[19606] in Kerberos

home help back first fref pref prev next nref lref last post

Active Directory as KDC, MIT Kerberos (Debian) as client

daemon@ATHENA.MIT.EDU (Timo Veith)
Thu Jul 17 08:31:09 2003

From: Timo Veith <tv@rz-zw.fh-kl.de>
Date: Thu, 17 Jul 2003 14:21:55 +0200
Message-ID: <bf64j8$7p7$1@news.uni-kl.de>
To: kerberos@MIT.EDU
Errors-To: kerberos-bounces@mit.edu

Hi all,

I am trying to change my password on the KDC which is running on a Active
Directory Controller (Windows Server 2003). I can get a TGT successfully
but when I run kpasswd I give it my current password and then get the
following error message:

tv@gareth [~] kpasswd
Password for timo@DS.FH-KL.DE:
kpasswd: Requested effective lifetime is negative or too short getting
initial ticket

The docs of MIT don't say much about this error, only that it is a valid
error code :(

Here is the output from klist, the time on the client and on the server:

tv@gareth [~] klist -f
Ticket cache: FILE:/tmp/krb5cc_1000
Default principal: timo@DS.FH-KL.DE

Valid starting     Expires            Service principal
07/17/03 14:03:16  07/17/03 23:59:03  krbtgt/DS.FH-KL.DE@DS.FH-KL.DE
        Flags: FPIA


tv@gareth [~] date
Thu Jul 17 14:17:05 CEST 2003

On the Server 14:16:02

What am I doing wrong?

TIA

Timo
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post