Skip to content

No key table entry found matching #308

Answered by simo5
lyrixx asked this question in Q&A
Discussion options

You must be logged in to vote

Your configuration says the server name is:

ServerName isyapp.foobar.fr
...
GssapiAcceptorName HTTP@isyapp.foobar.fr

And yet some client is trying to access it as HTTP/prod-01-isy.prod.com@

In your keytab you have no entry for that last name, yet if it is a krb principal alias in the KDC it could be made to work by adding the ignore_acceptor_hostname option in krb5.conf, see: man krb5.conf for details

If prod-01-isy.prod.com is not a principal alias in your KDC, then you have to fix your clients to not do canonicalization (which is insecure anyway).
Modern Linux clients set canonicalization off by default, I do not know what other OSs do exactly but I think both Windows and Mac should av…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@hecht-a
Comment options

Answer selected by simo5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #307 on June 25, 2024 17:46.

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy