• Register
0 votes
1.1k views

Problem :

I am working on the configuring SSO in obiee 11.1.1.7.14, where in which I am facing a issue in the step while configuring my krb5.conf and executing a kinit command.

Few notes regarding a Active Directory

· We have more than the one domain controller and to balance a request we are maintaing a load balancer with a port 3269.

· And a integration between obiee and a MSAD is successfully done with a load balancer name as host and a port as 3269.

· And few certificates have also been added in a demotrust.jks and to a ovd store and SSL is enabled in a new provider.

· Keytab file generated and also placed in obiee domain home, the krb5.conf and krb5Login.conf file also modified accordingly.

I have created my keytab file and placed it in my obiee domain home, then modified my krb5.conf by keeping a kdc as a one of the ip address of a domain controller and admin-server as a name of a domain controller. And while executing a

kinit -V -k -t /location/keytabfile.keytab HTTP/obiee_host_name

I have encountered the error as "kinit(v5): Client not found in Kerberos database while getting initial credentials" . Kindly share your ideas or suggestions to solve above issue.

7 5 2
3,870 points

Please log in or register to answer this question.

1 Answer

0 votes

Solution :

 First of all, this is the serverfault.

  1. 3269 is not a Kerberos, this is a SSL-backed global catalog. Pure LDAP not a Kerberos. Not a interesting here.
  1. Do not put a KDC IP addresses in a krb5.conf but rather rely on a DNS SRV records just like a Windows does.
  1. You cannot kinit with the SPN. kinit expects the UPN (from AD) from a keytab. Something like accountname$@EXAMPLE.COM if this is the machine account. Always remember, the SPN is always bound to some account, whether it is a machine or functional.
9 7 4
38,600 points

Related questions

0 votes
1 answer 35 views
35 views
Problem: kinit: password incorrect while getting initial credentials
asked Feb 18 Ethan ross 2.7k points
1 vote
1 answer 1.3K views
1.3K views
Problem: I am very new to Kerberos and Hadoop. I tried to create the "user.keytab" file by "ktutil" to try to renew a krb ticket without the use of the password as it was recommended in some online tutorial. Please find below the procedure I ... credentials Please find below my environment details for your reference: My OS: Centos Linux, My Cluster: Cloudera Hadoop Distribution, My Tool: Kerberos
asked May 27, 2020 Martin K 6.6k points
0 votes
1 answer 4 views
4 views
Problem: I'll make a submission for a response to my question. Please, I have searched the internet but have not found any useful material, and I am now having trouble continuing my studies.
asked Apr 1 rakib1 51.5k points
0 votes
1 answer 5 views
5 views
Problem: Need to find the solution please help me with this . The value of _stdout is incorrect .
asked Mar 21 PkGuy 13.1k points
0 votes
1 answer 8 views
8 views
Problem: I am struggling to get a SQL Server connection from machine A to machine B which is running the SQL Server. I would be happy to generate more debug info, just tell me what you need.
asked Mar 20 ummesalma 25.2k points
0 votes
1 answer 1K views
1K views
Problem : I am implementing kerberos Authentication in my existing java spring application.My unix team has provided me SPN, krb5.conf and keytab file. I am trying hard but getting unable to obtain password from user exception
asked Oct 22, 2019 peterlaw 6.9k points
0 votes
1 answer 5 views
5 views
Problem: As I previously stated in my question, I am having difficulty learning. Could someone help assist me in completing my project?
asked Apr 1 rakib1 51.5k points
0 votes
1 answer 4 views
4 views
Problem: I need assistance in resolving this problem: The hosted network couldn't be started the group or resource is not in the correct state to perform
asked Apr 1 rakib1 51.5k points
0 votes
1 answer 6 views
6 views
Problem: What are my options for dealing with this issue? what are my options for dealing with this issue
asked Apr 1 rakib1 51.5k points
0 votes
1 answer 2 views
2 views
Problem: How can I deal with this problem: If you inherit a class, you do not inherit the class' constructors. true or false?
asked Apr 1 rakib1 51.5k points