RH-SSO Kerberos Authentication Error: SPNEGO login failed: java.security.PrivilegedActionException: GSSException: Failure unspecified at GSS-API level (Mechanism level: Checksum failed)

Solution Verified - Updated -

Issue

  • When trying to authenticate users using a Kerberos keytab on an Active Directory User federation, all GSSAPI authentications result in a checksum failure

    WARN  [org.keycloak.federation.kerberos.impl.SPNEGOAuthenticator] (executor-thread-1) SPNEGO login failed: java.security.PrivilegedActionException: GSSException: Failure unspecified at GSS-API level (Mechanism level: Checksum failed)
    at java.base/java.security.AccessController.doPrivileged(AccessController.java:716)
    at java.base/javax.security.auth.Subject.doAs(Subject.java:439)
    

Environment

  • Red Hat build of Keycloak(RHBK)
    • 22.x
  • Operator

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content