pending/1094: Cannot find KDC problems
Edgar Lovecraft
ealovecraft at hotmail.com
Tue Apr 23 00:32:44 EDT 2002
>Number: 1094
>Category: pending
>Synopsis: Cannot find KDC problems
>Confidential: yes
>Severity: serious
>Priority: medium
>Responsible: gnats-admin
>State: open
>Class: sw-bug
>Submitter-Id: unknown
>Arrival-Date: Tue Apr 23 00:33:00 EDT 2002
>Last-Modified:
>Originator:
>Organization:
>Release:
>Environment:
>Description:
>How-To-Repeat:
>Fix:
>Audit-Trail:
>Unformatted:
<html><div style='background-color:'><P>I ran across this listing when I was having some troubles getting kadmin and kinit to find the KDC for my realm in a new KerberosV install on RedHat 7.2 on an isolated network. What I eventually traced it down to was this. The defined host name for the local machine was kerberos.foobar.com (/etc/sysconfig/network HOSTNAME=kerberos.foobar.com), same for the /etchosts file (127.0.0.1 kerberos.foobar.com kerberos), of course this is also what dns was pointing to krbmaster A 192.168.0.1, kerberos CNAME krbmaster, _kerberos._upd SRV 0 0 88 krbmaster, etc.) Once I changed the host name on the local machine from kerberos to krbmaster (in /etc/sysconfig/network and /etc/hosts), everything worked just fine. Just thought that I would let you know as I could not find anything on this out there on the web, this was the closest find I had. Mabey I missed something in the DOCS, but I do not remember reading anything this !
!
!
potential conflict.</P>
<P>Cannot find KDC</P>
<P>daemon at ATHENA.MIT.EDU (Nov-William H Rahe)<BR>Wed Jul 31 10:23:41 1991</P>
<P>Date: Wed, 31 Jul 91 07:59:40 MDT
From: <A href="mailto:whrahe at somnet.sandia.gov">whrahe at somnet.sandia.gov</A> (Nov-William H Rahe)
To: <A href="mailto:krb5-bugs at MIT.EDU">krb5-bugs at MIT.EDU</A>
I have successfully? built V5 on a Sun 4/110. I created the database
(/krb5/principal.xxx). Used kdb5_stash to preserve the key. Created
two principals whrahe using kdb5_edit av4k facility and whrahev5 using
kdb5_edit ank facility. Started krb5kdc in background (not in inetd)
Using old V4 kinit I obtain tickets for whrahe. Using V5 kinit with
whrahev5, I get:
kinit: Cannot find KDC for requested realm while getting initial
credentials. What piece of the puzzle am I missing? .
You should make sure that you have created krb.conf and krb.realms files
in /krb5. If that didn't fix the problem, you may have discovered a
more deep-seated problem with Kerberos V5 on Suns. I've gotten a
similar report from someone else who said that his krb.conf and
krb.realms were correctly set up but who still had problems. I don't
know what explicitly causing the problem or a fix yet, however. If you
can find more information, I would appreciate it if you could send it to
krb5-bugs at MIT.EDU. - Ted
--------------------------------------------------------------------------
I also have correct krb.conf and krb.realms. I will begin to see if I
can isolate what realm krb5_locate_kdc is passing to sendto_kdc.</P></div><br clear=all><hr>Send and receive Hotmail on your mobile device: <a href='http://g.msn.com/1HM205401/j'>Click Here</a><br></html>
More information about the krb5-bugs
mailing list