[OpenAFS] False replay error with 1.7 on Win 7 client

Steve Gaarder gaarder1@math.cornell.edu
Thu, 13 Dec 2012 11:19:44 -0500 (EST)

I made the change and everything seems to be working fine.  Thanks for all=
your advice and enjoy the holidays!

Steve Gaarder
System Administrator, Dept of Mathematics
Cornell University, Ithaca, NY, USA

On Wed, 12 Dec 2012, Brandon Allbery wrote:

> On Wed, Dec 12, 2012 at 8:45 AM, Steve Gaarder <gaarder1@math.cornell.edu=
> wrote:
>       On Tue, 11 Dec 2012, Harald Barth wrote:
>             1. Create afs/math.cornell.edu@MATH.CORNELL.EDU
>             2. Store the key in a keytab file
>             3. Use asetkey to add the key to the keyfile on
>             each of the AFS
>             servers
>       Methinks between 1. and 3. tokens with the new key may
>       fail.
> Yes, I think you're right. =A0THe time period is short enough, though,
> that I think I can live with that.
> If you script it (kadmin *is* scriptable in recent MIT, with some pain), =
> time between creating and adding to the first KeyFile can be milliseconds=
> script pushing that to the other servers and it's still likely to be a fe=
> seconds at most. =A0If using Heimdal, you can use 'ktutil get' and do the=
> one in effectively a single operation (ktutil get -k AFS3KEYFILE:...
> afs/cell@REALM). =A0Then Kerberos-authenticated parallel ssh to push to t=
> other servers for minimum latency. =A0:)
