We are attempting to configure Mac OS for smart card login with QAS 4.2. There are no issues testing the card or reader, however when running 'vastool smartcard login test' the following error gets returned:
vas_id_establish_cred_pkcs11: Failed to get initial cred. failed
ERROR: could not establish initial credentials
ERROR: VAS_ERR_KRB5: Kerberos error Failed to obtain credentials.
Client: USER@EXAMPLE.COM, Service: krbtgt/EXAMPLE.COM@EXAMPLE.COM, Server: dc01.example.com Caused by: KRB5_KDC_ERR_INVALID_CERTIFICATE (-1765328313): Certificate invalid Reason: KDC have wrong realm name in the certificate
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center