[27572] in Kerberos

home help back first fref pref prev next nref lref last post

kerberos and samba

daemon@ATHENA.MIT.EDU (Campbell, Dave L (N-Computer Scien)
Tue Mar 13 16:29:58 2007

Date: Tue, 13 Mar 2007 14:24:43 -0600
From: "Campbell, Dave L (N-Computer Sciences)" <dave.l.campbell@lmco.com>
To: kerberos@mit.edu
Message-id: <636EF1B79EBB8A4BA5ACD62CF1536BE76FDFDA@emss02m12.us.lmco.com>
MIME-version: 1.0
Content-class: urn:content-classes:message
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

We recently did some security testing on our Domain Controller (DC)
which involved setting the clock ahead 13 months and then back.  After
doing this our samba servers, Sun systems, could no longer authenticate
via the DC for share access.  We've since rebooted the DC, restarted the
samba process on the unix systems but still no luck.  We attempted to
remove and re-add the unix systems to the DC but get this error during
kinit; "Clock skew too great..."  The clock skew between all systems is
<5 sec and the Kerberos security policy is default (5 min).

 

Any ideas what would be causing this?  A cached, timestamped file or
entry in a file associated with the client system?

 

Regards,

Dave L. Campbell

Lockheed Martin

 

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post