Kyle McDonald wrote:
> Hi all, I'm getting this message in /var/krb5/kdc.log when trying to
> enable the kadmin service:
>
>> Oct 05 11:02:02 KeyMaster kadmind[2520](Error): Unable to set 
>> RPCSEC_GSS service name (`kiprop at KDC0.RelEng.Egenera.COM'), failing.
>
> kadmin.local listprincs shows:
>
>> root at KeyMaster:/var/svc/profile# kadmin.local          Authenticating 
>> as principal root/admin at RELENG.EGENERA.COM with password.
>> kadmin.local: listprincs
>> K/M at RELENG.EGENERA.COM
>> changepw/keymaster.releng.egenera.com at RELENG.EGENERA.COM
>> kadmin/changepw at RELENG.EGENERA.COM
>> kadmin/history at RELENG.EGENERA.COM
>> kadmin/keymaster.releng.egenera.com at RELENG.EGENERA.COM
>> kiprop/KDC0.RelEng.Egenera.COM at RELENG.EGENERA.COM
>> kiprop/kdc0.releng.egenera.com at RELENG.EGENERA.COM
>> kiprop/keymaster.releng.egenera.com at RELENG.EGENERA.COM
>> kmcdonald/admin at RELENG.EGENERA.COM
>> krbtgt/RELENG.EGENERA.COM at RELENG.EGENERA.COM
>> kadmin.local:
>
> I created 'kiprop/kdc0.releng.egenera.com at RELENG.EGENERA.COM' first
> according to the docs. Then I made
> 'kiprop/KDC0.RelEng.Egenera.COM at RELENG.EGENERA.COM' as an attempt to fix
> the error above.
>
> Where did I go wrong?

So it looks like we are dealing with three different host names for this 
server, right?

KeyMaster
kdc0
KDC0

So which one of the three is the actual canonical name for this host?  
Is this reflected in DNS?

-- 
Shawn.

Reply via email to