Symptom
- Get the error when try to create Kerberos keytab using ktpass: ktpass /out name.keytab /princ serviceaccount@REALM.COM /pass "serviceaccountpassword" /kvno 255 /ptype KRB5_NT_PRINCIPAL /crypto ALL
NOTE: creating a keytab but not mapping principal to any user.
For the account to work within a Windows domain, the
principal must be mapped to an account, either at the
domain level (with /mapuser) or locally (using ksetup)
If you intend to map serviceaccount@domain to an account through other means
or don't need to map the user, this message can safely be ignored.
KTPASS: Could not determine the correct principal type.
If this keytab is intended for a computer account, please use /ptype KRB5_NT_SRV_HST
If this keytab is intended for a user account, please use /ptype KRB5_NT_PRINCIPAL - There is double quotes in the password
Read more...
Environment
- SAP BusinessObjects Business Intelligence platform 4.x/2025
- Windows AD
Product
SAP BusinessObjects Business Intelligence platform 2025 ; SAP BusinessObjects Business Intelligence platform 4.3
Keywords
sso, windows ad, kerberos, keytab, ktpass, special characters, double quote, password quoting, idm.keytab, KTPASS: Could not determine the correct principal type , KBA , BI-BIP-AUT , Authentication, ActiveDirectory, LDAP, SSO, Vintela , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview