SAP Knowledge Base Article - Preview

3715238 - kvno: Wrong principal in request while decrypting ticket for hdb/server@domain" when updating the Kerberos key

Symptom

After updating the Kerberos keys and tickets using AES256 The error below occurs. 

-------- CHECK keytab ----------------------------------------------------------
Checking key version number and key in keytab /usr/sap/SID/etc/krb5_hdb.keytab for SPN hdb/server ...FAILED
    ERROR:   Key version numbers match, but keys in local keytab /usr/sap/SID/etc/krb5_hdb.keytab and AD are different.
      COMMAND: $DIR_EXECUTABLE/krb5/bin/kvno -k /usr/sap/SID/etc/krb5_hdb.keytab hdb/server@domain
      RETURN CODE: 1
      STDERR: "hdb/server@domain: kvno = 3, keytab entry invalid
kvno: Wrong principal in request while decrypting ticket for hdb/server@domain"
--------------------------------------------------------------------------------


Read more...

Environment

  • SAP HANA Database 1.0
  • SAP HANA Database 2.0

Product

SAP HANA, platform edition 2.0

Keywords

KVNO, kvno: Wrong principal in request while decrypting ticket, keytab, AES256, updating the Kerberos key, keytab entry invalid, kerberos, setspn, ktpass,  , KBA , HAN-DB-SEC , SAP HANA Security & User Management , How To

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.