[Freeipa-users] Windows client logon

Simo Sorce simo at redhat.com
Mon Sep 19 14:31:46 UTC 2011


On Mon, 2011-09-19 at 10:10 -0400, Jimmy wrote:
> I have verified that the password set for the workstation in the
> kerberos host principal(using ipa-getkeytab) and the password on the
> host (using ksetup) are the same. I'm still getting the " Decrypt
> integrity check failed" errors. I have also verified that the system
> clock is accurate on both the KDC and the workstation. What else could
> be causing this? As I have said, this system authenticates flawlessly
> against other KDC's I have set up.

The thing that is failing is your user password does not check with what
the KDC thinks is the user's secret. You are not yet to the stage where
the machine password is tried.

Simo.
> 

-- 
Simo Sorce * Red Hat, Inc * New York




More information about the Freeipa-users mailing list