[OpenAFS] AFS client -> Windows server w/AD & KDC -> Linux AFS servers

Mickey Lane mlane@sinenomine.net
Thu, 26 May 2011 05:31:46 -0500


Hi,

I want an AFS client (Windows or Linux) to get kerberos credentials from a =
Windows Server and use them to access AFS servers on a Linux machine. The L=
inux machine does not have a KDC.

Although I haven't personally tried it, I'm under the impression this works=
 without too many AD configuration issues with Server 2003.
I'm also under the impression it works with Server 2008 R2 once DES is enab=
led.

I currently have 2008 Standard (not R2) configured to provide tickets and I=
've moved the keytab to the Linux machine, etc. The process *appears* to wo=
rk but the credentials are invalid. Kvno numbers are correct. I think the p=
roblem is improper encryption types.

I'm aware of a Microsoft update to 64-bit Server 2008 that is related to pa=
ssword corruption in this process.

My question: Has anyone ever made this work on Server 2008 Standard (not R2=
)?

Thank you,
Mickey.