# Problem with active directory integration- Kerberus

**URL:** <https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925>\
**Category:** Configuring the server\
**Tags:** authentication\
**Created:** [May 24, 2020, 2:34pm UTC](https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925 "2020-05-24T14:34:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dudu](https://avatars.discourse-cdn.com/v4/letter/d/3ec8ea/32.png) [@dudu](https://forum.keycloak.org/u/dudu)\
**Post date:** [May 24, 2020, 2:34pm UTC](https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925/1 "2020-05-24T14:34:39Z")

</div>

Hi ,  
I have set up my keycloak to integrate with LDAP and Kerberos for SSO. I have failed to log in and I’m getting the following errors.

1. I’m running keycloak on top of Kubernetes
2. I didn’t configure krb5.conf - Should I ?
3. I have found the following file :cat /etc/krb5.conf.d/crypto-policies  
ermitted\_enctypes = aes256-cts-hmac-sha1-96 aes256-cts-hmac-sha384-192 camellia256-cts-cmac aes128-cts-hmac-sha1-96 aes128-cts-hmac-sha256-128 camellia128-cts-cmac

should I add RC4 with HMAC  
4.How can I tell if the keytab was found?

14:23:31,516 INFO [stdout] (default task-20) principal is HTTP/auth.hunting.dudu.com@LAB.LOCAL  
14:23:31,516 INFO [stdout] (default task-20) Will use keytab  
14:23:31,517 INFO [stdout] (default task-20) Commit Succeeded  
14:23:31,517 INFO [stdout] (default task-20)  
14:23:31,519 WARN [org.keycloak.federation.kerberos.impl.SPNEGOAuthenticator] (default task-20) SPNEGO login failed: java.security.PrivilegedActionException: GSSException: Failure unspecified at GSS-API level (Mechanism level: Invalid argument (400) - Cannot find key of appropriate type to decrypt AP-REQ - RC4 with HMAC)  
at java.base/java.security.AccessController.doPrivileged(Native Method)  
at java.base/javax.security.auth.Subject.doAs(Subject.java:423)  
at org.keycloak.keycloak-kerberos-federation@9.0.0//org.keycloak.federation.kerberos.impl.SPNEGOAuthenticator.authenticate(SPNEGOAuthenticator.java:68)  
at org.keycloak.keycloak-ldap-federation@9.0.0//org.keycloak.storage.ldap.LDAPStorageProvider.authenticate(LDAPStorageProvider.java:694)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.credential.UserCredentialStoreManager.authenticate(UserCredentialStoreManager.java:350)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.authentication.authenticators.browser.SpnegoAuthenticator.authenticate(SpnegoAuthenticator.java:89)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.authentication.DefaultAuthenticationFlow.processSingleFlowExecutionModel(DefaultAuthenticationFlow.java:496)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.authentication.DefaultAuthenticationFlow.processFlow(DefaultAuthenticationFlow.java:306)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.authentication.AuthenticationProcessor.authenticateOnly(AuthenticationProcessor.java:998)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.authentication.AuthenticationProcessor.authenticate(AuthenticationProcessor.java:860)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.protocol.AuthorizationEndpointBase.handleBrowserAuthenticationRequest(AuthorizationEndpointBase.java:150)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.protocol.oidc.endpoints.AuthorizationEndpoint.buildAuthorizationCodeAuthorizationResponse(AuthorizationEndpoint.java:465)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.protocol.oidc.endpoints.AuthorizationEndpoint.process(AuthorizationEndpoint.java:160)  
at org.keycloak.keycloak-services@9.0.0//org.keycloak.protocol.oidc.endpoints.AuthorizationEndpoint.buildGet(AuthorizationEndpoint.java:111)  
at jdk.internal.reflect.GeneratedMethodAccessor741.invoke(Unknown Source)  
at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)  
at java.base/java.lang.reflect.Method.invoke(Method.java:566)  
at org.jboss.resteasy.resteasy-jaxrs@3.9.1.Final//org.jboss.resteasy.core.MethodInjectorImpl.invoke(MethodInjectorImpl.java:138)  
at org.jboss.resteasy.resteasy-jaxrs@3.9.1.Final//org.jboss.resteasy.core.ResourceMethodInvoker.internalInvokeOnTarget(ResourceMethodInvoker.java:517)  
at org.jboss.resteasy.resteasy-jaxrs@3.9.1.Final//org.jboss.resteasy.core.ResourceMethodInvoker.invokeOnTargetAfterFilter(ResourceMethodInvoker.java:406)  
at org.jboss.resteasy.resteasy-jaxrs@3.9.1.Final//org.jboss.resteasy.core.ResourceMethodInvoker.lambda$invokeOnTarget$0(ResourceMethodInvoker.java:370)  
at org.jboss.resteasy.resteasy-jaxrs@3.9.1.Final//org.jboss.resteasy.core.interception.PreMatchContainerRequestContext.filter(PreMatchContainerRequestContext.java:35

---

<div class="post-metadata">

**Author:** ![Lacota](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@Lacota](https://forum.keycloak.org/u/Lacota)\
**Post date:** [May 25, 2020, 6:57pm UTC](https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925/2 "2020-05-25T18:57:49Z")

</div>

I’m getting the exact same error. I have an Active Directory domain but am not using Kubernetes.

