after a
day. Is there any way to have NIM monitor the afs tokens and get new
tokens if the kerberos tickts have an expiry date beyond that of the AFS
tokens? Or would one write a logon script that calls aklog every half
hour? Thanks and best wishes,
Christian
-buildpackage
Best,
Christian
On 15.01.2021 12:04, Valtteri Vuorikoski wrote:
Jakob Haufe writes:
On Fri, 15 Jan 2021 10:17:54 +
No, but 1.8.6-5 (containing the necessary patches) hit unstable
yesterday. As it's been uploaded with urgency "emergency", it should
migrate to bullseye to
Dear Ken,
thank you, this is exactly what I was looking for. I can confirm that it
works. The code from Michael were also very helpful. Thanks to all those
who replied,
Christian
On 04/08/2018 06:40, Ken Hornstein wrote:
>> is there an easy way to check in C (under linux) whether a dir
Hi all,
is there an easy way to check in C (under linux) whether a directory
entry is a mount point for an afs volume and maybe also obtain the name
of the volume mounted?
Thanks,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https
nd set the TransarcAFSDaemon to start manually so it
doesn't start, we can boot the workstation normally login normally. If we
start the service the symptoms persist.
We cannot fix this by uninstalling and reinstalling the client
Has anyone ever ran into this issue? Thank you in advance.
Christian Wat
have the same issue.
Has anyone run into this issue?
Thank you
Christian Watkins
University of Pittsburgh
Information Technology (CSSD) Office: 412.624.2974
Infrastructure
cmw...@pitt.edu<mailto:cmw...@
Am 06.11.2014 18:13, schrieb Andrew Deason:
> On Thu, 06 Nov 2014 00:18:36 +0100
> Christian wrote:
>
>> windump.exe -i blah host 130.75.103.223 and host 130.75.102.221 and
>> not tcp
>>
>> gives me just an arp who-has and reply.
> [...]
>> windump
? If they also have other IPs assigned to them, the traffic could be
> going over those.
The servers have private interfaces too, which are on a different subnet
and not connected to the rest. The fileservers have been told to ignore
these interfaces via NetInfo/NetRestrict.
Thanks,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
Am 05.11.2014 23:42, schrieb Andrew Deason:
> On Tue, 04 Nov 2014 16:05:24 +0100
> Christian wrote:
>
>> on some of our windows clients (win7 enterprise x64, openafs 1.7.31), we
>> are seeing issues where if I try to access a volume on a given server,
>> it gives
Am 05.11.2014 22:24, schrieb Jeffrey Altman:
> On 11/5/2014 4:10 PM, Christian wrote:
>> This is the result of
>> udebug 130.75.103.223 7000
>> on the client, which fails with
>> "return code -2 from VOTE_debug"
>>
>
> udebug will not work agains
On Tue, 04 Nov 2014 16:05:24 +0100 Christian
wrote:
>> on some of our windows clients (win7 enterprise x64, openafs 1.7.31), we
>> are seeing issues where if I try to access a volume on a given server,
>> it gives me "RPC service unavailable". This only happens for o
just fine. Should I post trace logs and udebug output for
people to look at, or what is the appropriate way to debug this? Thanks
a lot,
Christian
PS: I should add that this particular client we are looking at right now
is on the same subnet as the servers, but connected via a layer 2 bridge
wi
Jeffrey,
thanks for the quick answer. Upgrading to 1.6.9 from wheezy-backports
fixed these issues. Thanks a lot!
Best,
Christian
Am 01.11.2014 17:01, schrieb Jeffrey Altman:
> On 11/1/2014 11:48 AM, Christian Lists wrote:
>>
>>>> Dear all,
>>>>
>>>>
indicates that the drive is completely filled up. The total
> > capacity reported corresponds to the quota (which is far from being
> > exceeded). This does not happen on our other file servers, which have
> > <2TB vicep partitions. Is this a known issue? Thanks a lot,
> &
l
capacity reported corrresponds to the quota (which is far from being
exceeded). This does not happen on our other file servers, which have
<2TB vicep partitions. Is this a known issue? Thanks a lot,
Christian
___
OpenAFS-info mailing list
OpenAFS-inf
other workaround?
Any help is appreciated... Happy new year 2014,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
er we
have a support contract for Windows :-( so we probably don't...
Is there a way to find out whether one has a support contract?
Christian
Am 14.10.2013 15:59, schrieb Jeffrey Altman:
> Christian,
>
> Feel free to make noise wherever you wish but the reality is that when
>
submit? We are a University in
Germany and run Windows 7 Enterprise...
Best,
Christian
Am 05.10.2013 02:18, schrieb Jeffrey Altman:
> File a bug report with Microsoft if the problem is experienced when
> using the explorer shell or applications relying upon the shell api for
> file access.
.
I have read the debugging instructions, but I am a little unsure about
how we should proceed here. What should I do? Try fs trace?
Thanks,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
Can't you use wpkg tests for that, since you are using wpkg anyway? I'd
be happy to share our wpkg config for openafs... Best,
Christian
Am 22.08.2013 16:39, schrieb Christof Hanke:
> Hi,
> Am 22.08.2013, 16:33 Uhr, schrieb Gémes Géza :
>
>> Sorry for this slightly off
All,
Thanks for all the useful input. I will look into what I can do on the
KDCs. Best,
Christian
Am 01.08.2013 21:01 schrieb "Jeffrey Hutzelman" :
> On Thu, 2013-08-01 at 12:30 -0400, Jeffrey Altman wrote:
>
>
> > The rxkad-kdf change does not get rid of 1DES. It s
ed in finally getting rid of 1DES and
for the excellent documentation,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
Am 15.05.2013 20:19, schrieb Andrew Deason:
On Wed, 15 May 2013 09:40:50 +0200
Christian wrote:
we plan to upgrade one of our dbservers (scientific linux 5.3) to
debian by rsyncing the installation of our other dbserver, which
already runs debian (both systems x64). WRT openafs, I think I
(/vicep? and /var/cache/openafs) are mounted
correctly before I start the server
How about the vldb and the list of volumes on the server? Do I need to
do anything here? Thanks,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https
cular) has
> made everyone too nervous to make the switch. We should probably do so,
> though, as it will solve a whole host of 64bit issues.
>
Thank you for your answers. I guess I will continue to use my 64-bit
built version of "up" until this feature is included in the main
re
lution to this was to configure openafs with ./configure CC="gcc
-D_FILE_OFFSET_BITS=64".
Is this the desired behaviour and the proper solution to make it
possible to transfer large files with "up"?
Christian Biamont
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
Note you should not mix 1.4 and 1.6 dbservers.
Christian
On 24.09.2012 19:15, Andrew Deason wrote:
On Thu, 20 Sep 2012 09:44:18 +0200
"joerg.b...@gmx.net" wrote:
i want to add a second fileserver to my afs-cell - should i expect any
problems when mixing 1.4 (1.4.11+dfsg-1, debia
%~dp0\netidmgr-AMD64-rel-2_0_102_907.msi
msiexec /qn+ /i %~dp0\openafs-en_US-64bit-1-7-1500.msi
TRANSFORMS=%~dp0\openafs-tf.mst
msiexec /qn+ /i %~dp0\openafs-32bit-tools-en_US-1-7-1500.msi
cp %~dp0\krb5.ini C:\ProgramData\Kerberos\krb5.conf
pause
What is the best way to do something like this
integrated logon. Does anybody have something like this
available or something close which could be modified?
Thanks,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
Jeffrey,
hm. In all cases observed so far, we have been able to eliminate this
issue by installing the latest version of the windows client and by
doing a "fs flushall". I'll let you know whether it reappears on those
machines. Thanks,
Christian
On 18.05.2012 14:55, Jeffr
I can see these three:
OpenAFS Start Pending. Version OpenAFS_1.7.1300.
OpenAFS Running. RDR interface
Security Level is Crypt.
All at system startup. Nothing else. BTW, the machine is configured to
use freelance and use DNS to look for dbservers. Thanks,
Christian
On 18.05.2012 07:25
ess them under linux.
