[2244] in Kerberos-V5-bugs
Re: "Miscellaneous RPC error" with beta7
daemon@ATHENA.MIT.EDU (Nick Kralevich)
Wed Sep 18 06:59:23 1996
Date: Wed, 18 Sep 1996 03:57:36 -0700 (PDT)
From: Nick Kralevich <nickkral@porsche.autobahn.org>
To: Barry Jaspan <bjaspan@MIT.EDU>
Cc: krb5-bugs@MIT.EDU, "Benjamin C. Craft" <bcraft@bcraft.camd.lsu.edu>
In-Reply-To: <9609171835.AA24241@DUN-DUN-NOODLES.MIT.EDU>
Thanks for your suggestion Barry. I did what you requested, and the info
is below. There are two log records, one of when I ran the kadmin
command, and one of when I ran the kadmind command. Funny thing is, the
first two lines of the "kadmind.log" appeared right away, before I even
connected via the kadmin command. There were no unusual entries in the
syslog.
Here is some more basic system info, just FYI:
Linux 2.0.14, based on RedHat 3.0.3 (http://www.redhat.com)
GCC version 2.7.2
Kerberos beta7 compiled with default options.
I appreciate any help you can give me.
----- Begin kadmin.log -----
Script started on Wed Sep 18 03:43:53 1996
[root@granada /tmp]# /usr/local/sbin/kadmin
Enter password:
marshall_new_creds: starting
marshall_new_creds: auth_gssapi_creds is 12 bytes
marshall_new_creds: succeeding
gssapi_create: calling GSSAPI_INIT (1)
gssapi_marshall: not established, sending null verf
gssapi_wrap: context not established, noop
gssapi_refresh: failing
call_arg protocol version 3 rejected, trying 2.
gssapi_create: calling GSSAPI_INIT (1)
gssapi_marshall: not established, sending null verf
gssapi_wrap: context not established, noop
gssapi_refresh: failing
call_arg protocol version 2 rejected, trying 1.
gssapi_create: calling GSSAPI_INIT (1)
gssapi_marshall: not established, sending null verf
gssapi_wrap: context not established, noop
gssapi_refresh: failing
call_arg protocol version 1 rejected, trying 0.
gssapi_create: calling GSSAPI_INIT (1)
gssapi_marshall: not established, sending null verf
gssapi_wrap: context not established, noop
gssapi_refresh: failing
gssapi_create: GSSAPI_INIT (1) failed, stat 7
gssapi_create: bailing
gssapi_destroy: no client_handle, not calling destroy
gssapi_destroy: deleting context
gssapi_destroy: done
kadmin: GSS-API (or Kerberos) error while initializing kadmin interface
[root@granada /tmp]# exit
exit
Script done on Wed Sep 18 03:44:16 1996
----- End kadmin.log -----
----- Begin kadmind.log -----
Script started on Wed Sep 18 03:43:37 1996
[root@granada /root]# /usr/local/sbin/kadmind -nofork
GSS-API authentication error acquiring credentials: Miscellaneous failure
GSS-API authentication error acquiring credentials: No principal in keytab matches desired name
svcauth_gssapi: starting
clean_client: starting
clean_client: done
svcauth_gssapi: decoding credentials
svcauth_gssapi: got credentials, version 2, client_handle len 0
svcauth_gssapi: GSSAPI_INIT, creating client.
svcauth_gssapi: empty creds, creating
create_client: new client_data = 0x8098a00
svcauth_gssapi: new handle 1
create_client: done
svcauth_gssapi: context is not established
svc_gssapi_unwrap: not established, noop
svcauth_gssapi: trying creds 0
svcauth_gssapi: creds are correct, storing
svcauth_gssapi: accept_sec_context returned 0
svcauth_gssapi: got new output token
svcauth_gssapi: context established, isn 269167349
gssapi_seal_seq: failed
GSS-API authentication error sealing sequence number: The context has expired
GSS-API authentication error sealing sequence number: No error
svcauth_gssapi: starting
clean_client: starting
clean_client: client_data = 0x8098a00
clean_client: client 1 expired
destroy_client: destroying client_data
destroy_client: client_data = 0x8098a00
dump_db: before frees:
client_data = 0x8098a00, exp = 843043439
GSS-API authentication error deleting context: The context has expired
GSS-API authentication error deleting context: No error
destroy_client: client 1 destroyed
clean_client: done
svcauth_gssapi: decoding credentials
svcauth_gssapi: got credentials, version 2, client_handle len 0
svcauth_gssapi: GSSAPI_INIT, creating client.
