A client name with an '@'

Nordgren, Bryce L -FS bnordgren at fs.fed.us
Tue Jun 2 16:14:59 EDT 2015


>>Or am I thinking wrong: Does kinit parse the user principal name into client and realm? 
>>Should I rename my realm to lowercase fedidcard.gov?

> Its either 12001000550281 at FEDIDCARD.GOV or its 12001000550281 at fedidcard.gov

That it is. Deleting the realm and recreating a lowercase realm fixed the issue. (I can't change the smart cards.) Now I probably should make sure that everyone's UPN is from the same realm...

Thanks all,
Bryce





More information about the Kerberos mailing list