Troubleshooting
Problem
Doing a Windows-based installation and configuring an Active Directory namespace.
Symptom
Get the following errors when testing the Active Directory namespace.
[ ERROR ] CAM-AAA-0055 User input is required.
[ ERROR ] CAM-AAA-0036 Unable to authenticate because the credentials are invalid.
[ ERROR ] The encryption type requested is not supported by the KDC.
Cause
The encryption settings for Kerberos are mismatched between the server, and the user accounts in Active Directory.
Environment
Windows 2016 Server
Windows 2016 Domain controller
Diagnosing The Problem
On the Cognos Analytics server, check which types of encryption are enabled.
- On the server, start the Local Security Policy Editor (secpol.msc).
- Expand Security Settings ► Local policies ► Security options.
- Locate Network Security: Configure encryption types allowed for Kerberos.
- Select Properties. This policy setting allows customization of the encryption types that Kerberos is allowed to use.
Verify within Microsoft Active Directory which encryption settings are set for the computer or user running the Cognos Analytics service. Ensure that the object accepts the encryption type that is set for the server.
Resolving The Problem
Check, "This account supports Kerberos AES 128/256 bit encryption." on the service account in AD.
Document Location
Worldwide
[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSFKCN","label":"General Parallel File System"},"Component":"","Platform":[{"code":"PF033","label":"Windows"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]
Was this topic helpful?
Document Information
Modified date:
02 November 2021
UID
ibm11138390