[22332] in Kerberos

home help back first fref pref prev next nref lref last post

Re: kpasswd times out!

daemon@ATHENA.MIT.EDU (isfandarmad)
Tue Aug 31 14:49:35 2004

From: isfandarmad <brother_sand@yahoo.com>
Message-ID: <pan.2004.08.31.17.44.03.326524@yahoo.com>
Date: Tue, 31 Aug 2004 12:44:11 -0500
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

OK,
        Here are the details of my kpasswd problem.  Domain names, Realm
names, and user names have been changed to protect the innocent.

This is what shows up in the kdc log when I first run kpasswd:

Aug 31 12:00:06 kdc1.ourdomain.com krb5kdc[4654](info): AS_REQ
(7 etypes {18 17 16 23 1 3 2}) 192.168.2.101: NEEDED_PREAUTH:
myuser@OURREALM.COM for kadmin/changepw@OURREALM.COM, Additional
pre-authentication required

        When I type in my password, I get a response asking for my new password
and the following entry appears in the kdc log:

Aug 31 12:00:09 kdc1.ourdomain.com krb5kdc[4654](info): AS_REQ
(7 etypes {18 17 16 23 1 3 2}) 192.168.2.101: ISSUE: authtime
1093971609, etypes {rep=16 tkt=16 ses=16}, myuser@OURREALM.COM for kadmin/changepw@OURREALM.COM

        That's all the ever appears in the log.  I have the kadmin log
segregated and nothing ever shows up in that log during this
opperation.  Here's what the client side looks like:

myuser@machine:~$ kpasswd
Password for myuser@OURREALM.COM:
Enter new password: :
Enter it again: :
kpasswd: Connection timed out changing password


Here's what the access control file (kadm5.acl) has:

# This file Is the access control list for krb5 administration.
# When this file is edited run /etc/init.d/krb5-admin-server restart to activate
# One common way to set up Kerberos administration is to allow any principal
# ending in /admin  is given full administrative rights.
# To enable this, uncomment the following line:
 */admin *
*/admin@OURREALM.COM   *
myuser@OURREALM.COM     cli     *
kadmin/admin@OURREALM.COM *
kadmin/changepw@OURREALM.COM   *       *


Thanks.
D.


On Mon, 30 Aug 2004 18:46:45 -0500, isfandarmad wrote:

> OK,
> 	I have set up a functioning KDC in a Debian linux environment.  I have a
> couple of machines with the kerberized ssh package, keytabs in place, and
> everything is just dandy.  I log in, get a ticket and can then ssh to
> several other machines without having to enter another password.
> 
>  	But kpasswd always fails.  I run kpasswd - it asks me for my password
>  (username@REALM) - I enter it and it asks for my new password.  After I
>  enter it (the second time) it just waits.  Eventually it times out.
> 
> 	I'm not at the office right now so I don't have the details that would
> normally be requested.  I'll post them up tomorrow.  But has anyone ever
> come across this problem?  I have googled all over and can't find anyone
> who has ever had this issue.
> 
> Detail to follow.  Thanks.
> D.


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post