> Source: [sk184908](https://support.checkpoint.com/results/sk/sk184908)

# sk184908 - "Minor code: Wrong principal in request" error after updating Microsoft Server used for Active Directory, end users fail to authenticate using Kerberos SSO

| Property | Value |
|----------|-------|
| Solution ID | sk184908 |
| Date Created | 2026-04-28 |
| Last Modified | 2026-07-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * After updating a Windows Server running Active Directory Domain Services (DS) or a Domain Controller to the latest Microsoft version, user authentication to a Policy Decision Point (PDP) gateway fails for Kerberos SSO users.
* Identity Awareness logs in SmartConsole show an error indicating multiple failed login attempts when the Authentication Method is Kerberos.

* Logs in SmartConsole and PDP debug on a Security Gateway show Kerberos failures:
  `Minor code: Wrong principal in request`

## Cause

The Microsoft update KB5073381 related to the Windows Kerberos vulnerability CVE-2026-20833 changed the Kerberos behavior. The default encryption method changed from RC4 encryption to AES encryption.

If the service account used in the SSO configuration (configured under the LDAP Account Unit object) is still configured to use RC4, Kerberos authentication may fail, leading to repeated failed logins and the observed "Minor code" errors.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
