Re: Integrated Login Fails

Jeffrey Altman <[email protected]>
Newsgroups gmane.comp.file-systems.openafs.devel.win32
Organization No Longer Affiliated with Columbia University in the City of New York
Message-ID <[email protected]>
I use IBM Access Connections.  Unless you are intentionally turning off
the wireless card there is no reason the wireless drivers would not 
active the card and obtain a DHCP address for the adapter.  The 
afslogon.dll network provider is registered with dependencies on the
TCP/IP subsystem.  If TCP/IP is not ready and this includes the 
initialization of all active network adapters and attempts to obtain an
IP address.

The notes you see are not related to the acquisition of tokens.  What
they refer to is the ability to obtain Kerberos tickets during the
integrated logon and make the tickets available during the user session.
At the current time, there is no mechanism by which the Kerberos tickets
which are obtained by the "SYSTEM" account can be passed to the user
account's session which has yet to be created.

However, if you have absolutely no network access at the time you login,
then it will be impossible to obtain tickets or tokens and as described
there will be no mechanism by which tokens can be obtained in a delayed
manner.  In this situation, when the network does appear the 
afscreds.exe will display a Obtain Tokens dialog to the end user for
the purpose of logging into AFS.

Jeffrey Altman


Ben Fineman wrote:
> Thanks for your help on this issue. The problem was two-fold: in the 
> krb5.ini file, there was a hidden "^M" character following the domain 
> realm entry (our mistake). This did not cause a formatting error but 
> caused us to be unable to get tokens through the AFS client. Secondly, 
> even with this corrected and being able to get tokens from the AFS 
> client application, integrated logon still fails. We have concluded that 
> this is due to the fact the we utilize "IBM Access Connections" to 
> manage our network connections. Unfortunately, Access Connections does 
> not start up the network interface until after logging on to Windows. We 
> noticed the following in the afs-issues.txt file:
> 
> ===
> (13) AFS Integrated Logon:
> (13b) If using Kerberos, need to figure out a means of passing credentials
>      into the user space until such time as I finish the new credential
>      cache service.
> (13c) If network is not available must store the username and password 
>      somewhere until such time as the network starts.
> ===
> 
> This suggests to me that this is a known issue, and as the client is 
> written now integrated login will always fail if no network is available 
> at logon time. We will hopefully look forward to this feature in a 
> future release, however, we understand that this is a non-trivial 
> problem as caching of Kerberos passwords would need to be done in a 
> secure way.
> 
> Thanks for your help,
> Ben
> 
> Jeffrey Altman wrote:
> 
>> Please double check that you do not have more than one version of KFW on
>> your machine.  I can't think of anything obvious other then the wrong 
>> libraries
>> being loaded which would cause this problem.
>>
>> In particular, look for WSHELP32.DLL.  An old version of that file 
>> could result
>> in DNS lookup problems assuming you are relying on DNS for the Realm 
>> to KDC
>> mappings.
>>
>>
>> Ben Fineman wrote:
>>
>>> Thanks for the response. I cannot obtain tokens using the AFS systray 
>>> tool (as you probably suspected). It gives me the same "Cannot 
>>> resolve network address for KDC in requested realm" error with the 
>>> addition of "Error: -1765328164". I took a look at the krb5.ini file 
>>> and can't see anything blatantly wrong. I can send you the contents 
>>> of the file if that would be useful.
>>>
>>> Thanks,
>>> Ben
>>>
smime.p7s (application/x-pkcs7-signature, 3.2 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.