[23320] in Kerberos
Re: KADMIN error
daemon@ATHENA.MIT.EDU (Tom Yu)
Thu Feb 3 13:16:45 2005
To: Dennis Davis <D.H.Davis@bath.ac.uk>
From: Tom Yu <tlyu@mit.edu>
Date: Thu, 03 Feb 2005 13:15:54 -0500
In-Reply-To: <200502031415.aa17620@bath.ac.uk> (Dennis Davis's message of
"Thu, 3 Feb 2005 14:15:52 +0000 (GMT)")
Message-ID: <ldvmzulh5lx.fsf@cathode-dark-space.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
>>>>> "Dennis" == Dennis Davis <D.H.Davis@bath.ac.uk> writes:
Dennis> Well, I'm not concerned about obfuscating kerberos entries. I see
Dennis> the following log entry on my test server:
Dennis> Feb 03 13:45:09 ancho.bath.ac.uk krb5kdc[17597](info): AS_REQ (7 etypes {18 17 16 23 1 3 2}) 138.38.32.80: SERVER_NOT_FOUND: ccsdhd/admin@BATH.AC.UK for kadmin/ancho.bath.ac.uk@BATH.AC.UK, Server not found in Kerberos database
Dennis> This looks wrong to me. It shouldn't be requesting the
Dennis> kadmin/ancho.bath.ac.uk@BATH.AC.UK principal. That would be
Dennis> associated with the machine acting as the kerberos server. Instead
Dennis> it should be requesting the kadmin/admin@BATH.AC.UK principal which
Dennis> is what the 1.3.6 kadmin client does. This would also tally up with
Dennis> the "Required KADM5 principal missing" message.
Ok, that is very useful information to have. The host-based kadmin
principal name was a 1.4 change for SEAM compatibility. It should
fall back to kadmin/admin but does not appear to at the moment. I'll
investigate further.
---Tom
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos