Thanks for the help, I believe I now have my UNIX and Windows AFS clients authenticating against an MIT K5 server.
Rekeying the afs principal and moving the key to KeyFile using asetkey may have been what did it. Although who knows, there were some AFS server restarts in there also -- it wasn't clear whether KeyFile is read after a server starts and it was easy enough to just give users some warning and then restart them all. The only user-visible change is for password-changing which is easy enough to manage. Now on to the job of converting to native K5... -- Joe Buehler _______________________________________________ OpenAFS-info mailing list OpenAFS-info@openafs.org https://lists.openafs.org/mailman/listinfo/openafs-info