Re: afs integrated login with EnableKFW=1 and ccname set to "FILE:..."

Jeffrey Altman <[email protected]>
Newsgroups gmane.comp.file-systems.openafs.devel.win32
Organization Not Affiliated with Columbia University in the City of New York
Message-ID <[email protected]>
Beata A Pruski wrote:

> Hello,
> 
> I am trying to resolve a problem with OpenAFS using KFW and kerberos 5 
> to get afs tokens.
> Here is the environment I am working in:
> - windows xp sp2
> - kfw 1.2.65 with ccname set:
>         
> HKEY_LOCAL_MACHINE\Software\MIT\Kerberos5\ccname="FILE:<full_path\<file_name>" 
> 
> - openafs 1.3.76 installed and configured to aquire tokens at login time
> - running a custom written Network Provider which gets kerberos v5 
> tickets at login time (that is why ccname is set in HKEY_LOCAL_MACHINE 
> to be a file)

You should most likely use a "MEMORY:name" cache instead of a file.

What do you mean by "custom network provider"?  You have customized the 
one that is distributed by OpenAFS.org?  What prompted you to make that 
change?

> If EnableKFW= 0 and tokens are aquired via kerberos v.4 everything works 
> fine. Any attempt to aquire afs tokens via kerberos 5 by setting 
> EnableKFW (=1) fails. I cannot even launch afscreds.exe because it gives 
> me an application error.

EnableKFW is only meaningful if you are using afscreds to obtain tokens 
or using the OpenAFS.org Integrated Logon Network Provider.

Install the debug version of openafs 1.3.76 and attach a debugger to the 
process when it crashes.  Then you can file a reasonable bug report to 
[email protected] with stack information describing what is wrong.

> Can somebody help me resolve this problem, please?

I can help you help yourself.

Jeffrey Altman
smime.p7s (application/x-pkcs7-signature, 3.2 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.