikely (not knowing the details of Kafka).

--Ken
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post