FW: [OpenAFS] Windows XP problems getting an AFS token when logged into a Kerberos Realm

Douglas E. Engert deengert@anl.gov
Mon, 29 Nov 2004 15:41:11 -0600


Are you using Windows 2003 as the KDC? If so the encryption will
be md5, which the 1.2.11 can not accept without some modifications.
So if the aklog is bypassing the Krb524d  this could be a problem.



Jeffrey Altman wrote:

> You are or are not using Freelance mode?  My guess is 'no' since
> the fake root.afs volume does not use "AFS" tokens for access.
> 
> The version of the ASU.EDU servers are OpenAFS 1.2.8 or higher?
> I think so because authen[1234].asu.edu report 1.2.11 but they
> also report the AFS client on the machine as being "afs3.6 2.39".

Could be they updated the server but not the clients on the server.

> 
> Have you read afs-install-notes.txt?  Especially the sections
> discussing the use of Kerberos 5 tickets as tokens?  If Kerberos 5
> tickets do not work and tickets derived via krb524 do, then you need
> to be a bit more knowledgeable about your use of krb524d on campus.
> 
> Jeffrey Altman
> 
> Stephen Stoops wrote:
> 
>> I am using build 1.3.7401 standard install with Loopback. 
>> I am able to mount \\AFS\all IF I use other credentials from a different
>> domain.  I am unable to mount using the Kerberos credentials from
>> ASU.EDU. 
> 
> 

-- 

  Douglas E. Engert  <DEEngert@anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444