[OpenAFS] AFS/Windows questions

Robbie Foust rfoust@duke.edu
Wed, 15 Sep 2004 11:23:23 -0400


If I set the EnableKFW registry key to 0, and run "afscreds -A" then I 
get a token.  How can I tell (just for confirmation) that afscreds 
actually used kerberos 4 for tokens and not kerberos 5?  If I just run 
"tokens" from a command prompt, it doesn't tell me.

Also, if the Microsoft "AllowTGTSessionKey" registry setting is set at 
0, will this prevent AFS (afscreds/aklog?) from working properly, or 
does this registry setting only affect KFW/ms2mit?  I've noticed that 
AFS seems to be working on Pre-SP2 machines, even though that key is set 
to 0.  It completely broke on a SP2 machine, which is what led me to the 
registry setting.


- Robbie

Robbie Foust, IT Analyst
OIT - Administrative Information Support
Duke University