[OpenAFS] Tiger rc6 aklog and alternate service name

Enrico M. V. Fasanelli Enrico.M.V.Fasanelli@le.infn.it
Tue, 07 Feb 2006 16:24:24 +0100

This is a multi-part message in MIME format.
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit


it was a bad-configured /Library/Preferences/edu.mit.Kerberos (or better 
my misunderstanding on the priority between the DNS lookup of KDC and 
the hardcoded one in the [realms] stanza)

I corrected it (removed the hardcoded KDC definition) and all works fine.

Thanks for the hint.


Jeffrey Altman wrote:
> Enrico M. V. Fasanelli wrote:
>> Hi all,
>> I just installed 1.4.1-rc6 on my Tiger (10.4.4 on PowerPC PowerBook) and
>> tried to get my AFS token using aklog. The result is:
>>    pathfinder:~ enrico$ aklog -d
>>    Authenticating to cell le.infn.it (server afs01.le.infn.it).
>>    We've deduced that we need to authenticate to realm LE.INFN.IT.
>>    Getting tickets: afs/le.infn.it@LE.INFN.IT
>>    Kerberos error code returned by get_cred: -1765328324
>>    aklog: Couldn't get le.infn.it AFS tickets:
>>    aklog: Generic error (see e-text) while getting AFS tickets
> The KDC is returning a generic error not principal not found.
> Therefore, the aklog expects the KDC is simply broken and does not
> try a different principal name.
> If you can examine the exchange in a network monitor or review
> the KDC logs, what is the error text in the KRB-ERROR response?
> Jeffrey Altman

Content-Type: text/x-vcard; charset=utf-8;
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;

fn:Enrico M. V. Fasanelli
n:Fasanelli;Enrico M. V.
org:I.N.F.N. - Sezione di Lecce;Servizio Calcolo & Reti
adr:Via Provinciale Lecce-Arnesano;;c/o Dipartimento di Fisica;Lecce;LE;73100;Italia
tel;work:+39 0832 29 7442
tel;fax:+39 0832 29 7442