ORA-12638 With Kerberos Authentication Against MSAD Using Windows Credential Cache (Doc ID 1958479.1)

Last updated on OCTOBER 12, 2016

Applies to:

Advanced Networking Option - Version 12.1.0.2 and later
Information in this document applies to any platform.

Symptoms

On : 12.1.0.2 version, Secure Network Services

When attempting to use Kerberos Authentication against MSAD
the following error occurs.

ERROR
-----------------------
ORA-12638

STEPS
-----------------------
The issue can be reproduced at will with the following steps:
1. edit the client sqlnet.ora:
NAMES.DIRECTORY_PATH=(TNSNAMES, EZCONNECT)
SQLNET.AUTHENTICATION_SERVICES=(BEQ,KERBEROS5)
SQLNET.KERBEROS5_CONF=C:\app\oracle\security\krb5.conf
SQLNET.AUTHENTICATION_KERBEROS5_SERVICE=oracle
SQLNET.KERBEROS5_CONF_MIT=TRUE
SQLNET.KERBEROS5_CC_NAME=MSLSA: #-Windows SSO for SQLPlus


2. try to connect using sqlplus /@tns_alias

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms