How to Enable Kerberos Credential Delegation (TGT Forwarding) from Windows Client to RHEL via SSH
Issue
- Kerberos TGT not transferred with SSH login from Windows clients to RHEL systems.
- Kerberos authentication completes successfully, but credential delegation (TGT forwarding) does not occur.
- Error observed in SSH debug logs:
debug1: Next authentication method: gssapi-with-mic
debug1: Delegating credentials
debug1: sspi delegation was requested but not fulfilled
debug1: Delegating credentials
debug1: sspi delegation was requested but not fulfilled
Environment
- Red Hat Enterprise Linux 7/8/9/10
- Active Directory
- Windows clients using OpenSSH with Kerberos (GSSAPI) authentication
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.