cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2323
Views
15
Helpful
11
Replies

nac AD SSO integration with Microsoft server 2008 error

nataymenessa
Level 1
Level 1

this is my problem

C:\Program Files (x86)\Support Tools>ktpass.exe  -princ casuser/AFRICANUNION.LOCAL@AFRICANUNION.LOCAL -mapuser c
asuser -pass cisco -out c:\casuser.keytab -ptype KRB5_NT_PRINCIPAL +DesOnly
Error loading resource: 0x00003b01
Error loading resource: 0x00003b01
Error loading resource: 0x00003b01
Error loading resource: 0x00003b01
Error loading resource: 0x00003b01

why is it showing me this error any idea?

11 Replies 11

Tiago Antunes
Cisco Employee
Cisco Employee

Hi,

I am afraid you are running the ktpass with the wrong sintaxe.

Please take a look into the config guide:

http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cas/s_adsso.html#wp1174556.

You will see the steps for creating the user and how to run the ktpass command, as weel what is the correct version of the tool and the correct sintaxe for each version of AD.

HTH,

Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

yeah i saw that document but i don't know where i made the mistake

Well, can you send us a screenshot of the user account like it is showed in:

http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cas/s_adsso.html#wp1160497.

What is the complete version of Win2008 Server? SP? R?

What is the ktpass version?

Are you running an 2008 AD environment or 2008 with 2003 functional level?

Thanks,

Tiago

Windows Server 2008-Enterprise Edition, SP1, R1

ktpass version: 6.0.6001.22331

yes, we are running windows server 2008 AD Environment

Hi,

I see there are a couple of things you missed...so i would advise to read carefully the documentation as the ktpass run process tend to become very easy to fail...

The version of CAM/CAS you are running 4.7.2, supports Windows 2008 Enterprise SP1 (32-bit only), however you have to:

- Apply Microsoft Windows Hotfix KB951191 (http://support.microsoft.com/kb/951191)
- Use the native Windows 2008 KTPass tool (6.0.6001.18000)
-  (Optional) Issue the KTPass command using a slash (/) instead of a dash  (-), as instructed in the Microsoft TechNet support page (http://technet.microsoft.com/en-us/library/cc753771.aspx) The following illustrates an example command:
C:\Program  Files\Support Tools> ktpass.exe /princ  sanac/TestAD01.testdom.com@TESTDOM.COM /mapuser sanac /pass 123456sS  /out c:\casuser.keytab /ptype KRB5_NT_PRINCIPAL +DesOnly

This information can be found at:

http://www.cisco.com/en/US/docs/security/nac/appliance/support_guide/agntsprt.html#wp103146.

and

http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cas/s_adsso.html#wp1240376.

Example:

C:\Program  Files\Support Tools> ktpass.exe /princ casuser/africanunion.local@AFRICANUNION.LOCAL /mapuser casuser /pass Cisco123  /out c:\casuser.keytab /ptype KRB5_NT_PRINCIPAL +DesOnly

HTH,

Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

where can i find ktpass.exe version 6.0.6001.18000

As you can read the document I already shared with you...on Microsoft.

HTH,

Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

yeah, i found the link on the document but i could not locate support tools there, i think they moved it.

and onother thing is our AD is 2008 with 2003 functionality so we need ktpass version 6.0.6001.18000 if i am not mistaken

Yes, you are correct.

HTH,
Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

so  how do i find this version...shall i email to microsoft? or any ideas?

Yep, i think the best would be get in touch with microsoft.

HTH,

Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

Review Cisco Networking for a $25 gift card