[OpenAFS] ADS and MIT Kerberos transition auth continued

Russ Allbery rra@stanford.edu
Wed, 01 Jul 2009 13:57:35 -0700

Eric Chris Garrison <ecgarris@iupui.edu> writes:

> What I'm seeing now though, is that although used asetkey to add the
> service principal from the ADS realm to my test cell, permissions
> aren't working as I'd expect.
> So, we have realm AFSTEST.IU.EDU and ADS.IU.EDU.  Both in the KeyFile and
> in the /usr/afs/etc/krb.conf and both listed in the /etc/krb5.conf.

What's the kadmin examine output (or Heimdal equivalent) for the afs
principal for your AFS cell in ADS.IU.EDU?

