[31334] in Kerberos
Re: krenew: error renewing credentials: KDC returned error string:
daemon@ATHENA.MIT.EDU (Greg Hudson)
Sat Aug 1 08:16:22 2009
From: Greg Hudson <ghudson@mit.edu>
To: "marcus.nilsson@pulsen.se" <marcus.nilsson@pulsen.se>
In-Reply-To: <OF1DE8070C.DCFA2B5D-ONC1257605.002AA0F1-C1257605.002AA111@pulsen.se>
Date: Sat, 01 Aug 2009 08:15:51 -0400
Message-Id: <1249128951.7683.6.camel@ray>
Mime-Version: 1.0
Cc: kerberos <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
On Sat, 2009-08-01 at 03:45 -0400, marcus.nilsson@pulsen.se wrote:
> I'm not able to renew TGT's:
[...]
> mani@irit:~$ krenew
> krenew: error renewing credentials: KDC returned error string: NO PREAUTH
Is the requires-preauth bit set on your krbtgt/MERA.NU principal? For
reasons I don't personally understand, the "NO PREAUTH" error happens
when a TGS request with no preauth comes in for a service (not client)
principal with requires-preauth set.
Also, although I don't think this is at all relevant, krenew comes from
a different source package from MIT Kerberos, so you might test with
"kinit -R" just to remove that variable.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos