Skip to Content Information Center
Lexmark MS312

Lexmark MS312

Decrypt Integrity Check Failed Message with Smart Card Authentication Client (SCAC)

Issue description

"Decrypt integrity check failed" message displays when attempting to authenticate. This specific error instance relates to the erroneous use of an automatically generated krb5-affinity.conf located in the device's persistent memory.


Clearing the kerb5 file and rebooting the device may work for a period of time; however, firmware LW63.TU.P687 or later,will permanently alter the way theprinter configures and retains its krb5-affinity.conf.

To resolve this issue, make sure to update the printer firmware to the latest version. Please refer to the Firmware Update Instructions for steps in updating the printer firmware.

If the issue persists, search for more information related to this issue or contact support for further assistance.


An automatically generated Kerberos configuration file (krb5-affinity.conf) in the printer is causing the device to erroneously use incorrect Domain Controllers when trying to authenticate. This file is separate from the Kerberos configuration file (krb5.conf) and should normally, and only, be created and used when the device is joined to an Active Directory. Instead of the printer using the specified domain controllers on the Smart Card Authentication client, it is using this krb5-affinity.conf populated in persistent memory.


Was this article helpful?