• Re: Issue with Kerberos authentication using API / MSLSA ccache type

    From Ken Hornstein@21:1/5 to Samir Sayyed on Sat Nov 23 13:51:42 2024
    Copy: kerberos@mit.edu (kerberos@mit.edu)
    Copy: Prachi.Raikar2@ibm.com (Prachi Raikar)
    Copy: Sneha.Lodha3@ibm.com (Sneha Lodha)
    Copy: Aayush.Kumar3@ibm.com (Aayush Kumar)

    We are using 1.20 Kerberos library on our Windows platform for
    authenticating with our Netezza server.

    Are you sure you are using MIT Kerberos? Because based on the messages
    below it sure seems like you actually using the Java Kerberos library
    and I was under the impression that was it's own thing. Also, the
    debug messages you show are not ones typically generated by MIT Kerberos.
    E.g.:

    Java config name: C:\ProgramData\MIT\Kerberos5\krb5.ini
    Loading krb5 profile at C:\ProgramData\MIT\Kerberos5\krb5.ini
    Loaded from Java config
    KdcAccessibility: reset
    KdcAccessibility: reset
    Acquire TGT from Cache
    Principal is MYUSER@NZSQA.IBM.COM
    null credentials from Ticket Cache

    Nothing I can find in MIT Kerberos generates these messages. MIT
    Kerberos debug messages (which are generated by setting the KRB5_TRACE environment variable) look like this:

    [1613] 1732387726.184428: Response was from primary KDC
    [1613] 1732387726.184429: Processing preauth types: PA-ETYPE-INFO2 (19)

    --Ken

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)