arla-0.41 and support for Tiger

Jean-Damien Durand Jean-Damien.Durand at cern.ch
Wed Jan 11 15:28:29 CET 2006


On Monday, 9 January 2006 15:53, Harald Barth wrote:
> 3a) After using kinit which uses krb5.conf and DNS to find your kerberos
> server you get a ticket granting ticket:
./..
> 3b) With that you can get a service ticket for AFS from your AFS cell
> or cells:
./..
> $ /usr/openafs/bin/tokens
>
> Tokens held by the Cache Manager:
>
> User's (AFS ID 22421) tokens for afs at pdc.kth.se [Expires Jan  9 21:20]

Dear Harald,

Thank you very much for your detailed post! I'm a basic user, while you are an 
expert - May I ask, so, perhaps a question that would sound basic!

If I do kinit + klist like that:

% kinit --no-afslog
jdurand at CERN.CH's Password:
% klist -T
Credentials cache: FILE:/tmp/krb5cc_27343
        Principal: jdurand at CERN.CH

  Issued           Expires          Principal
Jan 11 15:15:42  Jan 12 16:15:39  krbtgt/CERN.CH at CERN.CH

Jan 11 09:35:27  Jan 11 17:35:27  Tokens for cern.ch

This sound normal. Now I do kalog and issue the arla's tokens command:

% kalog jdurand at cern.ch
Getting ticket for jdurand at cern.ch
Password:
% tokens

Tokens held by Arla:

Tokens for afs at cern.ch [Expires Jan 11 23:16]
   --End of list--

- Why do I not see something like: User's (AFS ID ...) etc ?
- When doing kalog, and if there is a krb.conf in addition to CellServDB, will 
krb.conf be used (you said that krb4 are a little bit better than kaservers - 
that's why I ask) ?

Btw when I said kerberos4 was to be dropped in debian, I meant that heimdal 
was now compiled without the support of it. I guess this is why, before the 
drop, when I was doing kinit I got everything in one go, and that now I have 
to do kalog in addition...

Thanks for your comments!

Cheers, JD.


More information about the Arla-drinkers mailing list