[OpenAFS] AFS root/admin passwords lost

Cory Puckett corypuckett@depauw.edu
Tue, 3 Aug 2010 13:40:08 -0400


--000e0cd3317ef07457048ceece77
Content-Type: text/plain; charset=ISO-8859-1

Thank you for your quick reply. I really appreciate it.

You will have to forgive me. I am new to using AFS and I'm learning as I go.

I ran kadmin locally on the server as root and go this:

[root@##### bin]# kadmin
Authenticating as principal root/admin@EXAMPLE.COM with password.
kadmin: Cannot resolve network address for KDC in requested realm while
initializing kadmin interface

Again sorry for being a newbie. Did I need to include more in my command?

On 8/3/10, Thomas Kula <kula@tproa.net> wrote:
>
> On Tue, Aug 03, 2010 at 12:39:48PM -0400, Cory Puckett wrote:
> >
> >    I  just  took  this job and one of the first things they had me do was
> >    change  the  root passwords on the linux servers. After I did this the
> >    Kerberos  admin  password  that  worked before I changed the machine's
> >    root password will not work anymore. The fall semester starts soon and
>
>
> I'm not sure how those are connected, but...
>
>
> >    I  need  to  be  able  to  make student AFS accounts but can't do that
> >    without  the  Kerberos  admin  password.  Can anyone help me reset the
> >    Kerberos admin password?
>
>
> What kerberos server are you using? Both MIT and Heimdal have a way of
> running kadmin locally if you run them on the master KDC --- run this
> option as root on the master KDC, change things as needed.
>
>
> --
> Thomas L. Kula | kula@tproa.net | http://kula.tproa.net/
> _______________________________________________
> OpenAFS-info mailing list
> OpenAFS-info@openafs.org
> https://lists.openafs.org/mailman/listinfo/openafs-info
>

--000e0cd3317ef07457048ceece77
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Thank you for your quick reply. I really appreciate it.<br>
<br>
You will have to forgive me. I am new to using AFS and I&#39;m learning as =
I go.<br>
<br>
I ran kadmin locally on the server as root and go this:<br>
<br>
[root@##### bin]# kadmin<br>
Authenticating as principal root/<a href=3D"mailto:admin@EXAMPLE.COM" targe=
t=3D"_blank">admin@EXAMPLE.COM</a> with password.<br>
kadmin: Cannot resolve network address for KDC in requested realm while ini=
tializing kadmin interface<br>
<br>
Again sorry for being a newbie. Did I need to include more in my command?<b=
r><br><div><span class=3D"gmail_quote">On 8/3/10, <b class=3D"gmail_sendern=
ame">Thomas Kula</b> &lt;<a href=3D"mailto:kula@tproa.net" target=3D"_blank=
">kula@tproa.net</a>&gt; wrote:</span><blockquote class=3D"gmail_quote" sty=
le=3D"border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;pad=
ding-left:1ex">

On Tue, Aug 03, 2010 at 12:39:48PM -0400, Cory Puckett wrote:<br> &gt;<br>
&gt;=A0=A0=A0=A0I=A0=A0just=A0=A0took=A0=A0this
job and one of the first things they had me do was<br> &gt;=A0=A0=A0=A0chan=
ge=A0=A0the=A0=A0root passwords on the linux servers. After I did this the<=
br>
&gt;=A0=A0=A0=A0Kerberos=A0=A0admin=A0=A0password=A0=A0that=A0=A0worked
before I changed the machine&#39;s<br> &gt;=A0=A0=A0=A0root password will n=
ot work anymore. The fall semester starts soon and<br> <br> <br>I&#39;m not=
 sure how those are connected, but...<br> <br><br>
&gt;=A0=A0=A0=A0I=A0=A0need=A0=A0to=A0=A0be=A0=A0able=A0=A0to=A0=A0make
student AFS accounts but can&#39;t do that<br>
&gt;=A0=A0=A0=A0without=A0=A0the=A0=A0Kerberos=A0=A0admin=A0=A0password.=A0=
=A0Can
anyone help me reset the<br> &gt;=A0=A0=A0=A0Kerberos admin password?<br> <=
br> <br>What kerberos server are you using? Both MIT and Heimdal have a way=
 of<br> running kadmin locally if you run them on the master KDC --- run th=
is<br>

 option as root on the master KDC, change things as needed.<br> <br><br> --=
<br> Thomas L. Kula | <a href=3D"mailto:kula@tproa.net" target=3D"_blank">k=
ula@tproa.net</a> | <a href=3D"http://kula.tproa.net/" target=3D"_blank">ht=
tp://kula.tproa.net/</a><br>
 _______________________________________________<br>
 OpenAFS-info mailing list<br> <a href=3D"mailto:OpenAFS-info@openafs.org" =
target=3D"_blank">OpenAFS-info@openafs.org</a><br> <a href=3D"https://lists=
.openafs.org/mailman/listinfo/openafs-info" target=3D"_blank">https://lists=
.openafs.org/mailman/listinfo/openafs-info</a><br>

 </blockquote></div><br>

--000e0cd3317ef07457048ceece77--