arla-0.41 and support for Tiger
Jean-Damien Durand
Jean-Damien.Durand at cern.ch
Wed Jan 11 15:28:29 CET 2006
On Monday, 9 January 2006 15:53, Harald Barth wrote:
> 3a) After using kinit which uses krb5.conf and DNS to find your kerberos
> server you get a ticket granting ticket:
./..
> 3b) With that you can get a service ticket for AFS from your AFS cell
> or cells:
./..
> $ /usr/openafs/bin/tokens
>
> Tokens held by the Cache Manager:
>
> User's (AFS ID 22421) tokens for afs at pdc.kth.se [Expires Jan 9 21:20]
Dear Harald,
Thank you very much for your detailed post! I'm a basic user, while you are an
expert - May I ask, so, perhaps a question that would sound basic!
If I do kinit + klist like that:
% kinit --no-afslog
jdurand at CERN.CH's Password:
% klist -T
Credentials cache: FILE:/tmp/krb5cc_27343
Principal: jdurand at CERN.CH
Issued Expires Principal
Jan 11 15:15:42 Jan 12 16:15:39 krbtgt/CERN.CH at CERN.CH
Jan 11 09:35:27 Jan 11 17:35:27 Tokens for cern.ch
This sound normal. Now I do kalog and issue the arla's tokens command:
% kalog jdurand at cern.ch
Getting ticket for jdurand at cern.ch
Password:
% tokens
Tokens held by Arla:
Tokens for afs at cern.ch [Expires Jan 11 23:16]
--End of list--
- Why do I not see something like: User's (AFS ID ...) etc ?
- When doing kalog, and if there is a krb.conf in addition to CellServDB, will
krb.conf be used (you said that krb4 are a little bit better than kaservers -
that's why I ask) ?
Btw when I said kerberos4 was to be dropped in debian, I meant that heimdal
was now compiled without the support of it. I guess this is why, before the
drop, when I was doing kinit I got everything in one go, and that now I have
to do kalog in addition...
Thanks for your comments!
Cheers, JD.
More information about the Arla-drinkers
mailing list