[OpenAFS] Debian - openafs -noauth problems

Derek Atkins warlord@MIT.EDU
Tue, 23 Aug 2005 17:23:16 -0400

Russ Allbery <rra@stanford.edu> writes:

> Madhusudan Singh <singh.madhusudan@gmail.com> writes:
>> Thanks for your response. I contacted the KDC admins yesterday and they
>> suggested that I use :
>> 	kinit -k -t /etc/krb5.keytab afs/omega.domain.edu@KERBEROS.DOMAIN.EDU
> When running afs-newcell, the admin principal is the user principal,
> either zzzz or zzzz/admin (or zzzz/root, or what have you), whatever you
> decide to use.  The afs/omega.domain.edu principal is something different,
> and once you've downloaded it and used asetkey on it, you shouldn't have
> to think about it any further.

Don't you have to do something special when cellname != REALM?
ISTR you needed to make some modification to some kerberos
configuration (on the server?) to get this working?  Or is my
memory completely out of date?

       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       warlord@MIT.EDU                        PGP key available