Hi all,
        we are running AFS 3.4a with MIT Kerberos V4 KDC as authentication
server.

        Now we would like to change our file system structure and move the
majority of disk space (including user's home dirs) to AFS space. So we
have to be able authenticate our users during login process. Because we
want/need continue to support MIT Kerberos services (some services from
Athena environment), we are thinking about possibility to setup AFS
kaserver as our KDC and replace the standard login/klog/tokens with *.krb
version. 

        As far as I know, this is unsupported (but working)
configuration. Hopefully there is some set of users using similar setup
and could give me some suggestion :-)

        Let me ask you some question:

- could someone recommend me to do described changes
- can kaserver serve (partially/entirely) as KV4 KDC/TGS for V4 clients
- can coexist kaserver & V4 kerberos (even on same machine)
- are there any problems or special configuration needs in case we have
  different names for cell and kerberos realm
- any other solution which allow users to authenticate to AFS & Kerberos
  V4/V5 at login time (maybe DCE/K5 stuff?)

Any comments, help, suggestion or experience (even negative) are welcome!

Thank you very much in advance for your help!

Best regards,
        Lubos


--------------------------------------------------------------------------
Lubos Kejzlar
System and Network Specialist

Laboratory for Computer Science                     Tel.:   +42-19 2171210
University of West Bohemia                                  +42-19 7221530
Americka 42, 30614 Pilsen                           Fax:    +42-19 2171485
Czech Republic                                      E-mail: [EMAIL PROTECTED]
--------------------------------------------------------------------------

Reply via email to