Skip to content

No key table entry found matching #308

Answered by simo5
lyrixx asked this question in Q&A
Discussion options

You must be logged in to vote

Your configuration says the server name is:

ServerName isyapp.foobar.fr
...
GssapiAcceptorName [email protected]

And yet some client is trying to access it as HTTP/prod-01-isy.prod.com@

In your keytab you have no entry for that last name, yet if it is a krb principal alias in the KDC it could be made to work by adding the ignore_acceptor_hostname option in krb5.conf, see: man krb5.conf for details

If prod-01-isy.prod.com is not a principal alias in your KDC, then you have to fix your clients to not do canonicalization (which is insecure anyway).
Modern Linux clients set canonicalization off by default, I do not know what other OSs do exactly but I think both Windows and Mac should av…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@hecht-a
Comment options

Answer selected by simo5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #307 on June 25, 2024 17:46.