Hello. I'm having trouble with sso kerberos authentication. Openfire server hosted on Ubuntu 12.04 LTS, DC - WinServer 2008 R2. Clients have WinXP or Win7.
When i'm trying to login from WinXP i get error:
GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: KDC has no support for encryption type (14))]
From Win7:
GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Illegal key size)]
Any help with this problem would be appreciated?
krb5.ini
[libdefaults] default_realm = MIS.PNCENTER.RU default_tkt_enctypes = rc4-hmac des3-cbc-sha1 des-cbc-crc des-cbc-md5 default_tgs_enctypes = rc4-hmac des3-cbc-sha1 des-cbc-crc des-cbc-md5 permitted_enctypes = rc4-hmac des3-cbc-sha1 des-cbc-crc des-cbc-md5
[realms]
MIS.PNCENTER.RU = { kdc = mis.pncenter.ru admin_server = mis.pncenter.ru default_domain = MIS.PNCENTER.RU }
[domain_realm] .mis.pncenter.ru = MIS.PNCENTER.RU mis.pncenter.ru = MIS.PNCENTER.RU
gss.conf
com.sun.security.jgss.accept {
com.sun.security.auth.module.Krb5LoginModule required storeKey=true keyTab=/usr/share/openfire/resources/xmpp.keytab doNotPrompt=true useKeyTab=true realm=MIS.PNCENTER.RU principal=xmpp/openfire.mis.pncenter.ru@MIS.PNCENTER.RU debug=true isInitiator=false;
};
krb5.conf
[libdefaults] default_realm = MIS.PNCENTER.RU kdc_timesync = 1 forwardable = true proxiable = true default_tkt_enctypes = rc4-hmac des3-cbc-sha1 des-cbc-crc des-cbc-md5 default_tgs_enctypes = rc4-hmac des3-cbc-sha1 des-cbc-crc des-cbc-md5 permitted_enctypes = rc4-hmac des3-cbc-sha1 des-cbc-crc des-cbc-md5
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[realms]
MIS.PNCENTER.RU = { kdc=orionserver.mis.pncenter.ru admin_server=orionserver.mis.pncenter.ru default_domain=mis.pncenter.ru }
[domain_realm]
mis.pncenter.ru = MIS.PNCENTER.RU .mis.pncenter.ru = MIS.PNCENTER.RU