afs-krb5 integration

Klaas Hagemann kerberos at northsailor.de
Thu Oct 17 15:02:40 EDT 2002


> At the end of the day, there is a ticket in a Keyfile that does not agree
> with the service ticket stored in your KDC.  This is the ONLY possible
> cause of this error (at least, the only one I've ever seen).

That is not the problem i meant.
It works fine with my krb5-1.2.4 kerberos master server.
But the new krb1.2.6 release has some new functions concerning this points
so that afs does not work with krb524d by default.
You have to do some konfiguration in krb5.conf and i didn't made it work.

>
> Possible causes of this:
>
> - You're not updating the KeyFile on ALL of your AFS servers (yes, you
>   have to do them ALL, and the best way to do that is with upclient,
>   because it needs to be the same one everywhere).
>
> - You entered in the wrong kvno for asetkey.
>
> - You have an old cached service ticket on your client.
>
> There may be more problems, but these are the only ones that I've seen.
> I know that some people were unable to make it work, but I am convinced
> that they still had one of these problems and they just didn't realize it.
>
> --Ken
> ________________________________________________
> Kerberos mailing list           Kerberos at mit.edu
> http://mailman.mit.edu/mailman/listinfo/kerberos




More information about the Kerberos mailing list