[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: ktutil and afs-KeyFile
Maybe it's better to display the default realm name.
In the case where the afs cellname is not the same as the realm name, one has
to create /usr/afs/etc/krb.conf (or link it to /etc/krb.conf). krb.conf
contains the realm name, /usr/afs/etc/ThisCell contains the cell name.
Maybe this information should be added to the afs info on
http://www.h5l.se/manual/HEAD/info/heimdal.html#Cross-realm
Kind Regards
On Thursday 10 May 2007 21:11, you wrote:
>
> On May 10, 2007, at 14:51 , Ronny Blomme wrote:
>
> > I want to check if the KeyFile realy contains the key for
> > afs@REALM.ELIS.UGENT.BE:
> >
> > # ktutil copy AFSKEYFILE:/usr/afs/etc/KeyFile FILE:/tmp/afs.keytab
> > # ktutil -k /tmp/afs.keytab list
> > /tmp/afs.keytab:
> > Vno Type Principal
> > 1 des-cbc-md5 afs/elis.ugent.be@ELIS.UGENT.BE
> >
> > This is the wrong principal!
>
> The KeyFile doesn't actually store a principal; it stores raw keys,
> indexed by kvno. ktutil fakes a standard principal name for display.
>
--
Ronny Blomme - http://www.elis.UGent.be/RonnyBlomme
***********************************************************************
This e-mail and/or its attachments may contain confidential information.
It is intended solely for the intended addressee(s). Any use of the
information contained herein by other persons is prohibited.
Both IMEC vzw and Ghent University do not accept any liability for the
contents of this mail and/or its attachments.
PGP signature