Configuration:
MIT Kerberos 1.4
Solaris 9 Master
Solaris 9, MAC OSX, PC Clients
/usr/lib/ssh/sshd daemon using pam_krb5.so.1
Pre-Auth enabled
Issue:
MAC and PC clients using ssh authenticate successfully against Solaris 9
servers and Kerberos system.
ssh -l username hostA
username@hostA
Since ssh authentication is taking place on the SUN server, I took a
copy of the keytab file from the Master kerberos server and placed it
place of the one created by running ktadd on hostA... now hostA has a
copy of the kadm5.keytab from the Master server.
Once I did this (and this was the
Decrypt integrity check errors usually point to a keytab problem. Although
I'm somewhat unsure why you had to copy your kadm5.keytab from the master
server, you should have instead created keytabs for each host. In my setup (we
use Solaris 9 SEAM KDCs with Solaris 9 and Red Hat clients) for each