[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ktutil and afs-KeyFile



Maybe it's better to display the default realm name.

In the case where the afs cellname is not the same as the realm name, one has 
to create /usr/afs/etc/krb.conf  (or link it to /etc/krb.conf). krb.conf 
contains the realm name, /usr/afs/etc/ThisCell contains the cell name.
Maybe this information should be added to the afs info on 
http://www.h5l.se/manual/HEAD/info/heimdal.html#Cross-realm

Kind Regards

On Thursday 10 May 2007 21:11, you wrote:
> 
> On May 10, 2007, at 14:51 , Ronny Blomme wrote:
> 
> > I want to check if the KeyFile realy contains the key for
> > afs@REALM.ELIS.UGENT.BE:
> >
> > # ktutil copy AFSKEYFILE:/usr/afs/etc/KeyFile FILE:/tmp/afs.keytab
> > # ktutil -k /tmp/afs.keytab list
> > /tmp/afs.keytab:
> > Vno  Type         Principal
> >   1  des-cbc-md5  afs/elis.ugent.be@ELIS.UGENT.BE
> >
> > This is the wrong principal!
> 
> The KeyFile doesn't actually store a principal; it stores raw keys,  
> indexed by kvno.  ktutil fakes a standard principal name for display.
> 

-- 
Ronny Blomme - http://www.elis.UGent.be/RonnyBlomme

***********************************************************************
This e-mail and/or its attachments may contain confidential information.
It is intended solely for the intended addressee(s). Any use of the
information contained herein by other persons is prohibited.
Both IMEC vzw and Ghent University do not accept any liability for the
contents of this mail and/or its attachments.

PGP signature