[OpenAFS] Debian - openafs -noauth problems

Derek Atkins warlord@MIT.EDU
Tue, 23 Aug 2005 17:23:16 -0400


Russ Allbery <rra@stanford.edu> writes:

> Madhusudan Singh <singh.madhusudan@gmail.com> writes:
>
>> Thanks for your response. I contacted the KDC admins yesterday and they
>> suggested that I use :
>
>> 	kinit -k -t /etc/krb5.keytab afs/omega.domain.edu@KERBEROS.DOMAIN.EDU
[snip]
> When running afs-newcell, the admin principal is the user principal,
> either zzzz or zzzz/admin (or zzzz/root, or what have you), whatever you
> decide to use.  The afs/omega.domain.edu principal is something different,
> and once you've downloaded it and used asetkey on it, you shouldn't have
> to think about it any further.

Don't you have to do something special when cellname != REALM?
ISTR you needed to make some modification to some kerberos
configuration (on the server?) to get this working?  Or is my
memory completely out of date?

-derek
-- 
       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       warlord@MIT.EDU                        PGP key available