[OpenAFS] Kerberos and AFS

Andreas Buhr andreas.buhr@epost.de
Mon, 21 Oct 2002 20:42:28 +0200


>>I will be running 1 Solaris 9 AFS server with 2 SuSe 8.1 KDC's, how do I
>>go about using the K5 authentication with AFS seamlessly?
> 
> 
> You need the krb5 migration kit (which is included in the Red Hat
> RPMS) so you can build 'asetkey' and 'aklog.  You generate an
> afs/<cell>@REALM key in your KDC, making sure you use '-e
> des-cbc-crc:v4' and extract that into an afs keytab.  Then you use
> asetkey to add the keytab key into an AFS KeyFile.
> 

Be aware that in the current release of Kerberos (1.2.6) krb524 (which 
converts the krb5-tickets to the kerberos 4 format, which is used by 
AFS) provides by default a keytype, which is IMHO not supportet by the 
current release of AFS. You can change this behavior in the config-files.

Greetz

Andreas

btw:
Hello to the list, I'm new here :-)