On July 10, 2017 8:16:05 AM EDT, Andreas Haupt <andreas.ha...@desy.de> wrote:
>... it "succeeds" in the CERN.CH case:
>Jul 10 13:27:36 fred-vm1 kdc: TGS-REQ aha...@ifh.de from
>IPv4:188.8.131.52 for host/lxplus040.cern...@ifh.de [canonicalize,
>Jul 10 13:27:36 fred-vm1 kdc: Searching referral for
>Jul 10 13:27:36 fred-vm1 kdc: Server not found in database:
>"Server not found" == "Success"? Is this really the expected answer? I
>guess, no - but not really sure ...
This is a bug in the kdc, or possibly two bugs. First, the database lookup
failed and no entry was returned, but the error code was not set and so
remained zero, which com_err translates as "Success".
Second, the kdc is not sending any response at all. That causes the client to
eventually time out and try another kdc. When it runs out of kdcs, it reports
an error (unable to contact any kdc in realm).
you can confirm this by watching traffic between your client and kdc on port
88, using your favorite packet-capture tool.