Sometimes, I can access volumes under the RW tree, but not under the RO
tree. This is always different from machine to machine. It does not only
concern our cell, but also browsing other cells from our machines (e. g.
desy.de). What could be wrong here? How can I best help debug thi
Thanks, Jeffrey. With 1.4.12 being the latest version on debian stable,
can I mix 1.4.12 and 1.4.7? Thanks,
Christian
Am 22.10.2011 02:18, schrieb Jeffrey Altman:
Database servers all must be the same version.
You can run 1.4.7 database servers on the 1.6.x fileserver machine but
all of the
it in the
archive, sorry. The only reference I find is
https://lists.openafs.org/pipermail/openafs-devel/2005-March/011717.html
which is admittedly rather old. Thanks,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.o
I apparently dropped off list, my bad. Posting to make it appear in
the archives for future help.
Anyhow, I managed to solve it by installing KfW for 64-bit
(http://www.secure-endpoints.com/#kfw).
Thanks!
-- Forwarded message --
From: Christian Svensson <[EMAIL PROTECTED]>
0 to 1 since the XP client had it
that way - then it starts.
4. Now when I try with getting tokens I get this error:
"Error: -1 (specified realm is unknown)"
KfW did not change its behaviour.
* By the way, MMC crashes if I try to read any AFS errors. I have to
export them to XML
server response triggering the
message.
Greetings!
P.S. I have verified that the AFS server works by using the AFS client
under Windows XP x32
D.S
--
Christian Svensson
Command Systems
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
pgI=
> =sTZl
> -END PGP SIGNATURE-
> ___
> OpenAFS-info mailing list
> OpenAFS-info@openafs.org
> https://lists.openafs.org/mailman/listinfo/openafs-info
>
--
---
Christian Kuka
[EMAIL PROTECTED]
signature.asc
Description: Digital signature
s/db and then run this program
> ERROR: again.
>
> Cell setup failed, ABORTING
> bos removeuser fileserver.x.com matt.admin -localauth
>
> ___
> OpenAFS-info mailing list
> OpenAFS-info@openafs.org
> https://lists.openafs.org/mailman/l
. Thank you very much,
Christian
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
; points to the AFS directory. I can browse the directory fine as a root
> or any other user, but Apache refuses to recognize it. It has to do
> with authentication I believe, but not sure on how to tackle this
> problem.
FollowSymLinks ?
Regards,
Christian
___
Jeffrey Altman wrote:
Christian Fischer wrote:
Jeffrey Altman wrote:
What does afsd_init.log report?
here the log..
8/31/2005 2:37:58 PM: cm_GetRootCellName code 0, cm_freelanceEnabled= 1, rcn=
ethz.ch
8/31/2005 2:37:58 PM: Mountpoint[0] = abled= 1, rcn= ethz.ch
#abled= 1, rcn
Jeffrey Altman wrote:
What does afsd_init.log report?
here the log..
11:54:33 AM: Create log file
11:54:33 AM: Created log file
PATH=C:\Perl\bin\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program
Files\OpenAFS\Common;C:\Program Files\OpenAFS\Client\Program
8/30/2005 11:54:33 A
Jeffrey Altman wrote:
If you are not familiar with how to debug OpenAFS for Windows,
please read afs-install-notes.txt
I can run the afs service, when I disable the freelance-mode..
I will send further information (logs..) next week.
cheers christian
Jeffrey,
I can run the setup, but the service can't be started successfully..
I tried it on an xp sp1 machine..
suggestions?
cheers
Jeffrey Altman wrote:
No. Byte range locking is not in the 1.4 release.
Byte range locking exists on the CVS HEAD and will be released
in a future 1.4 release
ainst kerberos via
LDAP & SASL to a web application server.
It would be a non trivial task to kerberize the application. It was
much easier to use secure the server and use the way over LDAP.
For workstations though we disabled all but kerberos for
authentification.
Regards,
Christia
e of these groups. For the problem to
occur, it is sufficient for that one user to be a member of more than two of
those additional groups. Maybe somebody can comment... Best regards,
Christian
PS: In fact, the group entries come from ldap, but I have verified that the
behaviour is exactly the sam
> I pulled down the source from Sourceforge and I'm not sure what made you
> think that this was based on Cusack's module. As near as I can tell, it's
> based on the Red Hat Kerberos v5 PAM module with nary a sign of Cusack's
> module in sight.
