Re: [OpenAFS] Help: aklog cannot work properly

2011-06-01 Thread Lee Eric
Thanks mates. I have fixed those problem properly.

Regards,

Eric

On Wed, Jun 1, 2011 at 9:00 PM, Jeffrey Altman
 wrote:
> On 6/1/2011 1:03 AM, Lee Eric wrote:
>> Hi,
>>
>> It seems aklog cannot work well in my server.
>>
>>
>> [root@server ~]# klist
>> Ticket cache: FILE:/tmp/krb5cc_0
>> Default principal: admin@HERDINGCAT.INTERNAL
>>
>> Valid starting     Expires            Service principal
>> 06/01/11 00:55:12  06/02/11 00:55:10
>> krbtgt/HERDINGCAT.INTERNAL@HERDINGCAT.INTERNAL
>>       renew until 06/01/11 00:55:12
>> [root@server ~]# aklog -d -c herdingcat.internal
>> Authenticating to cell herdingcat.internal (server 
>> server.herdingcat.internal).
>> Trying to authenticate to user's realm HERDINGCAT.INTERNAL.
>> Getting tickets: afs/herdingcat.internal@HERDINGCAT.INTERNAL
>> Kerberos error code returned by get_cred : -1765328370
>
> -1765328370 = KDC has no support for encryption type
>
> In other words, your KDC has support for DES-CBC-CRC turned off.
> Re-enable support for DES encryption types and you will get further.
>
> Jeffrey Altman
>
>
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info


Re: [OpenAFS] Help: aklog cannot work properly

2011-06-01 Thread Jeffrey Altman
On 6/1/2011 1:03 AM, Lee Eric wrote:
> Hi,
> 
> It seems aklog cannot work well in my server.
> 
> 
> [root@server ~]# klist
> Ticket cache: FILE:/tmp/krb5cc_0
> Default principal: admin@HERDINGCAT.INTERNAL
> 
> Valid starting ExpiresService principal
> 06/01/11 00:55:12  06/02/11 00:55:10
> krbtgt/HERDINGCAT.INTERNAL@HERDINGCAT.INTERNAL
>   renew until 06/01/11 00:55:12
> [root@server ~]# aklog -d -c herdingcat.internal
> Authenticating to cell herdingcat.internal (server 
> server.herdingcat.internal).
> Trying to authenticate to user's realm HERDINGCAT.INTERNAL.
> Getting tickets: afs/herdingcat.internal@HERDINGCAT.INTERNAL
> Kerberos error code returned by get_cred : -1765328370

-1765328370 = KDC has no support for encryption type

In other words, your KDC has support for DES-CBC-CRC turned off.
Re-enable support for DES encryption types and you will get further.

Jeffrey Altman



signature.asc
Description: OpenPGP digital signature


Re: [OpenAFS] Help: aklog cannot work properly

2011-06-01 Thread Jeff Blaine

On 6/1/2011 1:03 AM, Lee Eric wrote:

Hi,

It seems aklog cannot work well in my server.


[root@server ~]# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin@HERDINGCAT.INTERNAL

Valid starting ExpiresService principal
06/01/11 00:55:12  06/02/11 00:55:10
krbtgt/HERDINGCAT.INTERNAL@HERDINGCAT.INTERNAL
renew until 06/01/11 00:55:12
[root@server ~]# aklog -d -c herdingcat.internal
Authenticating to cell herdingcat.internal (server server.herdingcat.internal).
Trying to authenticate to user's realm HERDINGCAT.INTERNAL.
Getting tickets: afs/herdingcat.internal@HERDINGCAT.INTERNAL


Does this principal exist?  ^^^


Kerberos error code returned by get_cred : -1765328370
aklog: Couldn't get herdingcat.internal AFS tickets:
aklog: unknown RPC error (-1765328370) while getting AFS tickets
[root@server ~]# ls /afs
ls: cannot access /afs/herdingcat.internal: No such device
herdingcat.internal
[root@server ~]# fs wscell
This workstation belongs to cell 'openafs.org'
[root@server ~]#

And I noticed that the client belongs to openafs.org, how this could be?


What does your 'ThisCell' file say?
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info


[OpenAFS] Help: aklog cannot work properly

2011-05-31 Thread Lee Eric
Hi,

It seems aklog cannot work well in my server.


[root@server ~]# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin@HERDINGCAT.INTERNAL

Valid starting ExpiresService principal
06/01/11 00:55:12  06/02/11 00:55:10
krbtgt/HERDINGCAT.INTERNAL@HERDINGCAT.INTERNAL
renew until 06/01/11 00:55:12
[root@server ~]# aklog -d -c herdingcat.internal
Authenticating to cell herdingcat.internal (server server.herdingcat.internal).
Trying to authenticate to user's realm HERDINGCAT.INTERNAL.
Getting tickets: afs/herdingcat.internal@HERDINGCAT.INTERNAL
Kerberos error code returned by get_cred : -1765328370
aklog: Couldn't get herdingcat.internal AFS tickets:
aklog: unknown RPC error (-1765328370) while getting AFS tickets
[root@server ~]# ls /afs
ls: cannot access /afs/herdingcat.internal: No such device
herdingcat.internal
[root@server ~]# fs wscell
This workstation belongs to cell 'openafs.org'
[root@server ~]#

And I noticed that the client belongs to openafs.org, how this could be?

Could anyone show me how to fix that?

Thanks very much.

Eric
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info