配置PKI后kinit仍需输入密码?多平台Kerberos问题求助
Hey there, let's break down your two main issues step by step to get PKInit working properly:
The "KDC name mismatch" error and code 11 (KDC_ERR_NAME_MISMATCH) almost always boils down to a mismatch between the KDC hostname you're targeting and what's in the KDC's SSL certificate. Here's how to fix it:
Replace KDC IP with Hostname in krb5.conf
Your current config uses an IP address for the KDC (kdc = <ldap server IP>:88), but Kerberos PKInit validates that the KDC's certificate matches the hostname you're requesting tickets from. If the KDC's certificate was issued to a hostname (e.g.,kdc.myrealm) instead of an IP, this mismatch triggers the error. Update your realm config to use the hostname:[realms] myrealm = { kdc = kdc.myrealm:88 # ... rest of your config ... }Make sure the client can resolve this hostname (add it to
/etc/hostsif DNS isn't set up).Double-Check KDC Certificate Details
Verify the KDC's certificate includes the hostname in either its Common Name (CN) or Subject Alternative Name (SAN) field. You can inspect it with:openssl x509 -in /path/to/kdc-cert.pem -text -nooutAlso confirm the certificate has the
kpServerAuthEKU (OID1.3.6.1.5.5.7.3.1) enabled, since your config enforcespkinit_eku_checking = kpServerAuth.Align Client UPN with Kerberos Principal
Ensure the UPN in your client certificate (kclientcert2.pem) exactly matches the principal you're passing tokinit(case matters—Kerberos realms are typically uppercase). For example, if your UPN isuser@MYREALM, runkinit user@MYREALMinstead of a different variation.
Copying PKInit libraries alone isn't always enough—you need to ensure everything is correctly configured and dependencies are met:
Lock Down Private Key Permissions
Kerberos's PKInit module will refuse to use a private key with overly permissive permissions (it falls back to password auth instead). Set the correct permissions for your private key:chmod 600 /root/kclientkey2.pemValidate krb5.conf PKInit Settings
Double-check yourpkinit_identitiesline—while your syntax looks correct, confirm the paths to the certificate and key are absolute and spelled right. Also, make sure the client CA cert (kclientca.pem) is trusted and correctly referenced.Check Library Dependencies & Loading
- Use
ldd $(which kinit)to confirm your kinit binary links against the updated krb5 libraries you copied. If it's still using old system libraries, you may need to setLD_LIBRARY_PATHtemporarily to point to your new libraries. - Verify the
pkinit.soplugin is in the correct directory (usually/usr/lib/krb5/plugins/preauth/) and that it has the right permissions. Runldd /usr/lib/krb5/plugins/preauth/pkinit.soto check for missing dependencies (like OpenSSL libraries—libssl.soandlibcrypto.soare critical for PKInit).
- Use
Confirm PKInit Support in kinit
Runkinit -hand look for PKInit-specific options (like-pkinitor-X pkinit...). If you don't see these, your kinit binary wasn't compiled with PKInit support. Copying plugins won't help here—you'll need to recompile the krb5 suite with the--enable-pkinitflag during configuration.
内容的提问来源于stack exchange,提问作者sreedhar

