[27573] in Kerberos
Re: kerberos and samba
daemon@ATHENA.MIT.EDU (Danny Mayer)
Tue Mar 13 22:02:11 2007
Message-ID: <45F7574A.3060700@ntp.isc.org>
Date: Tue, 13 Mar 2007 22:00:42 -0400
From: Danny Mayer <mayer@ntp.isc.org>
MIME-Version: 1.0
To: "Campbell, Dave L (N-Computer Sciences)" <dave.l.campbell@lmco.com>
In-Reply-To: <636EF1B79EBB8A4BA5ACD62CF1536BE76FDFDA@emss02m12.us.lmco.com>
X-kostecke.net-MailScanner-From: mayer@ntp.isc.org
Cc: kerberos@mit.edu
Reply-To: mayer@ntp.isc.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Campbell, Dave L (N-Computer Sciences) wrote:
> We recently did some security testing on our Domain Controller (DC)
> which involved setting the clock ahead 13 months and then back. After
> doing this our samba servers, Sun systems, could no longer authenticate
> via the DC for share access. We've since rebooted the DC, restarted the
> samba process on the unix systems but still no luck. We attempted to
> remove and re-add the unix systems to the DC but get this error during
> kinit; "Clock skew too great..." The clock skew between all systems is
> <5 sec and the Kerberos security policy is default (5 min).
>
Are you running NTP on all your systems? If not why not? Did you start
ntpd with the -g option?
Danny
>
>
> Any ideas what would be causing this? A cached, timestamped file or
> entry in a file associated with the client system?
>
>
>
> Regards,
>
> Dave L. Campbell
>
> Lockheed Martin
>
>
>
> ________________________________________________
> Kerberos mailing list Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
>
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos