Why am I getting "KrbException: Invalid argument (400) - Cannot find key of appropriate type to decrypt AP REP - RC4 with HMAC"?

Solution Verified - Updated -

Issue

  • I’m configuring Kerberos authentication for RH-SSO, but I received "KrbException: Invalid argument (400) - Cannot find key of appropriate type to decrypt AP REP - RC4 with HMAC" when I test Kerberos authentication. What is the issue?

  • Facing issues while configuring RH SSO Operator 7.6 on Openshift 4.x , SPNEGO login failed: java.security.PrivilegedActionException: GSSException: Failure unspecified at GSS-API level (Mechanism level: Invalid argument (400) - Cannot find key of appropriate type to decrypt AP-REQ - AES256 CTS mode with HMAC SHA1-96)

  • After upgrading from RH-SSO to RHBK, Kerberos authentication stop working with the error above

Environment

  • Red Hat Single Sign On (RH-SSO)
    • 7.x
  • Red Hat Build of Keycloak (RHBK)
    • 22.0
    • 24.0
    • 26.x

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content