[36571] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Cannot contact any KDC for realm

daemon@ATHENA.MIT.EDU (Russ Allbery)
Fri Oct 24 13:16:30 2014

From: Russ Allbery <eagle@eyrie.org>
To: debian@lhanke.de
In-Reply-To: <544A3819.6010101@lhanke.de> (Lars Hanke's message of "Fri, 24
	Oct 2014 13:29:29 +0200")
Date: Fri, 24 Oct 2014 09:55:22 -0700
Message-ID: <87siidbe6d.fsf@hope.eyrie.org>
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Lars Hanke <debian@lhanke.de> writes:

> During boot of my system (Debian Wheezy) k5start is invoked to supply a 
> ticket for accessing the AD DC by nslcd. However, during boot it fails:

> k5start: error getting credentials: Cannot contact any KDC for realm 
> 'MY.AD.REALM'

> If I restart k5start using the very same init script once the system is 
> up and running everything works nicely.

> On another system I neither have any issues using a similar boot stack.

> What exactly does this message want to tell me, i.e. where do I start 
> troubleshooting?

It's probably telling you that init script is running before your network
stack is up, and DNS or UDP connectivity is failing when k5start first
runs.

-- 
Russ Allbery (eagle@eyrie.org)              <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post