ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 157 - SK0-005 discussion

Report
Export

A technician learns users are unable to tog in to a Linux server with known-working LDAP credentials. The technician logs in to the server with a local account and confirms the system is functional can communicate over the network, and is configured correctly However, the server log has entries regarding Kerberos errors. Which of the following is the MOST likely source of the issue?

A.
A local firewall is blocking authentication requests.
Answers
A.
A local firewall is blocking authentication requests.
B.
The users have expired passwords
Answers
B.
The users have expired passwords
C.
The system clock is off by more than five minutes
Answers
C.
The system clock is off by more than five minutes
D.
The server has no access to the LDAP host
Answers
D.
The server has no access to the LDAP host
Suggested answer: C

Explanation:

Kerberos is a network authentication protocol that uses tickets to allow clients and servers to prove their identity to each other. Kerberos relies on accurate time synchronization between the parties involved, as the tickets have expiration dates and timestamps. If the system clock of a Linux server is off by more than five minutes from the LDAP server or the domain controller, the Kerberos authentication will fail and generate errors. A local firewall is unlikely to block authentication requests if the server can communicate over the network and is configured correctly. The users’ passwords are not relevant if they are known-working LDAP credentials. The server has access to the LDAP host if it can communicate over the network and is configured correctly. Reference:

https://access.redhat.com/documentation/enus/red_hat_enterprise_linux/6/html/identity_management_guide/kerberos_errors https://www.ibm.com/docs/en/aix/7.2?topic=authentication-kerberos-time-synchronization

asked 02/10/2024
Carlos Evangelista
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first