[OpenAFS] Token discarding

JR Boyens JR Boyens <jboyens@iastate.edu>
Tue, 12 Nov 2002 16:17:29 -0600


Sorry for replying to myself, but I finally got it to work, it was a combination of a few things.

1) the fact that my krb524d was giving enc'd tickets
2) I must have missed a des-cbc-crc:v4 somewhere
3) I had about 15 afs tickets in my keytab

:)

Thanks to everyone,
--
JR Boyens
jboyens@iastate.edu

On Tue, Nov 12, 2002 at 12:01:00PM -0600 or thereabouts, JR Boyens wrote:
> On Tue, Nov 12, 2002 at 12:51:02PM -0500 or thereabouts, Ken Hornstein wrote:
> > >I have the Debian packages, so I was reading what I thought was the readme, when in
> > > fact it was not.
> > >
> > >Now I have added:
> > >
> > >[appdefaults]
> > >        afs_krb5 = {
> > >                FOONINJA.ORG = {
> > >                        afs = false
> > >                }
> > >        }
> > >
> > >Which /should/ disable the encrypted part that the server does not
> > >support.  But it seems that it does not. I have only 1 kerb server and
> > >1 AFS server. They are the same machine.
> > 
> > So, just so we're clear ... you added this to the krb5.conf on your KDC,
> > and your AFS service principal is afs@FOONINJA.ORG, right?
> 	
> 	I tried in both krb5.conf and kdc.conf, just incase the were
> 	named insanely by my distribution, and yes the princ is
> 	afs@FOONINJA.ORG.
> 
> > 
> > --Ken
> > 
> _______________________________________________
> OpenAFS-info mailing list
> OpenAFS-info@openafs.org
> https://lists.openafs.org/mailman/listinfo/openafs-info
>