That's true. It's based on the Red Hat module. I was
the READMEs for that module. Can somebody
else check if it compiles against MIT with these modifications?
Christian
- From README.heimdal:
Heimdal port:
=
It's now able to get krb5 tgt,
convert krb5 tgt to krb4 tgt (krb524),
get afs
> Christian Ospelkaus <[EMAIL PROTECTED]> writes:
> > From http://sourceforge.net/projects/pam-krb5/ This used to be the
> > recommended module for some time. Is it still???
>
> There are a few different PAM modules for Kerberos v5, it appears.
> libpam-krb5 in Debia
kg.
Question: Am I doing something wrong or has building this module really become
that difficult? Should the whole auto* stuff be fixed???
With the config I sent to you, credential refreshing with kscreensaver should
work.
Christian
___
OpenAFS
nrequired pam_unix.so
/etc/pam.d/kscreensaver:
authsufficient pam_krb5afs.so ignore_root force_creds refresh_creds
authrequiredpam_unix.so shadow try_first_pass
in /etc/krb5.conf:
[]
[appdefaults]
pam = {
ticket_lifetime = 8
info. I do not really see the link between running OpenAFS on
Windows XP embedded and Windows PE. Maybe somebody can give me a hint...
Christian Ospelkaus
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
https://lists.openafs.org/mailman/listinfo/openafs-info
Hello,
can anybody on this list comment on whether or not the current windows client
will run on XP embedded (R&S FSP spectrum analyzer) ? Best regards,
Christian Ospelkaus
___
OpenAFS-info mailing list
OpenAFS-info@openafs.org
h
artition.
>
># mkdir /vicepxx
>
>
There is no need to to create /vicepxx on a client. /vicepxx is needed only on
file servers.
Christian
--
Christian Pfaffel <[EMAIL PROTECTED]>
Technische Universität Graz Telefon: +43 / 316 / 873 - 81 90
Institut für Theoreti
Jeffrey Altman wrote:
If someone is willing to pay to have this work done I can try to make
time to add this support to the AFS for Windows client.
Jeffrey Altman
how much?:-)
--
Christian Fischer
ETH Zürich
IT Support Group D-AGRL
Schmelzbergstr. 7 / LFV E31
CH-8092 Zürich
Volker Lendecke wrote:
> On Wed, Mar 16, 2005 at 03:02:36PM +, Chris Crowther wrote:
>
>> Would translating those into whole-file locks instead be a workable
>>solution?
>
>
> For Samba as an AFS front end I've got a patch that takes another route: Once
> a
> file is opened in any way (r
Chris Crowther wrote:
> Neulinger, Nathan wrote:
>
>> MS Office does byte range locking - not full file locking. Byte range
>> locks in afs are no-ops. They are completely ignored.
>>
>>
>
>Would translating those into whole-file locks instead be a workable
> solution?
>
translating into
Jeffrey Altman wrote:
Christian Fischer wrote:
no, as I wrote, we didn't notice when the change happened. (Only the
users did :-( ). However, officially afs should support file locking
doesn't it?
What we can see, is that if the file is on a samba share, then MS-Office
opens it only
Jeffrey Altman wrote:
>
> I do not believe there has been any change in behavior. Are you aware
> of a version of AFS for Windows which does what you expect?
no, as I wrote, we didn't notice when the change happened. (Only the
users did :-( ). However, officially afs should support file lockin
ent v. 1.3.7100 under windows xp sp1
and Openafs server 1.2.13 under Solaris)
Any idea?
many thanks in advance.
Chris
--
Christian Fischer
ETH Zürich
IT Support Group D-AGRL
Schmelzbergstr. 7 / LFV E31
CH-8092 Zürich
___
OpenAFS-info mailing list
OpenAFS
Am Montag, 17. Januar 2005 13:51 schrieb Hagbard Celine:
> Thanks Frank and Christian,
>
> I thought too that /var/lib/openafs was the right guess, but seems
> that the Horst suggestion to strace fileserver was wise.
>
> In fact, from the strace:
>
> open("/etc/ope
/var/lib/openafs/NetRestrict
Best regards,
Christian
> On Jan 17, 2005, at 12:23 PM, Hagbard Celine wrote:
> > Hello,
> >
> > This may sound silly, but where's the correct location on Debian where
> > to put the NetRestrict file?
>
> That's always a g
gt; thanks,
>
> Ron
>
Hi Ron!
We had a similar problem. The solution was, that on installation the
configuration file ThisCell got overwritten with a wrong cell, because
the installer (debian) wrongly assumed it to be tu-graz.ac.at instead
of itp.tugraz.at and it overwrote the correct info.
0m0.043s
user0m0.020s
sys 0m0.030s
Any comment would be well appreciated,
regards,
Christian
--
Christian Pfaffel <[EMAIL PROTECTED]>
Technische Universität Graz Telefon: +43 / 316 / 873 - 81 90
Institut für Theoretische PhysikTelefax: +43 / 316 / 873
You might also find this thread interesting:
https://lists.openafs.org/pipermail/openafs-info/2004-March/012559.html
Best regards,
Christian Ospelkaus
___
OpenAFS-info mailing list
[EMAIL PROTECTED]
https://lists.openafs.org/mailman/listinfo/openafs
seems to use only the
public address as expected, but the server doesn't. What's going wrong here?
Thanks for any help,
Christian Ospelkaus
___
OpenAFS-info mailing list
[EMAIL PROTECTED]
https://lists.openafs.org/mailman/listinfo/openafs-info
s caused by "incorrect" usage of PAM: the
> authentication is done in a sub-process. Any change the openssh people
> will be sympathetic to this problem?)
This Is exactly what happens, they are using pthreads or fork.
Christian
--
Christian Pfaffel <[EMAIL PROTECTED]>
Technische Un
don't know what to look for.
Thanks,
Christian
___
OpenAFS-info mailing list
[EMAIL PROTECTED]
https://lists.openafs.org/mailman/listinfo/openafs-info
> Starting from heimdal-0.6 you no longer need kth-krb (v4 support) to get
> afs tokens
> if you use a reasonably recent version of openafs.
Oh, good news. Debian ships 0.4e in the stable distribution... Best regards,
Christian
___
Ope
an't find it in the packages either. But it is part of
the sources of openafs.
> Isn't this one for kaserver, though?
Yes, and it is not installed on my box. I just also pasted the lines starting
with "un" from the output of dpkg -l openafs*
> > openafs-ptutil
>
> Thi
> Yes, you used krb for auth, but do you prevent regular and passwordless
> auth from working?
+:*:0:0:::
in /etc/passwd (or similar for shadow-like configuration) should be enough?
Christian
___
OpenAFS-info mailing list
[EMAIL PROTECTED]
been playing with various settings in
krb5.conf without much success...
Thanks for your help,
Christian Ospelkaus
___
OpenAFS-info mailing list
[EMAIL PROTECTED]
https://lists.openafs.org/mailman/listinfo/openafs-info
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Charles Clancy <[EMAIL PROTECTED]> writes:
> On 28 Oct 2002, Christian Pfaffel wrote:
> >
> > Is there a way to configure a standard xscreensaver/xlock to
> > renew/replace the kerberos V ticket and obtain a newer AFS token
Scott,
At CERN, for some openAFS end-users, we have the same behaviour as the one
described in :
https://lists.openafs.org/pipermail/openafs-devel/2002-May/002936.html
Has the problem being identified, Is there any fix in preparation ?
Cheers; Christian Boissat
536870916 RO 5 K On-line
>
> Total volumes onLine 2 ; Total volumes offLine 0 ; Total busy 0
> - s n i p -
>
> How do I move the two remaining volumes?
>
You do not move a readonly volume. what you have to do is a
# vos addsite papadoc vicepb root.afs
# vos rems
Hi all!
Openafs does not start on my redhat7 box (smp-kernel). Insmod outputs:
"libafs-2.2.16-22.mp.o: unresolved symbol kernel_flag". When i grep my
/proc/ksyms file i find "c01fe400 kernel_flag_R__ver_kernel_flag". Can
someone help me?
Thanks a lot!
With best regards,
Chris
__
77 matches
Mail list logo