Re: Heimdal KDC 1.5.1 as AFS KA-server
Andreas Haupt <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | DESY |
| Message-ID | <[email protected]> |
Hi Harald, On Thu, 2011-10-13 at 15:38 +0200, Harald Barth wrote: > > Well, I know that - but many users are used to use the klog command > > They should write their passwords on their own > workstations/laptops/whatever, so you will allways have to tell them > the right thing for their specific OS which can change with the OS and > with your setup. Or do I understand you wrong? In our environment people often need tokens from many AFS cells. Users located in a foreign cell could simply acquire a token from our cell by the use of klog(.krb5). Both things don't work any more with a Heimdal 1.5.1 server ... Sure they can do kinit/aklog but kinit usually destroys the default K5 ticket, which is not desired (yes, one can write wrappers to avoid this ...). > > which doesn't work any more then. > > The KDC logs (old and new) should tell you the difference. See my post on openafs-info. > > Ok - there's the replacement klog.krb5 > > but this seems to have other problems (see my posts on the openafs-info > > mailing list). > > There might be more than one bug lurking here. Maybe. From my point of view it looks like the 1.5.1 KDC sends out a slightly different reply now (in the encrypted parts of the ticket) which klog.krb5 doesn't understand. So this can be a bug in klog.krb5 (when its not compatible to some new features) or in the new Heimdal KDC (it sends out broken replies). Or it's even a configuration issue ... I don't know. But I think its better to use just one mailing list for that ... Cheers & Thanks, Andreas -- | Andreas Haupt | E-Mail: [email protected] | DESY Zeuthen | WWW: http://www-zeuthen.desy.de/~ahaupt | Platanenallee 6 | Phone: +49/33762/7-7359 | D-15738 Zeuthen | Fax: +49/33762/7-7216