---

<div class="post-metadata">

**Author:** ![chasx003](https://avatars.discourse-cdn.com/v4/letter/c/b487fb/32.png) [@chasx003](https://forum.keycloak.org/u/chasx003)\
**Post date:** [May 27, 2020, 4:37am UTC](https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925/3 "2020-05-27T04:37:39Z")

</div>

I know this isn’t helpful, but I’ve have the same issue (both on Kubernetes, and local Docker)

It appears to work on keycloak:7.0.0, but none of the images after. I did notice the “base image” that is used to build the keycloak image changes after 7.0.0, so I suspect that could have something to do with it?

From googling, that error seems to deal more with the the app not having permissions to the keytab file? (If you just put in garbage in text box, you’ll get the same error, which leads me to believe its not actually being parsed)

---

<div class="post-metadata">

**Author:** ![dudu](https://avatars.discourse-cdn.com/v4/letter/d/3ec8ea/32.png) [@dudu](https://forum.keycloak.org/u/dudu)\
**Post date:** [May 27, 2020, 5:24am UTC](https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925/4 "2020-05-27T05:24:38Z")

</div>

I have managed to overcome this problem by adding “rc4-hmac” to crepto-policies file

---

<div class="post-metadata">

**Author:** ![chasx003](https://avatars.discourse-cdn.com/v4/letter/c/b487fb/32.png) [@chasx003](https://forum.keycloak.org/u/chasx003)\
**Post date:** [May 27, 2020, 5:33am UTC](https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925/5 "2020-05-27T05:33:18Z")

</div>

Awesome to hear! Are you manually adding it, or creating your own image?

---

<div class="post-metadata">

**Author:** ![chasx003](https://avatars.discourse-cdn.com/v4/letter/c/b487fb/32.png) [@chasx003](https://forum.keycloak.org/u/chasx003)\
**Post date:** [May 27, 2020, 3:28pm UTC](https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925/6 "2020-05-27T15:28:38Z")

</div>

in case anyone finds this via google, I added the rc4-hmac, and had no luck. I ended up redoing my keytab following instructions here

> <https://stackoverflow.com/questions/49282283/kerberos-aes-256-keytab-does-not-work/49304368#49304368>

and am now up and running

---

<div class="post-metadata">

**Author:** ![pkadian](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/pkadian/32/1354_2.png) [@pkadian](https://forum.keycloak.org/u/pkadian)\
**Post date:** [September 8, 2020, 11:55am UTC](https://forum.keycloak.org/t/problem-with-active-directory-integration-kerberus/2925/7 "2020-09-08T11:55:54Z")

</div>

Dear all,

I am facing the same issue but this time issue is little different.

11:21:27,509 TRACE [org.keycloak.federation.kerberos.impl.SPNEGOAuthenticator] (default task-1) Going to establish security context  
11:21:27,643 WARN [org.keycloak.federation.kerberos.impl.SPNEGOAuthenticator] (default task-1) SPNEGO login failed: java.security.PrivilegedActionException: GSSException: Failure unspecified at GSS-API level (Mechanism level: Checksum failed)  
at java.base/java.security.AccessController.doPrivileged(Native Method)  
at java.base/javax.security.auth.Subject.doAs(Subject.java:423)  
at org.keycloak.keycloak-kerberos-federation@9.0.5.redhat-00001//org.keycloak.federation.kerberos.impl.SPNEGOAuthenticator.authenticate(SPNEGOAuthenticator.java:68)  
at org.keycloak.keycloak-ldap-federation@9.0.5.redhat-00001//org.keycloak.storage.ldap.LDAPStorageProvider.authenticate(LDAPStorageProvider.java:701)  
at org.keycloak.keycloak-services@9.0.5.redhat-00001//org.keycloak.credential.UserCredentialStoreManager.authenticate(UserCredentialStoreManager.java:365)  
at org.keycloak.keycloak-services@9.0.5.redhat-00001//org.keycloak.authentication.authenticators.browser.SpnegoAuthenticator.authenticate(SpnegoAuthenticator.java:89)  
at org.keycloak.keycloak-services@9.0.5.redhat-00001//org.keycloak.authentication.DefaultAuthenticationFlow.processSingleFlowExecutionModel(DefaultAuthenticationFlow.java:438)

Caused by: GSSException: Failure unspecified at GSS-API level (Mechanism level: Checksum failed  
Caused by: KrbException: Checksum failed  
at java.security.jgss/sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType.decrypt(Aes256CtsHmacSha1EType.java:102)  
at java.security.jgss/sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType.decrypt(Aes256CtsHmacSha1EType.java:94)  
at java.security.jgss/sun.security.krb5.EncryptedData.decrypt(EncryptedData.java:180)  
at java.security.jgss/sun.security.krb5.KrbApReq.authenticate(KrbApReq.java:281)  
Caused by: java.security.GeneralSecurityException: Checksum failed  
at java.security.jgss/sun.security.krb5.internal.crypto.dk.AesDkCrypto.decryptCTS(AesDkCrypto.java:451)  
at java.security.jgss/sun.security.krb5.internal.crypto.dk.AesDkCrypto.decrypt(AesDkCrypto.java:272)  
11:21:27,650 INFO [stdout] (default task-1) [Krb5LoginModule]: Entering logout  
11:21:27,650 INFO [stdout] (default task-1) [Krb5LoginModule]: logged out Subject  
11:21:27,650 TRACE [org.keycloak.storage.ldap.LDAPStorageProvider] (default task-1) SPNEGO Handshake not successful  
11:21:27,702 WARN [org.keycloak.services] (default task-1) KC-SERVICES0013: Failed authentication: org.keycloak.authentication.AuthenticationFlowException  
at org.keycloak.keycloak-services@9.0.5.redhat-00001//org.keycloak.authentication.DefaultAuthenticationFlow.processResult(DefaultAuthenticationFlow.java:489)
