[OpenAFS] AFS Authentication to windows 2003 AD server.

Larry Cashdollar lcashdol@gmail.com
Wed, 7 Dec 2005 16:34:16 -0500


------=_Part_4522_6207800.1133991256683
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

I did recreate the keytab files and pushed those to the afs servers.   Usin=
g
the following command,  thinking this was the case.  There any new flags
that I might have missed?

ktpass -princ afs@vapid-labs.com <afs@corp.akamai.com> -mapuser afs
-pass * -out afs.keytab -kvno 1


I restarted the afs service daemons with bos restart, which seemed to
work fine as well.

On 12/7/05, Jeffrey Altman <jaltman@secure-endpoints.com> wrote:
>
> Microsoft changed the behavior of Windows with regards to the use of
> key version numbers in 2003.   You will need to re-export the service
> principal keys.
>
> Jeffrey Altman
>
>
> Larry Cashdollar wrote:
> > Hello all,
> >            So for two or three years now I have managed an AFS Cell tha=
t
> > authenticates to windows 2000 AD server.
> >
> > The AD servers were recently converted to windows 2003 and now I can no
> > longer authenticate to my cell.
> >
> > Authenticating to cell vapid-labs.com <http://vapid-labs.com> (server
> > afs-camdb1.vapid-labs.com <http://afs-camdb1.vapid-labs.com>).
> > We've deduced that we need to authenticate to realm VAPID-LABS.COM
> > <http://VAPID-LABS.COM>.
> > Getting tickets: afs/vapid-labs.com@VAPID-LABS.COM
> > <mailto:labs.com@VAPID-LABS.COM>
> > Kerberos error code returned by get_cred: -1765328154
> > aklog: Couldn't get vapid-labs.com <http://vapid-labs.com> AFS tickets:
> > aklog: Key version number for principal in key table is incorrect while
> > gettingAFS tickets
> >
> > On my other client I get the same error code, but it is mapped to a
> > different message.
> >
> > Which one is the correct message?
> >
> > larry@Mathom:~$ aklog -d
> > Authenticating to cell vapid-labs.com <http://vapid-labs.com> (server
> > afs-camdb1.vapid-labs.com <http://afs-camdb1.vapid-labs.com>).
> > We've deduced that we need to authenticate to realm vapid-labs.com
> > <http://vapid-labs.com>.
> > Getting tickets: afs/vapid-labs.com@VAPID-LABS.COM
> > <mailto:labs.com@VAPID-LABS.COM>
> > Kerberos error code returned by get_cred: -1765328154
> > aklog: Couldn't get vapid-labs.com <http://vapid-labs.com> AFS tickets:
> > aklog: New password cannot be zero length while getting AFS tickets
> >
> >
> > I use a seperate kerberos server running krb524 on port 4444 to convert
> > tickets.
> >
> > Any help will be appreciated.
> >
>
>
>

------=_Part_4522_6207800.1133991256683
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

