Troubleshooting

 

 

 

 

 

 

 

Troubleshooting Kerberos

Table 11-2

 

Troubleshooting Scenarios (Continued)

 

 

 

 

 

 

 

 

 

 

Cannot find/read stored

 

This problem occurs

Provide the master

 

master key while

 

when the stash file is not

key as a

 

getting master key.

 

found.

command-line option.

 

 

 

 

 

 

 

You can also create

 

 

 

 

 

 

 

the stash file.

 

 

 

 

 

 

 

 

 

Error verifying

 

This problem occurs due

Enter the correct

 

pre-authentication data

 

to an incorrect password.

password.

 

type 2.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Service key not

 

This problem can occur if

Create identical key

 

available while getting

 

your principal has a

types.

 

initial credentials.

 

3DES key but not a DES

 

 

 

 

 

key and the Kerberos

 

 

 

 

 

client does not support

 

 

 

 

 

3DES, or vice versa.

 

 

 

 

 

 

 

 

Table 11-3

 

Troubleshooting Scenarios for your LDAP-based Kerberos

 

 

server

 

 

 

 

 

 

 

 

 

 

 

 

 

Scenario

 

Cause

 

Troubleshooting

 

 

 

 

 

 

 

Tips

 

 

 

 

 

 

 

 

 

LDAP entry type

 

The Kerberos server

 

Remove the reference

 

 

not supported

 

does not support

 

entries associated with

 

 

 

 

 

reference entries.

 

the Kerberos attribute.

 

 

 

 

 

 

 

 

 

Incomplete

 

One or more

 

Delete the Kerberos

 

 

Kerberos entry in

 

Kerberos principal

 

principal and recreate

 

 

LDAP

 

attributes are

 

it. This could indicate a

 

 

 

 

 

missing or corrupted

 

potential security

 

 

 

 

 

in the Directory

 

problem.

 

 

 

 

 

server.

 

 

 

 

 

 

 

 

 

 

 

Another Kerberos

 

The DN that you

 

Specify another DN as

 

 

principal associated

 

have specified for the

 

you can associate only

 

 

with this DN

 

Kerberos principal is

 

one Kerberos principal

 

 

 

 

 

already associated

 

with any DN.

 

 

 

 

 

with another

 

 

 

 

 

 

 

Kerberos principal.

 

 

 

 

 

 

 

 

 

 

Chapter 11

299