Showing posts with label kerberos. Show all posts
Showing posts with label kerberos. Show all posts

Solution for GSS-API major_status:00090000, minor_status:861b6d0c

Problem: You are trying to configure mod_auth_kerb to work with Active Directory. You have created the technical user account "yourserver" for HTTP service in AD and associated it with the Kerberos SPN HTTP/your.server.com@YOURDOMAIN.COM using ktpass.exe. When accessing the page which requires Kerberos auth with IE, you see the following error messages in Apache error log (after raising LogLevel to debug):
[client nnn.nnn.nnn.nnn] Warning: received token seems to be NTLM, which isn't supported by the Kerberos module. Check your IE configuration.
src/mod_auth_kerb.c(1101): [client nnn.nnn.nnn.nnn] GSS-API major_status:00090000, minor_status:861b6d0c
[client nnn.nnn.nnn.nnn] gss_accept_sec_context() failed: A token was invalid (, Unknown code)
You have checked your IE (or Firefox) configuration and are pretty sure that the browser should be sending a Kerberos ticket instead of attempting NTLM authentication.

Solution: First apply some more diagnostics:
  1. Check if the command
    kvno HTTP/your.server.com@YOURDOMAIN.COM
    gives you this message: "HTTP/your.server.com@YOURDOMAIN.COM: Server not found in Kerberos database while getting credentials". If yes, you likely have the problem described here.
  2. On the Windows AD server check the output of setspn -l yourserver. Does it appear like so?
    Registered ServicePrincipalNames for CN=yoursever,OU=Service Accounts,OU=Accounts,DC=yourdomain,DC=com:
            HTTP/your.server.com@YOURDOMAIN.COM
    If yes, then you likely have the problem described here. The domain suffix highlighted in red should not appear in the command's output in a correct configuration.
To fix the incorrect SPN association, use the following commands on AD server:
setspn -d HTTP/your.server.com@YOURDOMAIN.COM yourserver
setspn -A HTTP/your.server.com yourserver

Solution for GSS-API major_status:000d0000, minor_status:96c73ae6

Problem: You are trying to configure mod_auth_kerb. When you access a page that requires Kerberos auth with IE, a popup asking for password appears. In Apache error log (after raising LogLevel to debug), you can see the following messages appearing:
[debug] src/mod_auth_kerb.c(1101): [client nnn.nnn.nnn.nnn] GSS-API major_status:000d0000, minor_status:96c73ae6
[error] [client nnn.nnn.nnn.nnn] gss_accept_sec_context() failed: Miscellaneous failure (, Unknown code)
Solution: Check that the kvno (key version number) stored in your keytab matches the kvno reported by the kvno command. You can view kvno from keytab using
klist -Kekt /path/to/keytab
Compare this against
kvno HTTP/your.server.com
The kvno command only works after a successful authentication with kinit. You can recreate your keytab with the expected kvno (in the example below: 3) using ktutil:
add_entry -password -p HTTP/your.server.com@YOURDOMAIN.COM -k 3 -e RC4-HMAC
wkt /path/to/newkeytab

Solution for "Key table entry not found while getting initial credentials"

Problem (with Kerberos on Debian stable):
kinit -V -k -t /tmp/keytab HTTP/somehost@LOCALDOMAIN
kinit: Key table entry not found while getting initial credentials
However klist -k -t /tmp/keytab works and correctly displays HTTP/somehost@LOCALDOMAIN as present under Principals. The keytab entry was previously created with using addent -password -p HTTP/somehost@LOCALDOMAIN -k 1 -e rc4-hmac.
Solution:
Had to adjust /etc/krb5.conf:
default_tkt_enctypes = arcfour-hmac-md5 des-cbc-crc des-cbc-md5
default_tgs_enctypes = arcfour-hmac-md5 des-cbc-crc des-cbc-md5
Source link