[31335] in Kerberos

home help back first fref pref prev next nref lref last post

Re: krenew: error renewing credentials: KDC returned error string: NO

daemon@ATHENA.MIT.EDU (marcus.nilsson@pulsen.se)
Sat Aug 1 09:40:21 2009

In-Reply-To: <1249128951.7683.6.camel@ray>
MIME-Version: 1.0
From: marcus.nilsson@pulsen.se
To: Greg Hudson <ghudson@mit.edu>
Message-ID: <OFAA7069DE.1819FA4B-ONC1257605.004B07D1-C1257605.004B07D6@pulsen.se>
Date: Sat, 1 Aug 2009 15:39:32 +0200
Cc: kerberos <kerberos@mit.edu>
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit

-----Greg Hudson <ghudson@MIT.EDU> wrote: -----

>Is the requires-preauth bit set on your krbtgt/MERA.NU principal?

kadmin:  getprinc krbtgt/MERA.NU
Principal: krbtgt/MERA.NU@MERA.NU
Expiration date: [never]
Last password change: [never]
Password expiration date: [none]
Maximum ticket life: 0 days 10:00:00
Maximum renewable life: 7 days 00:00:00
Last modified: Mon Feb 09 15:24:45 CET 2009 (db_creation@MERA.NU)
Last successful authentication: [never]
Last failed authentication: [never]
Failed password attempts: 0
Number of keys: 5
Key: vno 1, AES-256 CTS mode with 96-bit SHA-1 HMAC, no salt
Key: vno 1, ArcFour with HMAC/md5, no salt
Key: vno 1, Triple DES cbc mode with HMAC/sha1, no salt
Key: vno 1, DES cbc mode with CRC-32, no salt
Key: vno 1, DES cbc mode with RSA-MD5, no salt
MKey: vno 1
Attributes: REQUIRES_PRE_AUTH
Policy: [none]


>Also, although I don't think this is at all relevant, krenew comes
>from
>a different source package from MIT Kerberos, so you might test with
>"kinit -R" just to remove that variable.

mani@irit:~$ kinit -R
kinit: KDC returned error string: NO PREAUTH while renewing credentials


/ Marcus


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos


home help back first fref pref prev next nref lref last post