cancel
Showing results for 
Search instead for 
Did you mean: 

keytab user permission

Jump to solution

Hi folks,

I'm facing a really strange error right now.
In my testlab I created a new infrastructure with a new domain where mwg is a member of.
I created the keytab while stirctly following this document.

Afterwards I uploaded the file to my mwg.

My rules for AD authentication is the following:
ADauth.PNGADauthentication

Then I wanted to access a website e.g. google.com. But my mwg requested username and password.
The time on the AD-controller and on my mwg are correct.
My DNS works fine, too. Deleting my kerberos tickets and the dns cache didn't help.
The keytab is correct. I managed to decrypt the encrypted kerberos authentication via wireshark.

The mwg-core.errors.log gave the following output:
ADauth2.PNG

This is an odd behaviour and I don't understand it.
In our productive environment I created the keytab and everything else like this and didn't face the error. Has someone a good explanation for this?

Labels (1)
1 Solution

Accepted Solutions
McAfee Employee jscholte
McAfee Employee
Report Inappropriate Content
Message 4 of 6

Re: keytab user permission

Jump to solution

I'm not sure why the permissions would be different, did you upload from the UI or the CLI?

Regardless, lets chmod the file to match mine:

chmod 644 /etc/krb5.mwg.keytab
5 Replies
Highlighted
McAfee Employee jscholte
McAfee Employee
Report Inappropriate Content
Message 2 of 6

Re: keytab user permission

Jump to solution

Weird... what MWG version are you on by chance?

Also, can you run this command?

# ll /etc/krb5.mwg.keytab
-rw-r--r-- 1 root root 977 Aug 28 17:49 /etc/krb5.mwg.keytab

Re: keytab user permission

Jump to solution

Hi jscholte,

we're using MWG version 7.7.1. UI Version is 7.7.2.16.0 (26564).

The output ist

-rw------- 1 root root 392 Sep  4 14:11 krb5.mwg.keytab

 

McAfee Employee jscholte
McAfee Employee
Report Inappropriate Content
Message 4 of 6

Re: keytab user permission

Jump to solution

I'm not sure why the permissions would be different, did you upload from the UI or the CLI?

Regardless, lets chmod the file to match mine:

chmod 644 /etc/krb5.mwg.keytab

Re: keytab user permission

Jump to solution

Hi jscholte,

I uploaded the file via the GUI.

After changing the rights the authentication via kerberos was successful.

But it's still strange...

McAfee Employee jscholte
McAfee Employee
Report Inappropriate Content
Message 6 of 6

Re: keytab user permission

Jump to solution

You could try uploading it again and seeing what permissions you get. If its 600, then thats a problem, if you get 644, then I'd say we're safe.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community