[OpenAFS] Problems with windows Vista and OpenAFS

Jeffrey Altman jaltman@secure-endpoints.com
Thu, 04 Jun 2009 07:08:39 -0700


If you can browse \\afs and it lists printers and no file shares
there is may be a machine on your network with the netbios
name "AFS".

However, not being able to communicate with the OpenAFS cache
manager would have no impact on your ability to view kerberos
tickets from the command prompt.

You should read the troubleshooting section of the release
notes if you have not already done so.

The afsd_init.log file will indicate what the cache manager
believes it is configured to do.  "nbtstat -n" and "nbtstat -S"
will tell you what Windows believes the netbios configuration
is.

Jeffrey Altman



Claudio Prono wrote:
> Ok, it's clear why i can't see kerberos credentials in command prompt.
> And why i can't access to the afs ? If i try \\afs , it's empty and i
> can see only printers. What can be wrong? How i can debug this?
> 
> Cordially,
> 
> Claudio.
> 
> Jeffrey Altman ha scritto:
>> If your command prompt is being run as "administrator"
>> it will not be able to see the Kerberos credential caches
>> that are maintained by NetIdMgr.  This is because the
>> "administrator" processes are actually in a different
>> session.
>>
>> If you are using multiple identities in NetIdMgr, the
>> kerberos command line tools will only be able to access
>> the "default" identity.  If the command prompt is not
>> running as "administrator" try setting the default
>> identity again.
>>
>> Jeffrey Altman
>>
>>
>> Claudio Prono wrote:
>>   
>>> Hello all,
>>>
>>> I use Windows Vista SP1 with OpenAFS 1.5.60 and Mit Kerberos 3.2.2. I
>>> have some strange problems with that. If i try to authenticate with the
>>> Network identity manager, i can login, but if i do from the prompt a
>>> klist, i recieve that error:
>>>
>>> klist: No credentials cache found (ticket cache API:username1@domain.com)
>>>
>>> I have two identity configured into the network identity manager, if i
>>> want to delete one, i click on it, hit the canc key, then i go to apply
>>> than ok and if i reopen the network identity manager, no changes to
>>> identity is done (a bug?). If i do a kinit from the prompt, no problem
>>> at all, i can list all the tickets and all seems to work fine. But, if i
>>> try to access to the AFS, i recieve an error of Permission Denied.
>>>
>>> The server is an OpenSuse 11.0, with that packages installed:
>>>
>>> openafs-1.4.8-3.1
>>> openafs-authlibs-1.4.8-3.1
>>> openafs-kmp-pae-1.4.8_2.6.25.5_1.1-3.1
>>> pam-afs-session-1.5-6.11
>>> openafs-server-1.4.8-3.1
>>> openafs-client-1.4.8-3.1
>>> openafs-krb5-mit-1.4.8-3.1
>>>
>>> If i connect directly from the server, no problem.
>>>
>>> What i can do to debug that stuff?
>>>
>>> Thank you,
>>>
>>> Claudio Prono.
>>>
>>>     
>>
>>
>> !DSPAM:70,4a27ce87322202313377260!
>>
>>
>>
>>
>>   
> 
> -- 
> ------------
> Claudio Prono
> Systems Development @ PSS Srl, Divisione Implementazione Sistemi
> Via San Bernardino, 17 - 10137 Torino (TO) - IT
> Tel +39-011.32.72.100  Fax +39-011.32.46.497
> PGP Fingerprint: 75C2 4049 E23D 2FBF A65F  40DB EA5C 11AC C2B0 3647
> Disclaimer: http://atpss.net/disclaimer
> ------------ 
>