View previous topic :: View next topic |
Author |
Message |
KermitTheFragger n00b
Joined: 20 Aug 2004 Posts: 41 Location: Netherlands
|
Posted: Tue Aug 24, 2004 3:05 pm Post subject: [noob] OpenAFS, MIT Kerberos 5 and aklog |
|
|
Hi,
I've got a small problem with OpenAFS, maybe some of you nice folks could help me out here
I have set up AFS with MIT Kerberos V Authentication, added a principal named afs/zeus.lan@ZEUS.LAN in kerberos. Then I added the principal to a keytab with "ktadd -e des-cbc-crc:afs3 -k /usr/vice/etc/afs.keytab afs/zeus.lan". I also runned asetkey: "asetkey add 5 /usr/vice/etc/afs.keytab afs/zeus.lan"
All seems to be going smooth so far. But when I do aklog, after I have done kinit ktf/admin I get:
Code: |
Authenticating to cell zeus.lan (server storage).
We've deduced that we need to authenticate to realm ZEUS.LAN.
Getting tickets: afs/zeus.lan@ZEUS.LAN
Kerberos error code returned by get_cred: -1765328228
aklog: Couldn't get zeus.lan AFS tickets:
aklog: Cannot contact any KDC for requested realm while getting AFS tickets
|
The strange thing is; I DO get an AFS ticket:
Code: |
Valid starting Expires Service principal
08/24/04 16:17:51 08/25/04 02:17:51 krbtgt/ZEUS.LAN@ZEUS.LAN
renew until 08/25/04 16:17:51
08/24/04 16:17:59 08/25/04 02:17:51 afs/zeus.lan@ZEUS.LAN
renew until 08/25/04 16:17:51
|
Even weirder, on Windows XP (aaaah, i know, i know, plz stop hitting me ) AFS works. Its get its ticket and just works.
Im really at a loss here. |
|
Back to top |
|
|
KermitTheFragger n00b
Joined: 20 Aug 2004 Posts: 41 Location: Netherlands
|
Posted: Wed Aug 25, 2004 8:20 am Post subject: |
|
|
Ok I solved it, here's the answer for anyone who has the same problem. I'm almost ashame to tell it, really stupid mistake .
Be sure you have the krb524 deamon running! So that Kerberos 5 tickets can be translated to Kerberos 4 tickets. |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|