FIXED (need you advice): slave server :Decrypt integrity checkfailed error

FM dist-list at LEXUM.UMontreal.CA
Mon Dec 5 15:40:34 EST 2005


What I did :
delete krb5-server from slave and /var/kerberos
then :
on slave
I install krb5-server
I copy /var/kerberos/.k5.REALM from master to slave
I configure and start kpropd
have a krb5.keytab with : host/fqdn_slave at REALM (from master)
on master, sync with kprop

and on slave again : start the krb5kdc

authentification : ok

is it a good thing to copy the /k5 ?


FM wrote:

> Hello,
> I'm trying to create a slave server (RHEL 3 on master and slave).
> on slave :
> I installed krb5-server
> I create db with kdb5_util create -s
> I configure and start kpropd
> I have a krb5.keytab with : host/fqdn_slave at REALM (from master)
>
> on the master :
>
> I dump master DB and sync it witgh kprop :
> 32768 bytes sent.
> 65536 bytes sent.
> 69148 bytes sent.
> Database propagation to slaver: SUCCEEDED
>
> now I'm trying to kinit on the slave (I modify the krb5.conf on the 
> station) but :
>
> Dec 05 13:52:57 slave krb5kdc[5065](info): AS_REQ (5 etypes {16 23 1 3 
> 2}) 192.168.4.29(88): DECRYPT_SERVER_KEY: user at REALM for 
> krbtgt/REALM at REALM, Decrypt integrity check failed
>
> Do you have a idea ?
>
> Thanks !
> ________________________________________________
> Kerberos mailing list           Kerberos at mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos



More information about the Kerberos mailing list