[OpenAFS-port-darwin] after 10.6.3 upgrade: aklog: a pioctl failed while obtaining tokens

Fabien COMBERNOUS fcombernous@kezia.com
Wed, 07 Apr 2010 09:47:03 +0200


Derrick Brashear wrote:
> On Tue, Apr 6, 2010 at 9:31 AM, Fabien COMBERNOUS <fcombernous@kezia.com> wrote:
>   
>> Derrick Brashear wrote:
>>     
>>> Try 1.5.73.2, now on the web site.
>>>
>>> Fixes 32 bit binaries which set tokens.
>>>
>>>       
>> My cell looks better. But, i have yet some issues.
>> kinit <my admin user> followed by aklog permit to get a token.
>> But then i'm not able to set acl like explained here :
>> http://docs.openafs.org/QuickStartUnix/ch02s28.html
>>
>> # fs setacl /afs system:anyuser rl
>> fs: You don't have the required access rights on '/afs'
>>     
>
> dynroot. and this isn't a Mac issue. And this isn't the general
> OpenAFS list. Try openafs-info, like I suggested 2 weeks ago.
>   

You said this two weeks ago ? Perhaps. But the fix about pioctl is not 
so old.
OpenAFS-1.5.73.2-Snowleopard.dmg was released the 4th, less than a week ago.
The required access rights issue is a general issue. But i can't meet 
this issue without the dmg fix. And i'm not an AFS expert.

Well, for archives my rights issue was because my kerberos realm name 
was different of my cell name. In this case, the file 
/usr/afs/etc/krb.conf have to contains the kerberos realm name.

Thank you to billings and phalenor for solving this issue by IRC.

Best regards,


P.S : On my MacOSX /usr/afs is a link to 
/Library/OpenAFS/Tools/root.server/usr/afs.

-- 
*Fabien COMBERNOUS*
/unix system engineer/
www.kezia.com <http://www.kezia.com/>
*Tel: +33 (0) 467 992 986*
Kezia Group