svcauth_gssapi: empty creds, creating
create_client: new client_data = 0x8098880
svcauth_gssapi: new handle 2
create_client: done
svcauth_gssapi: context is not established
svc_gssapi_unwrap: not established, noop
svcauth_gssapi: trying creds 0
svcauth_gssapi: creds are correct, storing
svcauth_gssapi: accept_sec_context returned 0
svcauth_gssapi: got new output token
svcauth_gssapi: context established, isn 1169529124
gssapi_seal_seq: failed
GSS-API authentication error sealing sequence number: The context has expired
GSS-API authentication error sealing sequence number: No error
svcauth_gssapi: starting
clean_client: starting
clean_client: client_data = 0x8098880
clean_client: client 2 expired
destroy_client: destroying client_data
destroy_client: client_data = 0x8098880
dump_db: before frees:
client_data = 0x8098880, exp = 843043439
GSS-API authentication error deleting context: The context has expired
GSS-API authentication error deleting context: No error
destroy_client: client 2 destroyed
clean_client: done
svcauth_gssapi: decoding credentials
svcauth_gssapi: got credentials, version 2, client_handle len 0
svcauth_gssapi: GSSAPI_INIT, creating client.
svcauth_gssapi: empty creds, creating
create_client: new client_data = 0x80987c0
svcauth_gssapi: new handle 3
create_client: done
svcauth_gssapi: context is not established
svc_gssapi_unwrap: not established, noop
svcauth_gssapi: trying creds 0
svcauth_gssapi: creds are correct, storing
svcauth_gssapi: accept_sec_context returned 0
svcauth_gssapi: got new output token
svcauth_gssapi: context established, isn 889801541
gssapi_seal_seq: failed
GSS-API authentication error sealing sequence number: The context has expired
GSS-API authentication error sealing sequence number: No error
svcauth_gssapi: starting
clean_client: starting
clean_client: client_data = 0x80987c0
clean_client: client 3 expired
destroy_client: destroying client_data
destroy_client: client_data = 0x80987c0
dump_db: before frees:
client_data = 0x80987c0, exp = 843043439
GSS-API authentication error deleting context: The context has expired
GSS-API authentication error deleting context: No error
destroy_client: client 3 destroyed
clean_client: done
svcauth_gssapi: decoding credentials
svcauth_gssapi: got credentials, version 2, client_handle len 0
svcauth_gssapi: GSSAPI_INIT, creating client.
svcauth_gssapi: empty creds, creating
create_client: new client_data = 0x8098700
svcauth_gssapi: new handle 4
create_client: done
svcauth_gssapi: context is not established
svc_gssapi_unwrap: not established, noop
svcauth_gssapi: bad GSSAPI_INIT version
[root@granada /root]# exit
Script done on Wed Sep 18 03:44:19 1996
----- End kadmind.log -----
On Tue, 17 Sep 1996, Barry Jaspan wrote:
>
> However, when I try to run "kadmin", from any computer, I always get the
> following errors in the admin_server error messages:
>
> Sep 16 09:51:09 Miscellaneous RPC error: 206.79.223.2, internal error
> sealing sequence number
> Sep 16 09:51:09 Miscellaneous RPC error: 206.79.223.2, Warning: Accepted
> old RPC protocol request
> Sep 16 09:51:09 Miscellaneous RPC error: 206.79.223.2, internal error
> sealing sequence number
> Sep 16 09:51:09 Miscellaneous RPC error: 206.79.223.2, Warning: Accepted
> old RPC protocol request
> Sep 16 09:51:09 Miscellaneous RPC error: 206.79.223.2, internal error
> sealing sequence number
> Sep 16 09:51:09 Miscellaneous RPC error: 206.79.223.2, unsupported
> GSSAPI_INIT version
>
> None of those errors should be possible. I have no idea what could be
> causing them; it looks like the RPC request is getting munged
> somewhere. As an initial guess, I'd suggest going into your lib/rpc
> directory, editing the Makefile to add -DDEBUG_GSSAPI=100 on the
> compile line, recompiling libgssrpc.a, and then relinking kadmind.
> Run it with -nofork so you can see messages printed to stderr, run
> kadmin, and send both the syslog and stderr output to krb5-bugs.
>
> Barry
>