ms2mit = copy kerberos 5 tickets from MS credentials cache to the default MIT credentials cache

k524init = use Kerberos 5 TGT to obtain a Kerberos 4 TGT

aklog    = use a Kerberos 5 TGT to obtain a Kerberos 5 afs service
           ticket and repackage the Kerberos 5 ticket as an afs 2b token

aklog -4 = use a Kerberos 4 TGT to obtain a Kerberos 4 afs service
           ticket and repackage the Kerberos 4 ticket as an afs token

You do not need to upgrade all of your clients when you upgrade your
servers.  You should upgrade your servers first and then your clients.


Jeffrey Altman



Robbie Foust wrote:
How does the AFS client determine if KFW is installed/running or not? Is there some type of configurable option to force production of Kerberos 4 tickets within the tokens when running aklog, even if Kerberos 5 tickets are available?

I need to be able to use ms2mit, k524init, and aklog from the KFW package for seamless logins. Unfortunately, we aren't able to upgrade our db servers at this time because if our understanding is correct, we must upgrade all file servers too, and then all clients, and we still need to access other cells outside of our control which are still using older AFS builds and don't support Kerberos 5.

Thanks,

- Robbie

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature



Reply via email to