[23085] in Kerberos

home help back first fref pref prev next nref lref last post

Re: SASL problems

daemon@ATHENA.MIT.EDU (David \"3oz\" Sonenberg)
Wed Dec 22 14:27:19 2004

Message-ID: <20041222163329.63889.qmail@web52705.mail.yahoo.com>
Date: Wed, 22 Dec 2004 08:33:29 -0800 (PST)
From: "David \"3oz\" Sonenberg" <pip_prime@yahoo.com>
To: Chris Hallenbeck <cthallen@aol.net>
In-Reply-To: <41C997DD.6070000@aol.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

It was a typo + I have them all sym linked for safe
measure.  So it looks like the principals are the
same.  It's been over 10 years since I graduated High
School and I'm still getting in trouble with the
principal!  Anyway here's the output from my lastest
run.  


# klist -k -t /etc/kerberos/krb5.keytab
Keytab name: FILE:/etc/krb5.keytab
KVNO Timestamp         Principal
---- -----------------
--------------------------------------------------------
   4 12/22/04 09:52:43
host/ldap.myrealm.com@MYREALM.COM
   4 12/22/04 09:53:47
ldap/ldap.myrealm.com@MYREALM.COM

# kadmin -q "getprinc
host/ldap.myrealm.com@MYREALM.COM"
Authenticating as principal root/admin@MYREALM.COM
with password.
Principal: host/ldap.myrealm.com@MYREALM.COM
Expiration date: [never]
Last password change: Wed Dec 22 09:52:43 EST 2004
Password expiration date: [none]
Maximum ticket life: 1 day 00:00:00
Maximum renewable life: 0 days 00:00:00
Last modified: Wed Dec 22 09:52:43 EST 2004
(root/admin@MYREALM.COM)
Last successful authentication: [never]
Last failed authentication: [never]
Failed password attempts: 0
Number of keys: 1
Key: vno 4, DES cbc mode with CRC-32, no salt
Attributes:
Policy: [none]


--- Chris Hallenbeck <cthallen@aol.net> wrote:

> David "3oz" Sonenberg wrote:
> 
> > lt-sample-server: SASL Other: GSSAPI Error: 
> > Miscellaneous failure (see text) (failed to find
> > host/ldap.myrealm.com@MYREALM.COM(kvno 3) in
> keytab
> > FILE:/etc/kerberos/krb5.keytab)
> 
> > scp /tmp/ldap.keytab
> > ldap.myrealm.com:/etc/krb5/krb5.keytab
> > scp /tmp/Manager.keytab
> ldap.myrealm.com:/etc/openldap
> 
>    The error message in this case is looking for
> your keytab in
> /etc/*kerberos*/krb5.keytab, but you scp'd the file
> to
> /etc/*krb5*/krb5.keytab.
> 
>    If that was a typo on your part *grin*, we'll
> move on to other ways 
> to troubleshoot this:
> 
> klist -k -t /etc/_PATH_/krb5.keytab
> 
> In the output, you'll have KVNO info.
> 
> kadmin -q "getprinc
> host/ldap.myrealm.com@MYREALM.COM"
> 
> Compare the KVNO info. Do they match?
> 
> 
> -Chris
> 

> ATTACHMENT part 2 application/x-pkcs7-signature
name=smime.p7s




	
		
__________________________________ 
Do you Yahoo!? 
Yahoo! Mail - You care about security. So do we. 
http://promotions.yahoo.com/new_mail
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post