[OpenAFS] Re: Windows AFS client / Kerberos V

ted creedon tcreedon@easystreet.com
Tue, 30 Jan 2007 06:25:36 -0900

ank -kvno 2 -randkey -e "des-cbc-crc:normal" afs@HEKIMIAN.COM

This has been discussed before AND NOT ENTERED INTO THE DOCUMENTATION.


-----Original Message-----
From: openafs-info-admin@openafs.org [mailto:openafs-info-admin@openafs.org]
On Behalf Of Derrick J Brashear
Sent: Tuesday, January 30, 2007 6:17 AM
To: Joe Buehler
Cc: openafs-info@openafs.org
Subject: Re: [OpenAFS] Re: Windows AFS client / Kerberos V

On Tue, 30 Jan 2007, Joe Buehler wrote:

> There is a discrepancy between the users I imported using the afs-krb5
> database migration tool and the afs principal.  The users all have
> AFS3 salt but the afs principal does not.  Is this a problem?

No, in general users have passwords (salted) and service principals don't. 
Don't type passwords for service principals. Generate keys.

> I have not been able to recreate afs@HEKIMIAN.COM with the proper salt.

If you created it with the afs3 salt that would be the wrong one.

OpenAFS-info mailing list