Re: [EXT] 'HANDLE_AUTHDATA' error when trying to setup Kerberos trust between AD and FreeIPA

Robbie Harwood <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.general
Message-ID <[email protected]>
Robert Sturrock <[email protected]> writes:

> Hi Dmitri,
>
> Sorry - I did not give all the background in the interests of brevity.
> We do not want to establish a full trust between AD and IPA (at this
> stage).  This is for a number of reasons, but is primarily a
> reluctance to bring a very large and entirely irrelevant set of AD
> groups across to IPA-enrolled hosts.
>
> The IPA installation is running in a ‘winsync’ arrangement with AD,
> but as a convenience for the users it would be useful if a TGT from AD
> were sufficient to access services in the IPA realm, to save them
> having to ‘kinit' to another kerberos realm.
>
> So I’m interested in establishing a trust at the Kerberos level only.
> We have done this successfully between a legacy MIT kerberos service
> and IPA, so I hoped we could also set one up between AD and IPA,
> before running into the error I described.
>
> Any clues as to what the reason for the ‘HANDLE_AUTHDATA’ error might be?

For context, the full error is:

    kvno: KDC returned error string: HANDLE_AUTHDATA while getting credentials for host/[email protected]

Anyway, first step is to check the KDC logs (since that's who generated
the error) - there's possibly more information there.

Thanks,
--Robbie

________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos
signature.asc (application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEA5qc6hnelQjDaHWqJTL5F2qVpEIFAl7op78ACgkQJTL5F2qV
pEKwJBAAss6lb7zovh5bZg3L3Ua0YxKxDBTx9pFseVZSGPXSDM3yfAJ4sDsAlRFu
ikJkDmFuaAj/JsCLxS/b9b/fQ3bDdjdE1Uj1v+0t5K4BwrY9S9Y7Zh7Y816hCxla
hm1GIapgcCWL1lXNCprEHCUH1N8Uo56P5ceBN8hRAoSeygDGjrbenzx0rbbWqwMB
KVScMhZFhmtno9+LR/wYVZY7WSsgrv1Pm0ZZTFs6IWQIOzvTboLxxTNq3xtPovPl
dHR1ZGMG9+BdLb/9HWN3xPhv4OGDic3bY45Arm96Fpq/0+MonYx3hhdGu3stM+8q
wQV/IH+1gcMMES9rD4FxwQxRZhzuXI2ed4+7/5tMoPTIpfs5VXMmR1ghEk5IzZOC
mTKoZXKSxYjUcWaIjRbr5ih51uOpIGVmBBrV3oLklx7biHWB4E1DepUsVUD/579b
k7+HTzS+I+twKdEK/R2QtxHIV2LV3o1cJuBQsld8UTEW4MEBaXMgiSaF7Hb9S+mU
274Q/xjSdZe/y4kPK/MXq6kJXJPhK9dafrmAUBKhQdq5hjwEhmIYI7KHcCvhRnaH
1g0HPux99SgjxHQ8fOR39d0ZQRd1NGFCBx8A+Q8rr6y2eSbasNgkB/lWHMob36QB
g4JZ1qLVw7ugU1XPM8O3Ls+aN679aPl3JzQC+FzPoAIS5QmwuuY=
=MWfQ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.