[27717] in Kerberos
KfW 3.2 beta1, OpenAFS 1.5.18 integrated logon for Windows Server
daemon@ATHENA.MIT.EDU (Volkmar Glauche)
Fri Apr 27 09:23:15 2007
Date: Fri, 27 Apr 2007 15:22:38 +0200 (CEST)
From: Volkmar Glauche <volkmar.glauche@uniklinik-freiburg.de>
To: kerberos@mit.edu
Message-ID: <Pine.LNX.4.64.0704271509440.6671@nz23036.ukl.uni-freiburg.de>
MIME-Version: 1.0
Reply-To: Volkmar Glauche <volkmar.glauche@uniklinik-freiburg.de>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Dear List,
I am having trouble getting the above configuration to perform integrated
logon on a Windows 2003 Terminal server. The exact configuration is:
- Samba 3.0.24 acting as Primary/Backup Domain Controller
- Windows 2003 server as domain member
- heimdal KDC with LDAP database backend
Whenever a user tries to login to a terminal server session, I get an
error message "Credential cache I/O failed: XXX". After being logged in,
obtaining tickets and AFS token works fine. However, integrated login
works for the same user if she is logging in to the server console
session, so I think there must be a permissions problem somewhere. I have
tried to ask this also on the OpenAFS side, this is what Jeff Altman said:
http://rt.central.org/rt/Ticket/Display.html?id=59277
I would greatly appreciate any hint on how to debug and fix this problem.
Yours,
--
Volkmar Glauche
-
Department of Neurology volkmar.glauche@uniklinik-freiburg.de
Universitaetsklinikum Freiburg Phone 49(0)761-270-5331
Breisacher Str. 64 Fax 49(0)761-270-5416
79106 Freiburg http://fbi.uniklinik-freiburg.de/
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos