Re: [EXT] 'HANDLE_AUTHDATA' error when trying to setup Kerberos trust between AD and FreeIPA
Robbie Harwood <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.general |
|---|---|
| Message-ID | <[email protected]> |
Robert Sturrock <[email protected]> writes: > Hi Dmitri, > > Sorry - I did not give all the background in the interests of brevity. > We do not want to establish a full trust between AD and IPA (at this > stage). This is for a number of reasons, but is primarily a > reluctance to bring a very large and entirely irrelevant set of AD > groups across to IPA-enrolled hosts. > > The IPA installation is running in a ‘winsync’ arrangement with AD, > but as a convenience for the users it would be useful if a TGT from AD > were sufficient to access services in the IPA realm, to save them > having to ‘kinit' to another kerberos realm. > > So I’m interested in establishing a trust at the Kerberos level only. > We have done this successfully between a legacy MIT kerberos service > and IPA, so I hoped we could also set one up between AD and IPA, > before running into the error I described. > > Any clues as to what the reason for the ‘HANDLE_AUTHDATA’ error might be? For context, the full error is: kvno: KDC returned error string: HANDLE_AUTHDATA while getting credentials for host/[email protected] Anyway, first step is to check the KDC logs (since that's who generated the error) - there's possibly more information there. Thanks, --Robbie ________________________________________________ Kerberos mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/kerberos
signature.asc
(application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEA5qc6hnelQjDaHWqJTL5F2qVpEIFAl7op78ACgkQJTL5F2qV pEKwJBAAss6lb7zovh5bZg3L3Ua0YxKxDBTx9pFseVZSGPXSDM3yfAJ4sDsAlRFu ikJkDmFuaAj/JsCLxS/b9b/fQ3bDdjdE1Uj1v+0t5K4BwrY9S9Y7Zh7Y816hCxla hm1GIapgcCWL1lXNCprEHCUH1N8Uo56P5ceBN8hRAoSeygDGjrbenzx0rbbWqwMB KVScMhZFhmtno9+LR/wYVZY7WSsgrv1Pm0ZZTFs6IWQIOzvTboLxxTNq3xtPovPl dHR1ZGMG9+BdLb/9HWN3xPhv4OGDic3bY45Arm96Fpq/0+MonYx3hhdGu3stM+8q wQV/IH+1gcMMES9rD4FxwQxRZhzuXI2ed4+7/5tMoPTIpfs5VXMmR1ghEk5IzZOC mTKoZXKSxYjUcWaIjRbr5ih51uOpIGVmBBrV3oLklx7biHWB4E1DepUsVUD/579b k7+HTzS+I+twKdEK/R2QtxHIV2LV3o1cJuBQsld8UTEW4MEBaXMgiSaF7Hb9S+mU 274Q/xjSdZe/y4kPK/MXq6kJXJPhK9dafrmAUBKhQdq5hjwEhmIYI7KHcCvhRnaH 1g0HPux99SgjxHQ8fOR39d0ZQRd1NGFCBx8A+Q8rr6y2eSbasNgkB/lWHMob36QB g4JZ1qLVw7ugU1XPM8O3Ls+aN679aPl3JzQC+FzPoAIS5QmwuuY= =MWfQ -----END PGP SIGNATURE-----