Oracle 10g R2 on Linux with Kerberos 5 2005-11-08 - By Maimon Oded
Hi all, I'm getting desperate.. I've a working KDC on linux (RH3-U5), i can authenticate to my other linux machines with it, i can run rsh,telnet with that KDC. so the kdc is working. i'm trying to configure oracle 10gR2 (also on linux) with it, but i guss i'm missing something very important. the OS kinit command is working, oracle okinit command is not working, i'm getting:
*[oracle@(protected) admin]$ okinit*
*Kerberos Utilities for Linux: Version 10.2.0.1.0 - Production on 08-NOV-2005 15:31:34*
*Copyright (c) 1996, 2004 Oracle. All rights reserved.*
*Password for **oracle@(protected)* <oracle@(protected)>*: okinit: Password incorrect okinit: Decrypt integrity check failed *
my sqlnet.ora:
*NAMES.DIRECTORY_PATH= (TNSNAMES) SQLNET.AUTHENTICATION_SERVICES = (KERBEROS5) SQLNET.KERBEROS5_KEYTAB = /etc/krbora10g.keytab SQLNET.KERBEROS5_CONF = /etc/krb5.conf SQLNET.KERBEROS5_CONF_MIT = TRUE SQLNET.AUTHENTICATION_KERBEROS5_SERVICE = ora10g TRACE_LEVEL_CLIENT = SUPPORT TRACE_LEVEL_SERVER = SUPPORT TRACE_DIRECTORY_CLIENT = /tmp/clnt TRACE_DIRECTORY_SERVER = /tmp/srv*
the owner of /etc/krbora10g.keytab is oracle:dba.
running kinit, and then running "sqlplus /@(protected)" return:
*SQL*Plus: Release 10.2.0.1.0 - Production on Tue Nov 8 15:46:02 2005*
*Copyright (c) 1982, 2005, Oracle. All rights reserved.*
*ERROR: ORA-12638 (See ORA-12638.ora-code.com): Credential retrieval failed *
pleaaaaasssssseee, HELP!
Oded.
<div>Hi all,</div> <div>I'm getting desperate..</div> <div> </div> <div>I've a working KDC on linux (RH3-U5), i can authenticate to my other linux machines with it, i can run rsh,telnet with that KDC.</div> <div>so the kdc is working.</div> <div> </div> <div>i'm trying to configure oracle 10gR2 (also on linux) with it, but i guss i 'm missing something very important.</div> <div>the OS kinit command is working, oracle okinit command is not working, i'm getting:</div> <div> <p><strong><em>[oracle@(protected) admin]$ okinit</em></strong></p> <p><strong><em>Kerberos Utilities for Linux: Version 10.2.0.1.0 - Production on 08-NOV-2005 15:31:34</em></strong></p> <p><strong><em>Copyright (c) 1996, 2004 Oracle. All rights reserved.</em> </strong></p> <p><strong><em>Password for </em></strong><a href="mailto:oracle@(protected)"> <strong><em>oracle@(protected)</em></strong></a><strong><em>:<br>okinit: Password incorrect<br>okinit: Decrypt integrity check failed<br></em></strong> </p> <p>my sqlnet.ora:</p> <p><strong><em>NAMES.DIRECTORY_PATH= (TNSNAMES)<br>SQLNET.AUTHENTICATION _SERVICES = (KERBEROS5)<br>SQLNET.KERBEROS5_KEYTAB = /etc/krbora10g.keytab<br >SQLNET.KERBEROS5_CONF = /etc/krb5.conf<br>SQLNET.KERBEROS5_CONF_MIT = TRUE <br>SQLNET.AUTHENTICATION_KERBEROS5_SERVICE = ora10g<br>TRACE_LEVEL_CLIENT = SUPPORT<br>TRACE_LEVEL_SERVER = SUPPORT<br>TRACE_DIRECTORY_CLIENT = /tmp/clnt <br>TRACE_DIRECTORY_SERVER = /tmp/srv</em></strong><br></p> <p>the owner of /etc/krbora10g.keytab is oracle:dba.</p> <p>running kinit, and then running "sqlplus /@(protected)" return:</p> <p><strong><em>SQL*Plus: Release 10.2.0.1.0 - Production on Tue Nov 8 15:46:02 2005</em></strong></p> <p><strong><em>Copyright (c) 1982, 2005, Oracle. All rights reserved.</em ></strong></p> <p><strong><em>ERROR:<br>ORA-12638 (See ORA-12638.ora-code.com): Credential retrieval failed<br></em>< /strong></p> <p>pleaaaaasssssseee, HELP!</p> <p>Oded.</p></div>
|
|