[OpenAFS] NetRestrict

2007-03-14 Thread Steve Devine
Environment: Volserver is OpenAFS 1.4.2 built 2007-02-19 OS is Suse 10.2 Server has an Iscsi enclosure on a private ip address (192.168.0.9) I put NetRestrict file in place in /usr/afs/local/ inside file I put one line 192.168.0.255 Hoping to cover entire subnet. restart bosserver move a volume

Re: [OpenAFS] NetRestrict

2007-03-14 Thread Derrick J Brashear
On Wed, 14 Mar 2007, Steve Devine wrote: Environment: Volserver is OpenAFS 1.4.2 built 2007-02-19 OS is Suse 10.2 Server has an Iscsi enclosure on a private ip address (192.168.0.9) I put NetRestrict file in place in /usr/afs/local/ inside file I put one line 192.168.0.255 Hoping to cover

Re: [OpenAFS] NetRestrict

2007-03-14 Thread Steve Devine
Derrick J Brashear wrote: On Wed, 14 Mar 2007, Steve Devine wrote: Environment: Volserver is OpenAFS 1.4.2 built 2007-02-19 OS is Suse 10.2 Server has an Iscsi enclosure on a private ip address (192.168.0.9) I put NetRestrict file in place in /usr/afs/local/ inside file I put one line

Re: [OpenAFS] NetRestrict

2007-03-14 Thread Derrick J Brashear
On Wed, 14 Mar 2007, Steve Devine wrote: Derrick J Brashear wrote: On Wed, 14 Mar 2007, Steve Devine wrote: Environment: Volserver is OpenAFS 1.4.2 built 2007-02-19 OS is Suse 10.2 Server has an Iscsi enclosure on a private ip address (192.168.0.9) I put NetRestrict file in place in

Re: [OpenAFS] Passwordless login through ssh on krb5/afs enabled workstation.

2007-03-14 Thread Walter Lamagna
I am using PAM + AFS to authenticate the user, i have given persmissions to everybody read the .ssh directory of the users home directory, but ssh complains with: pam_afs[25129]: AFS Won't use illegal password for user walter How could i resolve it ? Thanks Walter On Thu, 2007-03-08 at 10:20

Re: [OpenAFS] Passwordless login through ssh on krb5/afs enabled workstation.

2007-03-14 Thread Russ Allbery
Walter Lamagna [EMAIL PROTECTED] writes: I am using PAM + AFS to authenticate the user, i have given persmissions to everybody read the .ssh directory of the users home directory, but ssh complains with: pam_afs[25129]: AFS Won't use illegal password for user walter How could i resolve it

Re: [OpenAFS] Passwordless login through ssh with pam/afs.

2007-03-14 Thread Walter Lamagna
Yes, i want to login to a server though ssh authenticating with public key, using the authorized_keys2 file located in the users home directory, i have this directive in sshd_config: AuthorizedKeysFile ~/.ssh/authorized_keys2 How can i do this ? Thanks Walter On Wed, 2007-03-14 at 08:39

Re: [OpenAFS] Passwordless login through ssh with pam/afs.

2007-03-14 Thread Russ Allbery
Walter Lamagna [EMAIL PROTECTED] writes: Yes, i want to login to a server though ssh authenticating with public key, using the authorized_keys2 file located in the users home directory, i have this directive in sshd_config: AuthorizedKeysFile ~/.ssh/authorized_keys2 How can i do this ?

Re: [OpenAFS] NetRestrict

2007-03-14 Thread Steve Devine
Derrick J Brashear wrote: On Wed, 14 Mar 2007, Steve Devine wrote: Derrick J Brashear wrote: On Wed, 14 Mar 2007, Steve Devine wrote: Environment: Volserver is OpenAFS 1.4.2 built 2007-02-19 OS is Suse 10.2 Server has an Iscsi enclosure on a private ip address (192.168.0.9) I put

Re: [OpenAFS] Passwordless login through ssh with pam/afs.

2007-03-14 Thread Walter Lamagna
Thanks for your answer. It is acceptable for me to doesnt have the token when i ssh, the ~/.ssh directory in the users home (which is in the AFS) is publicly readable. But i do get this error when i want to ssh to the host: pam_afs[26655]: AFS Won't use illegal password for user integra Does

Re: [OpenAFS] Passwordless login through ssh with pam/afs.

2007-03-14 Thread Russ Allbery
Walter Lamagna [EMAIL PROTECTED] writes: Thanks for your answer. It is acceptable for me to doesnt have the token when i ssh, the ~/.ssh directory in the users home (which is in the AFS) is publicly readable. But i do get this error when i want to ssh to the host: pam_afs[26655]: AFS

[OpenAFS] Vista compatibility

2007-03-14 Thread Andrew Bacchi
I'll be upgrading both hardware and software for our AFS servers next summer. Will OpenAFS 1.4.x on the servers be compatible with the client for MS Vista when it is ready, or will I need to upgrade the server software to 1.5 too? -- veritatas simplex oratio est -Seneca

[OpenAFS] Windows XP SP2, OpenAFS 1.4.3rc3, KfW 2.6.5

2007-03-14 Thread James Rogers
I'm having a problem getting OpenAFS 1.4.3 and KfW 2.6.5 working properly. I'm working on Windows XP SP2 joined to a Windows 2003 Active Directory domain. I installed and configured both clients (OpenAFS and KfW). When I login to the domain with my user account I get AFS tokens and

Re: [OpenAFS] Windows XP SP2, OpenAFS 1.4.3rc3, KfW 2.6.5

2007-03-14 Thread Douglas E. Engert
James Rogers wrote: I'm having a problem getting OpenAFS 1.4.3 and KfW 2.6.5 working properly. I'm working on Windows XP SP2 joined to a Windows 2003 Active Directory domain. I installed and configured both clients (OpenAFS and KfW). When I login to the domain with my user account I get AFS

Re: [OpenAFS] Vista compatibility

2007-03-14 Thread Jeffrey Altman
Andrew Bacchi wrote: I'll be upgrading both hardware and software for our AFS servers next summer. Will OpenAFS 1.4.x on the servers be compatible with the client for MS Vista when it is ready, or will I need to upgrade the server software to 1.5 too? OpenAFS 1.4 on the servers is

Re: [OpenAFS] Windows XP SP2, OpenAFS 1.4.3rc3, KfW 2.6.5

2007-03-14 Thread Douglas E. Engert
James Rogers wrote: On Mar 14, 2007, at 2:52 PM, Douglas E. Engert wrote: Options: Rename one of the realms, and maybe use cross realm between them. Just use the AD KDCs for everything. Is there some documentation available on how to set up the KfW client to use Active Directory

[OpenAFS] umbc's mod_waklog stuff

2007-03-14 Thread Robert Banz
I just posted this to the mod_waklog developers list, however, I think this stuff might be of interest to the rest of the AFS community, since we all seem to have the same problems ;) -- Awhile back I posted something regarding some work we had been doing to the umich mod_waklog to make