[OpenAFS] Re: aklog carps Couldn't determine realm of user

Benjamin Kaduk kaduk@mit.edu
Thu, 22 Dec 2016 12:35:56 -0600

On Thu, Dec 22, 2016 at 06:07:08AM +0000, Ted Creedon wrote:
> Heimdal set the ticket up..(I think)
> So how does one login krbtgt?
> PS making progress on the glibc/swig bug
> Suse Leap uses glibc 2.22 the current is 2.24, offhand I suspect  something like a missing .align 64
> tedc
> admin@CREEDON.BIZ's Password:
> ookpik:/data1/openafs-1.8.0pre1 # klist
> Credentials cache: FILE:/tmp/krb5cc_0
>         Principal: admin@CREEDON.BIZ
>   Issued                Expires        Principal
> Dec 21 21:52:59 2016  >>>Expired<<<  krbtgt/CREEDON.BIZ@CREEDON.BIZ

This is the important part; the local TGT in the cache has expired and cannot
be used to get a new service ticket for AFS.  Running 'kinit' should prompt
for admin's password and get things into a workable state where aklog has
a chance at succeeding.