OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • Wrong KVNO in Squid configuration compared to the generated keytab
« previous next »
  • Print
Pages: [1]

Author Topic: Wrong KVNO in Squid configuration compared to the generated keytab  (Read 87 times)

Heiwa24

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Wrong KVNO in Squid configuration compared to the generated keytab
« on: November 20, 2024, 09:15:52 am »
Hello All,
Configuring the Squid with Kerberos enabled authentication, I get an error in cache.log:

kid1| ERROR: Negotiate Authentication validating user. Result: {result=BH, notes={message: gss_accept_sec_context() failed: Unspecified GSS failure. Minor code may provide more information. Cannot find key for HTTP/myopnsensebox.domain.com@DOMAIN..COM kvno 1 in keytab; }}

And that is normal as the show keytab display that:

Keytab name: FILE:/usr/local/etc/squid/squid.keytab
KVNO Principal
---- --------------------------------------------------------------------------
   3 MYOPNSENSEBOX-K$@DOMAIN.COM
   3 MYOPNSENSEBOX-K$@DOMAIN.COM
   3 MYOPNSENSEBOX-K$@DOMAIN.COM
   3 host/myopnsensebox@DOMAIN.COM
   3 host/myopnsensebox@DOMAIN.COM
   3 host/myopnsensebox@DOMAIN.COM
   3 HTTP/myopnsensebox.domain.com@DOMAIN.COM
   3 HTTP/myopnsensebox.domain.com@DOMAIN.COM
   3 HTTP/myopnsensebox.domain.com@DOMAIN.COM


That are all in KVNO 3...

The question is: How to change the Squid configuration to ask for KVNO 3 ?

Thank you for your help.
« Last Edit: November 20, 2024, 11:01:10 am by Heiwa24 »
Logged

Heiwa24

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: Wrong KVNO in Squid configuration compared to the generated keytab
« Reply #1 on: November 21, 2024, 09:50:49 am »
For information: it has been fixed by itself... I have no idea of the reason...

Before that, I have rebooted the OPNSense box with no luck, quit an restarted the client Firefox browser with no luck... Strange.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • Wrong KVNO in Squid configuration compared to the generated keytab
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2