Re: Access denied after 20 minutes or so

Jeffrey Altman <[email protected]> Thu, 11 Jan 2007 16:09:28 -0500
Newsgroups gmane.comp.file-systems.openafs.devel.win32
Organization Secure Endpoints Inc.
Message-ID <[email protected]>
Joshua Mann wrote:
> Hi,
> 
> We're using OpenAFS v 1.5.13 w/ MIT Krb5 V 3.1 for
> Windows XP. After obtaining a krb5 ticket & a token
> via the afscred or the NID gui, we get access to our
> afs shares. But this lasts for less than an hour {this
> time appears to be random) at which time we get
> "access denied" connecting to AFS drives or "share not
> found" when connecting to UNC shortcuts.  In order to
> recover from this situation, we have to 1) destroy the
> afs token via NID or unlog.exe or destroy all tickets,
> 2) click on the AFS drives or shortcuts, and 3) then
> obtain new tickets.  This will give us temporary
> access to AFS until it breaks again in less than
> another hour.  Has anyone seen this behavior?

Are your tokens expired?

Have you obtained any log data as per the instructions
in the OpenAFS for Windows release notes?

> We also tried using OpenAFS v 1.4.2 with the same
> results.
> 
> OpenAFS for Windows works fine with krb4. 
> 
> We noticed when we do a Properites listing of the afs
> ticket in NID that the "Client Principle" is formated
> "[email protected]@company.com" which seems peculiar. 
> Is this normal?

Its <Kerberos 5 Principal>@<cell> which is a bug.  It
should just be <Kerberos 5 Principal>
smime.p7s (application/x-pkcs7-signature, 3.3 KB) - not displayed