You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置PKI后kinit仍需输入密码?多平台Kerberos问题求助

Hey there, let's break down your two main issues step by step to get PKInit working properly:

1. Ubuntu: KDC Name Mismatch Error (AS-REP Code 11)

The "KDC name mismatch" error and code 11 (KDC_ERR_NAME_MISMATCH) almost always boils down to a mismatch between the KDC hostname you're targeting and what's in the KDC's SSL certificate. Here's how to fix it:

  • Replace KDC IP with Hostname in krb5.conf
    Your current config uses an IP address for the KDC (kdc = <ldap server IP>:88), but Kerberos PKInit validates that the KDC's certificate matches the hostname you're requesting tickets from. If the KDC's certificate was issued to a hostname (e.g., kdc.myrealm) instead of an IP, this mismatch triggers the error. Update your realm config to use the hostname:

    [realms]
    myrealm = {
        kdc = kdc.myrealm:88
        # ... rest of your config ...
    }
    

    Make sure the client can resolve this hostname (add it to /etc/hosts if DNS isn't set up).

  • Double-Check KDC Certificate Details
    Verify the KDC's certificate includes the hostname in either its Common Name (CN) or Subject Alternative Name (SAN) field. You can inspect it with:

    openssl x509 -in /path/to/kdc-cert.pem -text -noout
    

    Also confirm the certificate has the kpServerAuth EKU (OID 1.3.6.1.5.5.7.3.1) enabled, since your config enforces pkinit_eku_checking = kpServerAuth.

  • Align Client UPN with Kerberos Principal
    Ensure the UPN in your client certificate (kclientcert2.pem) exactly matches the principal you're passing to kinit (case matters—Kerberos realms are typically uppercase). For example, if your UPN is user@MYREALM, run kinit user@MYREALM instead of a different variation.

2. Embedded Linux Client: Still Prompting for Password

Copying PKInit libraries alone isn't always enough—you need to ensure everything is correctly configured and dependencies are met:

  • Lock Down Private Key Permissions
    Kerberos's PKInit module will refuse to use a private key with overly permissive permissions (it falls back to password auth instead). Set the correct permissions for your private key:

    chmod 600 /root/kclientkey2.pem
    
  • Validate krb5.conf PKInit Settings
    Double-check your pkinit_identities line—while your syntax looks correct, confirm the paths to the certificate and key are absolute and spelled right. Also, make sure the client CA cert (kclientca.pem) is trusted and correctly referenced.

  • Check Library Dependencies & Loading

    • Use ldd $(which kinit) to confirm your kinit binary links against the updated krb5 libraries you copied. If it's still using old system libraries, you may need to set LD_LIBRARY_PATH temporarily to point to your new libraries.
    • Verify the pkinit.so plugin is in the correct directory (usually /usr/lib/krb5/plugins/preauth/) and that it has the right permissions. Run ldd /usr/lib/krb5/plugins/preauth/pkinit.so to check for missing dependencies (like OpenSSL libraries—libssl.so and libcrypto.so are critical for PKInit).
  • Confirm PKInit Support in kinit
    Run kinit -h and look for PKInit-specific options (like -pkinit or -X pkinit...). If you don't see these, your kinit binary wasn't compiled with PKInit support. Copying plugins won't help here—you'll need to recompile the krb5 suite with the --enable-pkinit flag during configuration.

内容的提问来源于stack exchange,提问作者sreedhar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:13:19