[OpenAFS] AFS/KRB principal service constraints?

Alena Manova nymano@seznam.cz
Tue, 26 Jan 2010 14:47:38 +0100 (CET)


I have strange issue with AFS authentication.

There are any problems with user principal access. Even server principals for http/* servers work fine (eg. krb principal http/server.domain.tld@REALM with afs equivalent http.server can authenticate and access the AFS)

But can't make it working for cron/* principals - created cron/server.domain.tld@REALM principal and cron.server AFS user but no way to obtain AFS tokens. the procedure is the same like for http/* principals which work fine, so I am confused.

is there some constraint what is accepted as service in the principal?

thank you, Nick.