I did recreate the keytab files and pushed those to the afs
servers.&nbsp;&nbsp; Using the following command,&nbsp; thinking this
was the case.&nbsp; There any new flags that I might have missed?<br>
<br>
<pre>ktpass -princ <a class=3D"moz-txt-link-abbreviated" href=3D"mailto:afs=
@corp.akamai.com">afs@vapid-labs.com</a> -mapuser afs -pass * -out afs.keyt=
ab -kvno 1<br><br><br>I restarted the afs service daemons with bos restart,=
 which seemed to work fine as well.
<br></pre>
<div><span class=3D"gmail_quote">On 12/7/05, <b class=3D"gmail_sendername">=
<span style=3D"font-weight: bold;"></span>Jeffrey Altman</b> &lt;<a href=3D=
"mailto:jaltman@secure-endpoints.com">jaltman@secure-endpoints.com</a>&gt; =
wrote:
</span><blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid rg=
b(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Microsoft =
changed the behavior of Windows with regards to the use of<br>key version n=
umbers in 2003.&nbsp;&nbsp; You will need to re-export the service
<br>principal keys.<br><br>Jeffrey Altman<br><br><br>Larry Cashdollar wrote=
:<br>&gt; Hello all,<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;So
for two or three years now I have managed an AFS Cell that<br>&gt; authenti=
cates to windows 2000 AD server.<br>&gt;<br>&gt; The AD servers were recent=
ly converted to windows 2003 and now I can no<br>&gt; longer authenticate t=
o my cell.
<br>&gt;<br>&gt; Authenticating to cell <a href=3D"http://vapid-labs.com">v=
apid-labs.com</a> &lt;<a href=3D"http://vapid-labs.com">http://vapid-labs.c=
om</a>&gt; (server<br>&gt; <a href=3D"http://afs-camdb1.vapid-labs.com">afs=
-camdb1.vapid-labs.com
</a> &lt;<a href=3D"http://afs-camdb1.vapid-labs.com">http://afs-camdb1.vap=
id-labs.com</a>&gt;).<br>&gt; We've deduced that we need to authenticate to=
 realm <a href=3D"http://VAPID-LABS.COM">VAPID-LABS.COM</a><br>&gt; &lt;<a =
href=3D"http://VAPID-LABS.COM">
http://VAPID-LABS.COM</a>&gt;.<br>&gt; Getting tickets: afs/vapid-<a href=
=3D"mailto:labs.com@VAPID-LABS.COM">labs.com@VAPID-LABS.COM</a><br>&gt; &lt=
;mailto:<a href=3D"mailto:labs.com@VAPID-LABS.COM">labs.com@VAPID-LABS.COM<=
/a>
&gt;<br>&gt; Kerberos error code returned by get_cred: -1765328154<br>&gt; =
aklog: Couldn't get <a href=3D"http://vapid-labs.com">vapid-labs.com</a> &l=
t;<a href=3D"http://vapid-labs.com">http://vapid-labs.com</a>&gt; AFS ticke=
ts:
<br>&gt; aklog: Key version number for principal in key table is incorrect =
while<br>&gt; gettingAFS tickets<br>&gt;<br>&gt; On my other client I get t=
he same error code, but it is mapped to a<br>&gt; different message.<br>
&gt;<br>&gt; Which one is the correct message?<br>&gt;<br>&gt; larry@Mathom=
:~$ aklog -d<br>&gt; Authenticating to cell <a href=3D"http://vapid-labs.co=
m">vapid-labs.com</a> &lt;<a href=3D"http://vapid-labs.com">http://vapid-la=
bs.com
</a>&gt; (server<br>&gt; <a href=3D"http://afs-camdb1.vapid-labs.com">afs-c=
amdb1.vapid-labs.com</a> &lt;<a href=3D"http://afs-camdb1.vapid-labs.com">h=
ttp://afs-camdb1.vapid-labs.com</a>&gt;).<br>&gt; We've deduced that we nee=
d to authenticate to realm=20
<a href=3D"http://vapid-labs.com">vapid-labs.com</a><br>&gt; &lt;<a href=3D=
"http://vapid-labs.com">http://vapid-labs.com</a>&gt;.<br>&gt; Getting tick=
ets: afs/vapid-<a href=3D"mailto:labs.com@VAPID-LABS.COM">labs.com@VAPID-LA=
BS.COM
</a><br>&gt; &lt;mailto:<a href=3D"mailto:labs.com@VAPID-LABS.COM">labs.com=
@VAPID-LABS.COM</a>&gt;<br>&gt; Kerberos error code returned by get_cred: -=
1765328154<br>&gt; aklog: Couldn't get <a href=3D"http://vapid-labs.com">va=
pid-labs.com
</a> &lt;<a href=3D"http://vapid-labs.com">http://vapid-labs.com</a>&gt; AF=
S tickets:<br>&gt; aklog: New password cannot be zero length while getting =
AFS tickets<br>&gt;<br>&gt;<br>&gt; I use a seperate kerberos server runnin=
g krb524 on port 4444 to convert
<br>&gt; tickets.<br>&gt;<br>&gt; Any help will be appreciated.<br>&gt;<br>=
<br><br></blockquote></div><br>

------=_Part_4522_6207800.1133991256683--