Lexmark X925 Common Criteria Installation Supplement and Administrator Guide - Page 40

User is logged out almost immediately after logging

Page 40 highlights

40 "Realm on the card was not found in the Kerberos Configuration File" error message This error occurs during Smart Card login. UPLOAD A KERBEROS CONFIGURATION FILE AND MAKE SURE THE REALM HAS BEEN ADDED TO THE FILE The PKI Authentication settings do not support multiple Kerberos Realm entries. If multiple realms are needed, then you must create and upload a krbf5.conf file containing the needed realms. If you are already using a Kerberos configuration file, then verify that the missing realm has been added to the file correctly. "Client [NAME] unknown" error message This error indicates that the KDC being used to authenticate the user does not recognize the User Principal Name specified in the error message. VERIFY THAT THE DOMAIN CONTROLLER INFORMATION IS CORRECT 1 From the Embedded Web Server, click Settings > Device Solutions > Solutions (eSF) > PKI Authentication > Configure. 2 If the Simple Kerberos Setup has been configured, then verify that the IP address or host name of the Domain Controller is correct. 3 If you are using a Kerberos configuration file, then verify that the Domain Controller entry is correct. Login does not respond at "Getting User Info" For information about LDAP‑related issues, see"LDAP issues" on page 41. User is logged out almost immediately after logging in INCREASE THE PANEL LOGIN TIMEOUT INTERVAL 1 From the Embedded Web Server, click Settings > Security > Miscellaneous Security Settings > Login Restrictions. 2 Increase the time (in seconds) of the Panel Login Timeout setting, and then click Submit to save your changes.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56

“Realm on the card was not found in the Kerberos Configuration File” error
message
This error occurs during Smart Card login.
U
PLOAD
A
K
ERBEROS
CONFIGURATION
FILE
AND
MAKE
SURE
THE
REALM
HAS
BEEN
ADDED
TO
THE
FILE
The PKI Authentication settings do not support multiple Kerberos Realm entries. If multiple realms are needed, then
you must create and upload a krbf5.conf file containing the needed realms. If you are already using a Kerberos
configuration file, then verify that the missing realm has been added to the file correctly.
“Client [NAME] unknown” error message
This error indicates that the KDC being used to authenticate the user does not recognize the User Principal Name
specified in the error message.
V
ERIFY
THAT
THE
D
OMAIN
C
ONTROLLER
INFORMATION
IS
CORRECT
1
From the Embedded Web Server, click
Settings
>
Device Solutions
>
Solutions (eSF)
>
PKI Authentication
>
Configure
.
2
If the Simple Kerberos Setup has been configured, then verify that the IP address or host name of the Domain
Controller is correct.
3
If you are using a Kerberos configuration file, then verify that the Domain Controller entry is correct.
Login does not respond at “Getting User Info”
For information about LDAP
related issues, see“LDAP issues” on page 41.
User is logged out almost immediately after logging in
I
NCREASE
THE
P
ANEL
L
OGIN
T
IMEOUT
INTERVAL
1
From the Embedded Web Server, click
Settings
>
Security
>
Miscellaneous Security Settings
>
Login Restrictions
.
2
Increase the time (in seconds) of the Panel Login Timeout setting, and then click
Submit
to save your changes.
40