Re: recent certificate failure for pkinit

2024-07-08 Thread Ken Hornstein via Kerberos
>> KDC: >> KDC_RETURN_PADATA:WELLKNOWN/anonym...@example.com for krbtgt/ >> example@example.com, Failed to verify own certificate (depth 0): unable >> to get local issuer certificate > >I've run into this error before. MIT's KDC, for some bizarre reason, >insists that its server cert validate

Re: recent certificate failure for pkinit

2024-07-08 Thread Carson Gaspar
On 7/8/2024 2:54 PM, Matt Zagrabelny via Kerberos wrote: Greetings Kerberos-users, I've been successfully using OTP and pkinit for the past year or so. Within the last week, or so, it has started to fail with: client: $ /usr/bin/kinit -n -c /tmp/.kerberos_cache kinit: Preauthentication failed

recent certificate failure for pkinit

2024-07-08 Thread Matt Zagrabelny via Kerberos
Greetings Kerberos-users, I've been successfully using OTP and pkinit for the past year or so. Within the last week, or so, it has started to fail with: client: $ /usr/bin/kinit -n -c /tmp/.kerberos_cache kinit: Preauthentication failed while getting initial credentials KDC: KDC_RETURN_PADATA: W