Tim Schaab wrote:
 > May 09 11:43:04 kdc1.geology.wisc.edu krb5kdc[4081](info): TGS_REQ (1
> etypes {1}) 144.92.X.X: PROCESS_TGS: authtime 0,  <unknown client> for
> afs/[EMAIL PROTECTED], Clock skew too great
> May 09 11:43:04 kdc1.geology.wisc.edu krb5kdc[4081](info): TGS_REQ (1
> etypes {1}) 144.92.X.X: PROCESS_TGS: authtime 0,  <unknown client> for
> afs/[EMAIL PROTECTED], Clock skew too great
> May 09 11:43:04 kdc1.geology.wisc.edu krb5kdc[4081](info): TGS_REQ (1
> etypes {1}) 144.92.X.X: PROCESS_TGS: authtime 0,  <unknown client> for
> afs/[EMAIL PROTECTED], Clock skew too great
> May 09 11:43:04 kdc1.geology.wisc.edu krb5kdc[4081](info): TGS_REQ (1
> etypes {1}) 144.92.X.X: PROCESS_TGS: authtime 0,  <unknown client> for
> afs/[EMAIL PROTECTED], Clock skew too great
> 
> -- END krb5kdc.log --
> 
> Clock skew shouldn't be an issue though since the KDC, AFS server, and
> client are all synced up almost to the second. In addition, if I use the
> AFS client window instead of the NIM, I can obtain an AFS token and the
> NIM can even see the token I received from the AFS client.

Are you able to

  kvno afs/[EMAIL PROTECTED]

???

What about

  aklog -d geology.wisc.edu

???

When you obtain the AFS token with afscreds, does an associated TGT
appear in the NIM listing?

Jeffrey Altman
Secure Endpoints Inc.


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to