GSSAPI on Linux using Windows AD Servers as KDCs - Errors about Keytab Entries

Jason D. McCormick jason at devrandom.org
Mon Jan 7 13:51:33 EST 2008


Douglas E. Engert wrote:
> The problem might be that on the AD account the UserAccountControl flag
> does not have the USE_DES_KEY_ONLY 0x200000 set, So AD is returning an
> ArcFour ticket, which is not in the keytab. ktpass has a /DESOnly option
> to set this.
> 
> See kb 305144 too.

This is EXACTLY what I needed.  Everything works now.  Thanks to
everyone for the help.

- Jason



More information about the Kerberos mailing list