KDC does not respond within the required time
Try one or more of the following:
M
AKE
SURE
THAT
THE
IP
ADDRESS
OR
HOST
NAME
OF
THE
KDC
IS
CORRECT
1
From the Embedded Web Server, click
Settings
>
Device Solutions
>
Solutions (eSF)
>
PKI Authentication
>
Configure
.
2
For Simple Kerberos Setup, make sure that the IP address or host name specified for the Domain Controller is
correct.
3
Apply the changes.
M
AKE
SURE
THAT
THE
KDC
IS
AVAILABLE
You can specify multiple KDCs in the PKI Authentication settings or in the krb5.conf file.
M
AKE
SURE
THAT
P
ORT
88
IS
NOT
BLOCKED
BY
A
FIREWALL
Port 88 must be opened between the printer and the KDC for authentication to work.
Cannot find user realm in the Kerberos configuration file
M
AKE
SURE
THAT
THE
W
INDOWS
D
OMAIN
IS
SPECIFIED
IN
THE
K
ERBEROS
SETTINGS
1
From the Embedded Web Server, click
Settings
>
Device Solutions
>
Solutions (eSF)
>
PKI Authentication
>
Configure
.
2
From the Simple Kerberos Setup, add the Windows Domain in lowercase to the Domain setting.
For example, if the Domain setting is
mil,.mil
and the Windows Domain is
x.y.z
, then change the Domain
setting to
mil,.mil,x.y.z
.
3
If you are using a krb5.conf file, then add an entry to the domain_realm section. Map the lowercase Windows
domain to the uppercase realm (similar to the existing mapping for the “mil” domain).
Cannot find realm on card in the Kerberos configuration file
This error occurs during smart card login.
U
PLOAD
A
K
ERBEROS
CONFIGURATION
FILE
AND
MAKE
SURE
THAT
THE
REALM
HAS
BEEN
ADDED
TO
THE
FILE
The PKI Authentication settings do not support multiple Kerberos Realm entries. If multiple realms are needed, then
create and upload a krbf5.conf file containing the needed realms. If you are already using a Kerberos configuration
file, then make sure that the missing realm is correctly added to the file.
Troubleshooting
61