Wrong principal in request

Jeff Blaine jblaine at kickflop.net
Wed Dec 30 13:33:14 EST 2009


Just me again, stumped...

Client: PuTTY-GSSAPI from Matt Loar configured to perform GSSAPI
         authentication only, KfW 3.2, credentials for jblaine at FOO

Server: CentOS 5.3, MIT Kerberos 1.6.x, Russ Alberry's pam_krb5

Failure: Aside from GSSAPI not being used...

sshd[12234]: pam_krb5RA(sshd:auth): pam_sm_authenticate: entry (0x1)
sshd[12234]: pam_krb5RA(sshd:auth): (user jblaine) attempting 
authentication as jblaine at FOO
sshd[12234]: pam_krb5RA(sshd:auth): (user jblaine) credential 
verification failed: Wrong principal in request

======================================================================

Client: Solaris 10 SPARC, credentials for jblaine at FOO

         /usr/bin/ssh -l jblaine -o "GSSAPIAuthentication yes" -o
         "GSSAPIDelegateCredentials yes" 192.168.1.6

Server: CentOS 5.3, MIT Kerberos 1.6.x, Russ Alberry's pam_krb5
         (Same as previous failure)

Failure:

sshd[12256]: Postponed gssapi-with-mic for jblaine from 192.168.1.240 
port 32812 ssh2
sshd[12255]: debug1: Unspecified GSS failure.  Minor code may provide 
more information\nWrong principal in request\n

======================================================================



More information about the Kerberos mailing list