Oops -- I meant Mac OS X 10.10.5 (Yosemite).

---------- Forwarded message ----------
From: James F. Green <jfgre...@gmail.com>
Date: Fri, Sep 25, 2015 at 9:20 AM
Subject: OpenAFS on OS X 10.5.5
To: openafs-info@openafs.org


Does anyone have OpenAFS working on Mac OS X 10.5.5?  I've been trying to
get it to work for a while with no success.

I have the YFS-packaged OpenAFS client installed
(OpenAFS-1.6.14-Yosemite.dmg).  Here is what I get with aklog:

jglt:~ jfgreen$ aklog -c msu.edu -k MSU.EDU -d
Authenticating to cell msu.edu (server afsdb0.cl.msu.edu).
We were told to authenticate to realm MSU.EDU.
Getting tickets: afs/msu....@msu.edu
Getting tickets: a...@msu.edu
Kerberos error code returned by get_cred : -1765328370
aklog: Couldn't get msu.edu AFS tickets:
aklog: unknown RPC error (-1765328370) while getting AFS tickets

Googling around for ways to diagnose this, I ran across this:

jglt:~ jfgreen$ kgetcred a...@msu.edu
kgetcred: krb5_get_creds: Error from KDC: BAD_ENCRYPTION_TYPE

Maybe I am still not overcoming Apple's Heimdal not supporting single-DES?
I believe the YFS-packaged OpenAFS includes a private Heimdal version to
get around this.  Maybe I've missed a configuration step somewhere to get
my computer to use the private Heimdal, or maybe it somehow didn't get
installed?  Here is my /etc/krb5.conf:

libdefaults]
    default_realm = MSU.EDU
    noaddresses = TRUE
    dns_lookup_realm = true
    allow_weak_crypto = true
    clockskew = 300
    dns_lookup kdc = true

[realms]
    MSU.EDU =  {
    kdc = kerberos.msu.edu
    kdc = kdc1.kerberos.msu.edu
    kdc = kdc2.kerberos.msu.edu
    admin_server = kerberos.msu.edu
    default_domain = msu.edu
    }

[domain_realm]
    .msu.edu = MSU.EDU
    msu.edu = MSU.EDU

Any help or ideas to try would be appreciated, thanks.

Jim Green
Michigan State University

Reply via email to