[28346] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Problems with kadmind, kpasswd and cross-realm authentication

daemon@ATHENA.MIT.EDU (Christopher D. Clausen)
Tue Sep 4 19:19:48 2007

Message-ID: <0F92FECD648148D59654343E489891FC@CDCHOME>
From: "Christopher D. Clausen" <cclausen@acm.org>
To: "Anthony Brock" <brocka@sterlingcgi.com>
Date: Tue, 4 Sep 2007 18:19:19 -0500
Cc: kerberos@mit.edu
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Anthony Brock <brocka@sterlingcgi.com> wrote:
> I have created several cross-realm trusts on a test server. At this
> point, nearly everything is working properly. However, users are
> unable to change their passwords unless their account is in the
> initial domain. Users see the following when attempting it from the
> initial domain:
>
> # kpasswd
> Password for brocka@SCGROUP.ORG:
> Enter new password:
> Enter it again:
> Password changed.
> #
>
> Unfortunately, following happens for additional domains:
>
> # kpasswd
> Password for brocka@STERLINGCGI.COM:
> Enter new password:
> Enter it again:
> Authentication error: Failed reading application request
> #

What happens if you run:
kpasswd user@REALM
and manually specify the realm name where the user account is at?
so in your case, try running:
kpasswd brocka@SCGROUP.ORG
on the above machine where you were prompted for brocka@STERLINGCGI.COM 
credentials.

Additionally, are you behind a NAT when kpasswd fails?

<<CDC 


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post