[36573] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Cannot contact any KDC for realm

daemon@ATHENA.MIT.EDU (Brandon Allbery)
Fri Oct 24 13:18:53 2014

From: Brandon Allbery <ballbery@sinenomine.net>
To: "kerberos@mit.edu" <kerberos@mit.edu>
Date: Fri, 24 Oct 2014 16:53:24 +0000
Message-ID: <1414169615.18702.9.camel@vikktakkht>
In-Reply-To: <544A3819.6010101@lhanke.de>
Content-Language: en-US
Content-ID: <B2A305091BC78E4B9F51461D88E2A0E9@mex05.mlsrvr.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On Fri, 2014-10-24 at 13:29 +0200, Lars Hanke wrote:
> During boot of my system (Debian Wheezy) k5start is invoked to supply a 
> ticket for accessing the AD DC by nslcd. However, during boot it fails:
> 
> k5start: error getting credentials: Cannot contact any KDC for realm 
> 'MY.AD.REALM'
> 
> If I restart k5start using the very same init script once the system is 
> up and running everything works nicely.
> 
> On another system I neither have any issues using a similar boot stack.
> 
> What exactly does this message want to tell me, i.e. where do I start 
> troubleshooting?

First thing I'd check is whether the network is actually up when it
runs. This means more than just the proper network interfaces on the
machine being up; for example, certain network and switch configurations
can lead to the switch port not passing packets until spanning tree has
completed.

-- 
brandon s allbery kf8nh                           sine nomine associates
allbery.b@gmail.com                              ballbery@sinenomine.net
unix openafs kerberos infrastructure xmonad        http://sinenomine.net

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post