Error "The call to Kerberos 5 failed" when trying to join Edge SWG (ProxySG) appliance to domain
book
Article ID: 166960
calendar_today
Updated On:
Products
ProxySG Software - SGOS
Issue/Introduction
You receive the error "The call to Kerberos 5 failed" when trying to join an Edge SWG (ProxySG) appliance to the domain during IWA-Direct authentication configuration.
Cause
The issue is caused by one of the following:
Join credentials contain complex or Cyrillic characters.
You previously joined the domain, left the domain, and are trying to join again using the Join option (not Rejoin).
DNS cannot resolve resolve _kerberos-master._tcp.domain.com.
Old DNS records exist, causing the Kerberos KDC name to be resolved incorrectly.
Resolution
Perform the appropriate step to resolve the issue.
Simplify the password. Although complex passwords are supported, Kerberos might not be able to decrypt them if the contain non-UTF8 characters.
Delete the machine account from Active Directory and click Join again.
Force the DNS server to resolve _kerberos-master._tcp.domain.com to a good Kerberos master domain for TCP communication.