We have been having problems with the pam_krb5 module. It takes a long time 20-30 seconds after entering your password for a prompt to return. We having been able to figure out this problem yet. Here is a sample of output from syslog during a login. 

Of special interest is the 20 second jump at the following point:
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: preparing to place v4 credentials in '/tmp/tkt1529_Ic5472'
Oct 25 12:13:52 rfs2 sshd[5472]: pam_krb5[5472]: could not obtain initial v4 creds: 7 (Argument list too long)

Any advice on what is wrong or how to debug this further would be helpful.

Thanks.

-KAS


Oct 25 12:13:33 rfs2 sshd(pam_unix)[5472]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=156.56.13.2  user=seiffert
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: configured realm 'IU.EDU'
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: flags: forwardable
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: flag: no ignore_afs
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: flag: tokens
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: flag: user_check
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: flag: krb4_convert
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: flag: warn
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: ticket lifetime: 36000
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: renewable lifetime: 36000
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: banner: Kerberos 5
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: ccache dir: /tmp
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: keytab: /etc/krb5.keytab
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: called to authenticate 'seiffert'
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: authenticating '[EMAIL PROTECTED]'
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: trying previously-entered password for 'seiffert'
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: authenticating '[EMAIL PROTECTED]' to 'krbtgt/[EMAIL PROTECTED]'
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: krb5_get_init_creds_password(krbtgt/[EMAIL PROTECTED]) returned 0 (Success)
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: got result 0 (Success)
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: obtaining v4-compatible key
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: obtained des-cbc-crc v5 creds
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: converting v5 creds to v4 creds (etype = 1)
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: conversion failed: -1765328377 (Server not found in Kerberos database)
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: obtaining initial v4 creds
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: converted principal to 'seiffert'[.]''@'IU.EDU'
Oct 25 12:13:33 rfs2 sshd[5472]: pam_krb5[5472]: preparing to place v4 credentials in '/tmp/tkt1529_Ic5472'
Oct 25 12:13:52 rfs2 sshd[5472]: pam_krb5[5472]: could not obtain initial v4 creds: 7 (Argument list too long)
Oct 25 12:13:52 rfs2 sshd[5472]: pam_krb5[5472]: error obtaining v4 creds: 57 (Invalid slot)
Oct 25 12:13:52 rfs2 sshd[5472]: pam_krb5[5472]: authentication succeeds for 'seiffert' ([EMAIL PROTECTED])
Oct 25 12:13:52 rfs2 sshd[5472]: pam_krb5[5472]: pam_authenticate returning 0 (Success)
Oct 25 12:13:52 rfs2 sshd[5470]: Accepted keyboard-interactive/pam for seiffert from ::ffff:156.56.13.2 port 52071 ssh2
Oct 25 12:13:52 rfs2 sshd(pam_unix)[5473]: session opened for user seiffert by (uid=0)
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: configured realm 'IU.EDU'
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: flags: forwardable
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: flag: no ignore_afs
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: flag: user_check
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: flag: krb4_convert
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: flag: warn
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: ticket lifetime: 36000
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: renewable lifetime: 36000
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: banner: Kerberos 5
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: ccache dir: /tmp
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: keytab: /etc/krb5.keytab
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: no v5 creds for user 'seiffert', skipping session setup
Oct 25 12:13:52 rfs2 sshd[5473]: pam_krb5[5473]: pam_open_session returning 0 (Success)
Oct 25 12:13:52 rfs2 pam_loginuid[5473]: set_loginuid failed opening loginuid


Kurt A. Seiffert                        | [EMAIL PROTECTED]
UITS Distributed Storage Services Group | C: 812-345-1892
Indiana University, Bloomington         | W: 1 812-855-5089     

Reply via email to