[22123] in Kerberos
Re: leash32 2.6.4 issues
daemon@ATHENA.MIT.EDU (Jeffrey Altman)
Wed Aug 4 13:17:07 2004
From: jaltman@columbia.edu (Jeffrey Altman)
Date: 4 Aug 2004 10:08:43 -0700
Message-ID: <a51eadcf.0408040908.6797c82e@posting.google.com>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
matt@cs.auckland.ac.nz (Matthew Cocker) wrote in message news:<41103AFC.9030500@cs.auckland.ac.nz>...
> Hi
>
> I am using Kerberos for Windows 2.6.4 and have some issues with it. The
> first is that when I use RDP to access a windows XP Pro box as a normal
> user the GUI is very slow unless I copy the conf files from c:\windows
> to the %userprofile%\windows directory for each user, then it seems
> happy. This is similar to how it works on server 2003 TS. Is this the
> intended behavior and this is how I should set it up.
You have installed KFW on your Terminal Server machine without
installing it from within the Add/Remove Programs Control Panel.
Therefore the proper registry entries have not been applied to allow
Leash to read the common KRB5.INI file from %WINDIR%.
> The other problem is with how leash32 interacts with the openafs
> autologon process. The openafs auto logon gets krb5 tickets via leash
> setup (I can see this via the krb5kdc.log) and stores them in
> API:principle@REALM. Now if I start the leash32 gui and change the krb5
> cache to this and refresh the gui I see I have tickets on some machines
> (well one) but on the other 3 PCs I have no tickets until I
> reauthenticate with the afslogon tools. As I don't get a consistent
> result on all the machines I am guessing a configuration error in
> leash32 some how.
Huh?
What is the relationship of the three other PCs to the one which is
running
Leash?
Leash supports one credential cache at a time. Afscreds supports
multiple credential caches at a time and will use the tickets from all
caches including the Leash default cache when it needs to renew
tokens.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos