Subject: | |
From: | |
Reply To: | Eve V. E. Kovacs |
Date: | Tue, 25 Aug 2009 17:08:48 -0500 |
Content-Type: | TEXT/PLAIN |
Parts/Attachments: |
|
|
I just upgraded one of our systems to SL5 and now one of our users
is having problems ssh'ing to minos06.fnal.gov. Everything still works on
all the SL4 systems.
The problem she is having has something to do with the change in kinit
and aklog in SL5. She gets her ticket using kinit and then ssh'es to
minos06. The error she gets on logging in is:
aklog: Couldn't determine realm of user:)aklog: unknown RPC error
(-1765328189) while getting lm
/usr/X11R6/bin/xauth: timeout in locking authority file
On minos06, the users' home area is an /afs file system. When she logs in,
she can't touch her own files. So clearly, she is not getting her AFS
token correctly on the SL5 system.
As suggested in some messages of a few days ago, I tried aliasing
kinit to
/usr/kerberos/bin/kinit ; /usr/bin/aklog
But now, when she tries to get her ticket before ssh'ing to minos06
she gets the error:
aklog: can't get afs configuration (afsconf_Open(/usr/vice/etc))
I also tried
aklog [log in to unmask]
which gave the same error.
Do I just have the syntax wrong, or is there some other setup I need to do
to get aklog working correctly on SL5? (I think my krb5.conf file is ok,
because she has no problem getting a kerberos ticket and ssh'ing to other
hosts that don't use an /afs filesystem)
Thanks
Eve
***************************************************************
Eve Kovacs
Argonne National Laboratory,
Room E-217, Bldg. 362, HEP
9700 S. Cass Ave.
Argonne, IL 60439 USA
Phone: (630)-252-6208
Fax: (630)-252-5047
email: [log in to unmask]
***************************************************************
|
|
|