KfW and NiM getting mutliple TGT's

David Bear David.Bear at asu.edu
Thu Apr 30 17:36:16 EDT 2009


Normally, when we install KfW (currently using 3.2.2) on windows, we include
a krb5.ini file that is mostly the same as the krb5.conf we use on linux.
Our krb5.ini only has asu.edu realm information in it. We also have an AD
domain to which our windows clients are joined. When a user does a domain
logon, they normally get 2 credentials automatically, one for the AD domain,
and one for our ASU.EDU realm. This is the behavior we like.

However, today, using the same configuration file, NiM is only reporting
credentials for the AD domain -- it is not automatically getting credentials
from the ASU.EDU realm. We have selected (obtain new creds at startup) and
(destroy all creds on exit) but this makes no difference. For some reason,
KfW is not getting all the creds we are used to at startup. Any advice on
how to get the behavior back that we want?

-- 
David Bear
College of Public Programs at ASU
602-464-0424



More information about the Kerberos mailing list