[30989] in Kerberos

home help back first fref pref prev next nref lref last post

RE: kpasswd: Authentication error: Failed reading application request

daemon@ATHENA.MIT.EDU (Mendez, Franklyn)
Thu Apr 9 08:16:20 2009

Content-class: urn:content-classes:message
MIME-Version: 1.0
Date: Thu, 9 Apr 2009 08:15:10 -0400
Message-ID: <5888FCB767AD5F41A65DC0DCFE91C9210ECE4D1D@EDC-SUW-EXCH.edeltacom.biz>
In-Reply-To: <5888FCB767AD5F41A65DC0DCFE91C9210EC40DF4@EDC-SUW-EXCH.edeltacom.biz>
From: "Mendez, Franklyn" <fmendez@qualitytech.com>
To: <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Any ideas anyone?

Thanks,


Franklyn Mendez 
Sr. UNIX Engineer 
95 Christopher Columbus Drive * 16th Floor * Jersey City, NJ, 07302 
Direct: 212.625.7327 * Fax: 212.625.7246
P THINK GREEN | Don't print this email unless absolutely necessary

-----Original Message-----
From: kerberos-bounces@mit.edu [mailto:kerberos-bounces@mit.edu] On
Behalf Of Mendez, Franklyn
Sent: Tuesday, April 07, 2009 12:09 PM
To: kerberos@mit.edu
Subject: kpasswd: Authentication error: Failed reading application
request 

Need assistance solving this issue.

My Kerberos users can't change their password running kpasswd userid
The client users can successfully login with their accounts. They can
run kinit to acquire a token, but even though they do, they can't change
their password.
The client is configured to use PAM.

Password for user@DOMAININT.COM: 
Enter new password: 
Enter it again: 
Authentication error: Failed reading application request

On the Server's side I do see the client trying to change the user's
password but no more detail:

Apr 07 11:54:17 host02 krb5kdc[13289](info): AS_REQ (5 etypes {16 23 18
3 1}) 10.x.x.x: ISSUE: authtime 1239119657, etypes {rep=16 tkt=16
ses=16}, user@DOMAININT.COM for kadmin/changepw@DOMAININT.COM
Apr 07 11:54:17 host02 krb5kdc[13289](info): AS_REQ (5 etypes {16 23 18
3 1}) 10.x.x.x: ISSUE: authtime 1239119657, etypes {rep=16 tkt=16
ses=16}, user@DOMAININT.COM for kadmin/changepw@DOMAININT.COM

Any ideas?

Thanks all,

QUALITY TECHNOLOGY SERVICES CONFIDENTIALITY NOTICE:  This e-mail message including its attachments is classified COMPANY CONFIDENTIAL.  It is intended for the person or entity to which it is addressed and may contain confidential material.  Quality Technology Services controls the distribution of COMPANY CONFIDENTIAL assets, as such, any unauthorized review, use, disclosure or distribution is prohibited.  If you are not the intended recipient, please contact us at irt@qualitytech.com or 866-239-5000 and destroy all copies of the original message.  Thank you.



________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post