Re: Help setting up openafs on debian bookworm

Dirk Heinrichs <[email protected]> Sun, 2 Jun 2024 15:10:52 +0200
Newsgroups gmane.comp.file-systems.openafs.general
Message-ID <[email protected]>
Ernesto Alfonso:

> Now my problem is still understanding why `bos listkeys` now succeeds 
> but returns an empty set when asetkey does list 4 keys.

Because you deleted the wrong key. The AFS principal should be named 
"afs/<domain>@<REALM>".  Just follow the instructions in 
https://docs.openafs.org/QuickStartUnix/HDRWQ50.html, under "Generating 
the Cell's Kerberos V5 Keys", but replace "/usr/afs/etc" with 
"/etc/openafs/server", which is used on Debian/Ubuntu, and you should be 
all set.

Also note that if you setup multiple servers, you only need to do the 
kadmin part once, and copy the resulting rxkad.keytab (and probably 
KeyFileExt) to all servers, since the kvno needs to be the same on all 
servers, but exporting the key increases it.

HTH...

     Dirk

-- 
Dirk Heinrichs <[email protected]>
Matrix-Adresse: @heini:chat.altum.de
GPG Public Key: 80F1540E03A3968F3D79C382853C32C427B48049
Privacy Handbuch: https://www.privacy-handbuch.de
OpenPGP_signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQBbRZ091iOtChJXdXJlzdNRFS0TAUCZlxvXAAKCRDJlzdNRFS0
TISPAQCajjjRyF2r/KvelHJwqX+C7Cge3tmhYM9scD9Gf1/JmgD/YfNvSskBAKe2
F7C3/ridKcBjeDh2NMQqnh6/uzbC9QQ=
=3U0K
-----END PGP SIGNATURE-----