[OpenAFS] Active Directory 2003, kerberos 5, openAFS - rxkad
Wed, 03 Jan 2007 09:16:50 -0500
L=F6nroth Erik wrote:
> I believe I have... My file looks like this. Can I be sure this is OK?
> In my missery I can't trust anything at the moment.
> [root@vmware01 ~]# cat /usr/afs/etc/krb.conf
> LAB.SCANIA.COM sesocolab11.scania.com
This is fine. Although the second line is not used by AFS so you
can remove it.
Did you restart the AFS servers after setting this value?
> I have also looked in AD to se the Service principal binding (Is this
> right?) :
> C:\setspn -A afs/sss.se.scania.com afs
> Registering ServicePrincipalNames for
> Updated object
> C:\setspn -L afs
> Registered ServicePrincipalNames for
That is fine.
RXKADBADTICKET can be generated if the clocks between AFS and AD
are not synchronized. Are they?