Lars Schimmer wrote:
> Hi!
> 
> I´ve got some questions about Win LogOn and obtaining tokens/tickets
> while logon.
> 
> Our setup: 1 windows AD server (CGV is the domain name)
> 1 linux MIT krb5 server (REALM: CGV.TUGRAZ.AT)
> OpenAFS Cell cgv.tugraz.at

Rename one of your realms.  Or add afs/cgv.tugraz.at service tickets to
both realms with different kvnos and insert both keys in the AFS keyfile.

> Yes, two different krb5 server, it´s bad, I know.

And it will make things almost impossible for you to support for any
service other than AFS.

> Til yet (krb5 <3.1 and OpenAFS <1.5.16) everything went more or less
> well. Win XP SPII clients are in the CGV domain, user logon and obtained
>  krb5 tickets for CGV.TUGRAZ.AT and a token for cgv.tugraz.at (win
> profile is on AFS space).

You really should use KFW 3.2 and OpenAFS 1.5.19.  See the security
advisories.  The critical thing you need to do is disable DNS lookups
for Kerberos and disable the importation of the MSLSA: credentials.

> I just installed krb5 2.x or 3.0, setup the REALM info in the
> krb5.config in C:\WINDOWS to the linux MIT krb5 server and configure
> OpenAFS to obtain tokens while logging in.
> 
> 
> I was told the official way now is to obtain tickets/tokens via the
> leash manager 3.2 and not via OpenAFS 1.5.x

Not Leash but Network Identity Manager using the AFS Credential Provider
installed by OpenAFS.  See the OpenAFS release notes.

> Right now I expirienced some flaws while obtaining tickets/tokens (user
> can change krb5 settings AFTER logon, but with not correct setting, they
> can´t logon ??) or just not getting any tickets.
> I assume the 2 krb5 servers (one AD server, one linux MIT) are the problem.

yes they are.

> Anyone got a hint/info about conifg this system the right way?
> (no, not using only the win server or cross auth, I just think about the
> clients).

Realms are unique by name.  As long as you have two realms with the same
name you are always going to have problems.   You can hack around them
for AFS but you are never going to be able to work around them for all
services.  Microsoft provides a mechanism for performing domain name
renames.  You really should consider using it.

Jeffrey Altman
Secure Endpoints Inc.


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to