<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html lang="en-us" xml:lang="en-us"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta name="security" content="public" /> <meta name="Robots" content="index,follow" /> <meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' /> <meta name="DC.Type" content="concept" /> <meta name="DC.Title" content="Troubleshoot" /> <meta name="abstract" content="This section provides links to troubleshooting information about common problems for network authentication service, Enterprise Identity Mapping (EIM), and IBM-supplied applications that support Kerberos authentication." /> <meta name="description" content="This section provides links to troubleshooting information about common problems for network authentication service, Enterprise Identity Mapping (EIM), and IBM-supplied applications that support Kerberos authentication." /> <meta name="DC.Relation" scheme="URI" content="rzakh000.htm" /> <meta name="DC.Relation" scheme="URI" content="rzakhcommonerr.htm" /> <meta name="DC.Relation" scheme="URI" content="rzakhapperr.htm" /> <meta name="DC.Relation" scheme="URI" content="rzakhadvtapitracetool.htm" /> <meta name="DC.Relation" scheme="URI" content="rzakhadvtpase.htm" /> <meta name="copyright" content="(C) Copyright IBM Corporation 1998, 2006" /> <meta name="DC.Rights.Owner" content="(C) Copyright IBM Corporation 1998, 2006" /> <meta name="DC.Format" content="XHTML" /> <meta name="DC.Identifier" content="rzakhtrouble" /> <meta name="DC.Language" content="en-us" /> <!-- All rights reserved. Licensed Materials Property of IBM --> <!-- US Government Users Restricted Rights --> <!-- Use, duplication or disclosure restricted by --> <!-- GSA ADP Schedule Contract with IBM Corp. --> <link rel="stylesheet" type="text/css" href="./ibmdita.css" /> <link rel="stylesheet" type="text/css" href="./ic.css" /> <title>Troubleshoot</title> </head> <body id="rzakhtrouble"><a name="rzakhtrouble"><!-- --></a> <!-- Java sync-link --><script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script> <h1 class="topictitle1">Troubleshoot</h1> <div><p>This section provides links to troubleshooting information about common problems for network authentication service, Enterprise Identity Mapping (EIM), and IBM-supplied applications that support Kerberos authentication.</p> <ol><li>All <a href="rzakhplanwrkshts.htm#rzakhplanwrkshts">prerequisites</a> have been completed.</li> <li>Ensure that the user has a user profile on the iSeries™ and a principal on the Kerberos server. On the iSeries, verify the user exists by opening the Users and Groups in iSeries Navigator or using the <tt>WRKUSRPRF</tt> for a command line. On Windows<sup>®</sup> systems, verify the user exists by accessing the Active Directory Users and Computers folder.</li> <li>Check to see if the iSeries is contacting the Kerberos server by using the kinit command from Qshell Interpreter. If the kinit command fails, check to see if the i5/OS™ service principal has been registered on the Kerberos server. If it has not, you can <a href="rzakhdefineiseries.htm#rzakhdefineiseries">add the i5/OS principal</a> to the Kerberos server.</li> </ol> <p>For information about specific troubleshooting techniques, see the following topics:</p> </div> <div> <ul class="ullinks"> <li class="ulchildlink"><strong><a href="rzakhcommonerr.htm">Network authentication service errors and recovery</a></strong><br /> You may encounter these messages during the network authentication service wizard or when you are managing network authentication service properties in iSeries Navigator.</li> <li class="ulchildlink"><strong><a href="rzakhapperr.htm">Application connection problems and recovery</a></strong><br /> You may encounter these messages when applications use network authentication service.</li> <li class="ulchildlink"><strong><a href="rzakhadvtapitracetool.htm">API trace tool</a></strong><br /> You can set up the API trace tool to troubleshoot problems with Kerberos and Generic Security Services API calls.</li> <li class="ulchildlink"><strong><a href="rzakhadvtpase.htm">Troubleshoot Kerberos server in i5/OS PASE</a></strong><br /> Troubleshoot Kerberos server in i5/OS PASE by accessing status and informational log files.</li> </ul> <div class="familylinks"> <div class="parentlink"><strong>Parent topic:</strong> <a href="rzakh000.htm" title="Network authentication service allows the iSeries server and several iSeries services, such as iSeries eServer Access for Windows, to use a Kerberos ticket as an optional replacement for a user name and password for authentication.">Network authentication service</a></div> </div> </div> </body> </html>