Troubleshooting PKINIT
Troubleshooting PKINIT Issues¶
PKINIT (Public Key Infrastructure Initialization) relies on secure certificate-based authentication between clients and domain controllers. Failures in PKINIT can stem from misconfigured certificates, network issues, or Kerberos misconfigurations. Below are steps to diagnose and resolve common PKINIT authentication problems.
1. Verify Certificate Validity and Trust Chain¶
Ensure the client certificate is valid, trusted, and properly configured:
- Check certificate validity:
KDC Authentication).
-
Validate trust chain:
Ensure all intermediate and root certificates are trusted by the client’s certificate store.
Usecertutilto verify the certificate chain:
-
Confirm certificate store location:
Certificates must be placed in theLocalMachine\Mystore for PKINIT to recognize them.
2. Check KDC Configuration¶
Verify the Key Distribution Center (KDC) settings on domain controllers:
- Confirm KDC role:
Ensure the domain controller has the KDC role enabled via:
- Validate KDC trust settings:
Useksetupto check KDC trust configuration:
Ensure the KDC is correctly configured with the domain’s DNS name and CA trust settings.
3. Validate Time Synchronization¶
PKINIT requires precise time synchronization between clients and domain controllers:
- Check NTP configuration:
Ensure all systems are synchronized with a reliable NTP source:
w32tm /resync to force resynchronization if drift exceeds 5 minutes.
- Verify time zone consistency:
Ensure all systems are set to the same time zone and regional settings.
4. Review Event Logs for Errors¶
Check the Security and System event logs on both clients and domain controllers for PKINIT-related errors:
- Common error codes:
- Event ID 4768: "A Kerberos authentication ticket was issued." (Normal, but verify if it’s a one-time event.)
- Event ID 4769: "A Kerberos authentication ticket was revoked." (Indicates certificate revocation issues.)
- Event ID 4766: "A Kerberos authentication ticket was issued for a user account." (Normal, but check for repeated occurrences.)
- Query specific logs:
5. Test Network Connectivity and Firewall Rules¶
Ensure network connectivity and firewall rules allow PKINIT traffic:
- Test ports 88 (Kerberos) and 464 (Kerberos) UDP/TCP:
Test-NetConnection -ComputerName <DCName> -Port 88
Test-NetConnection -ComputerName <DCName> -Port 464
- Check firewall exceptions:
Ensure the domain controller’s firewall allows inbound traffic on ports 88 and 464 for the client’s IP or subnet.
6. Client-Side Configuration¶
Ensure the client is properly configured for PKINIT:
- Enroll certificate:
Use certutil or the Certification Authority snap-in to enroll a certificate for the client.
-
Verify certificate enrollment:
-
Check client’s certificate store:
Confirm the certificate is present in theLocalMachine\Mystore and marked as trusted forKDC Authentication.
Key takeaways¶
- Certificates must be valid, trusted, and correctly stored in the client’s certificate store.
- KDC configuration on domain controllers must align with the domain’s DNS and CA trust settings.
- Time synchronization within 5 minutes is critical for PKINIT to function.
- Event logs provide actionable insights into Kerberos and certificate-related failures.
- Network connectivity and firewall rules must allow Kerberos traffic (ports 88 and 464).