[27721] in Kerberos
Re: Lots of UNKNOWN_SERVER this time... whoa
daemon@ATHENA.MIT.EDU (Ken Hornstein)
Mon Apr 30 15:10:40 2007
Message-Id: <200704301910.l3UJACeG021458@ginger.cmf.nrl.navy.mil>
To: kerberos@mit.edu
In-Reply-To: <46363BDB.2070609@kickflop.net>
Date: Mon, 30 Apr 2007 15:10:12 -0400
From: Ken Hornstein <kenh@cmf.nrl.navy.mil>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
>The authentication process is trying to find
>krbtgt/rcf.foo.com@RCF.FOO.COM which does not exist.
>
>Is kdb5_util creating an improperly named krbtgt principal
>or is RHELv4 pam_krb5.so improperly naming its requested
>principal (lowercasing it)?
As a guess, I believe that pam_krb5.so thinks that it needs to authenticate
to the realm rcf.foo.com, so it's asking for a cross-realm ticket to go
between rcf.foo.com and RCF.FOO.COM. I don't see anything in your
krb5.conf that would make it think that, but something is hinky here.
(It's definately not a problem on your KDC, FWIW).
--Ken
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos