krb5 from MIT and Win2003 Server AD and client login..

Lars Schimmer l.schimmer at cgv.tugraz.at
Sun Aug 28 07:55:11 EDT 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi!

I've got a domain here with some linux and some windows XP SP2 clients.
I setup a OpenAFS Cell, a windows 2003 server AD and a mit krb5 server
on linux.
All PCs should obtain access to the OpenAFS cell, so I planned all users
to obtain a realm on the mit krb5 server.
And the users should obtain tickets/tokens autmoatic on login.
On Windows I've got a problem:
The users  can login to the domain/AD with their userID and get a
ticket. But it seems that ticket is NOT from the linux MIT krb5 server,
instead from the krb5-AD-windows-server. so the users doesn't obtain a
token for AFS.
How can I change this in that way, that every user of the domain obtain
a ticket from the linux-krb5-server and a token for OpenAFS?
Or is there a way for the AD server to let the user get tickets from AD
server and obtain tokens automatic with this ticket?
Any hints, urls, FAQs..?

Cya & thx
Lars
- --
- -------------------------------------------------------------
TU Graz, Institut für ComputerGraphik & WissensVisualisierung
Tel.: +43 316 873-5405       E-Mail: l.schimmer at cgv.tugraz.at
PGP-Key-ID: 0xB87A0E03
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDEaYeVguzrLh6DgMRAlsTAKC0dGTwGMRhathXvLG8dfAOif7G3QCgzHnA
RJEWkYRztmW/QbM85PvIWZk=
=p40K
-----END PGP SIGNATURE-----


More information about the Kerberos mailing list