SAP Knowledge Base Article - Preview

3794310 - Issue to create Kerberos keytab using ktpass

Symptom

  • Get the error when try to create Kerberos keytab using ktpass: ktpass /out name.keytab /princ serviceaccount@REALM.COM /pass "serviceaccountpassword" /kvno 255 /ptype KRB5_NT_PRINCIPAL /crypto ALL

    NOTE: creating a keytab but not mapping principal to any user.
    For the account to work within a Windows domain, the
    principal must be mapped to an account, either at the
    domain level (with /mapuser) or locally (using ksetup)
    If you intend to map serviceaccount@domain to an account through other means
    or don't need to map the user, this message can safely be ignored.
    KTPASS: Could not determine the correct principal type.
    If this keytab is intended for a computer account, please use /ptype KRB5_NT_SRV_HST
    If this keytab is intended for a user account, please use /ptype KRB5_NT_PRINCIPAL
  • There is double quotes in the password


Read more...

Environment

  • SAP BusinessObjects Business Intelligence platform 4.x/2025
  • Windows AD

Product

SAP BusinessObjects Business Intelligence platform 2025 ; SAP BusinessObjects Business Intelligence platform 4.3

Keywords

sso, windows ad, kerberos, keytab, ktpass, special characters, double quote, password quoting, idm.keytab, KTPASS: Could not determine the correct principal type , KBA , BI-BIP-AUT , Authentication, ActiveDirectory, LDAP, SSO, Vintela , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.