Forum Discussion

Dev_56330's avatar
Dev_56330
Icon for Cirrus rankCirrus
Jun 30, 2018

Kerberos - Requesting ticket can't get forwardable tickets (-1765328163)

Can anyone provide details into how to resolve this error? I have included screenshots of my delegation account and Kerb SSO configuration. Not quite sure how to resolve this.

 

/Common/WDMSmartCardAuth:Common:df0ae4ff:UCCmap.size = 3 2018-06-30 14:29:47

 

/Common/WDMSmartCardAuth:Common:df0ae4ff:S4U ======> - NO cached S4U2Proxy ticket for user: user@DEMO.LAB server: HTTP/webserver.demo.lab@DEMO.LAB - trying to fetch 2018-06-30 14:29:47

 

/Common/WDMSmartCardAuth:Common:df0ae4ff:S4U ======> trying to fetch S4U2Proxy ticket for user: user@DEMO.LAB server: HTTP/webserver.demo.lab@DEMO.LAB 2018-06-30 14:29:47

 

/Common/WDMSmartCardAuth:Common:df0ae4ff:Kerberos: can't get S4U2Proxy ticket for server HTTP/webserver.demo.lab@DEMO.LAB - Requesting ticket can't get forwardable tickets (-1765328163) 2018-06-30 14:29:47

 

/Common/WDMSmartCardAuth:Common:df0ae4ff: Kerberos: Failed to get ticket for User: 'user@DEMO.LAB' accessing service: 'HTTP/webserver.demo.lab@DEMO.LAB'

 

 

2 Replies

  • Modified the delegation account to use "Any Authentication Protocol" and I am now able to obtain a kerberos ticket.

     

    • boneyard's avatar
      boneyard
      Icon for MVP rankMVP

      hehe, thanks for reporting back, was already predicting that when i saw the screenshot.

       

      still not enough Microsoft AD knowledge to understand why that other setting doesn't work.