Re: [OpenAFS] Re: IPA + OpenAFS

2012-07-13 Thread Brandon Allbery
On Fri, Jul 13, 2012 at 11:40 AM, Qing Chang wrote: > Though I get this the next: > [root@smb1 etc]# fs mkmount /afs/openafs.sri.utoronto.ca root.cell > fs: cell dynroot not in /usr/vice/etc/CellServDB > You're using dynroot; you don't need to do this, it's generated dynamically. -- brandon s

Re: [OpenAFS] Re: IPA + OpenAFS

2012-07-13 Thread Qing Chang
Much appreciated to everyone bearing with a newbie with all the dumb questions. It is indeed taken care of dynamically, this runs successfully: [root@smb1 etc]# fs setacl /afs/openafs.sri.utoronto.ca system:anyuser rl Just a humble suggestion, it would help much if there is a few words explicit

Re: [OpenAFS] Re: IPA + OpenAFS

2012-07-13 Thread Derrick Brashear
you're using dynroot. you don't need to (or, indeed, get to) create a mount point in /afs for root.cell. you should already have /afs/openafs.sri.utoronto.ca and /afs/.openafs.sri.utoronto.ca visible. On Fri, Jul 13, 2012 at 11:40 AM, Qing Chang wrote: > Many many thanks. > > After removing the

Re: [OpenAFS] Re: IPA + OpenAFS

2012-07-13 Thread Qing Chang
Many many thanks. After removing the comment line, I got this: [root@smb1 etc]# vos create smb1 /vicepa root.cell Volume 536870915 created on partition /vicepa of smb1 Though I get this the next: [root@smb1 etc]# fs mkmount /afs/openafs.sri.utoronto.ca root.cell fs: cell dynroot not in /usr/vi

[OpenAFS] Re: IPA + OpenAFS

2012-07-13 Thread Andrew Deason
On Fri, 13 Jul 2012 10:15:50 -0400 Qing Chang wrote: > Silly me, I just copied system krb5.conf to the location without > really noticing the difference in name and syntax... > [root@smb1 etc]# cat /usr/afs/etc/krb5.conf > # Realm mapping: > SRI.UTORONTO.CA The file is krb.conf, not krb5.conf. A

Re: Fwd: Re: [OpenAFS] Re: IPA + OpenAFS

2012-07-12 Thread Qing Chang
On 12/07/2012 5:18 PM, Qing Chang wrote: On 12/07/2012 4:47 PM, Andrew Deason wrote: On Thu, 12 Jul 2012 15:10:36 -0500 Qing Chang wrote: [root@smb1 ~]# asetkey list kvno 20: I assume you removed the actual key from this output? That is, 'asetkey' did show a key there. What about

Fwd: Re: [OpenAFS] Re: IPA + OpenAFS

2012-07-12 Thread Qing Chang
On 12/07/2012 4:47 PM, Andrew Deason wrote: On Thu, 12 Jul 2012 15:10:36 -0500 Qing Chang wrote: [root@smb1 ~]# asetkey list kvno 20: I assume you removed the actual key from this output? That is, 'asetkey' did show a key there. What about 'bos listkeys'? Can you run 'kvno afs/open

[OpenAFS] Re: IPA + OpenAFS

2012-07-12 Thread Andrew Deason
On Thu, 12 Jul 2012 15:39:05 -0400 Qing Chang wrote: > I did use asetkey to add the key with thr right vno to KeyFile. But I > was wrong in assuming that I got a keytab with salt: > = > kadmin.local: ktadd -e des-cbc-crc:v4 -k /tmp/openafs > afs/openafs.sri.utoronto.ca [...] > kadmin.local

Re: [OpenAFS] Re: IPA + OpenAFS

2012-07-12 Thread Qing Chang
On 12/07/2012 3:35 PM, Andrew Deason wrote: On Thu, 12 Jul 2012 11:16:55 -0400 Qing Chang wrote: As recommended, you should create an AFS service principal as afs/DOMAIN@REALM, eg, afs/sri.utoronto.ca. IPA does not allow a service principal to be created if there is no corresponding host pri

Re: [OpenAFS] Re: IPA + OpenAFS

2012-07-12 Thread Qing Chang
On 12/07/2012 3:25 PM, Andrew Deason wrote: On Thu, 12 Jul 2012 11:16:55 -0400 Qing Chang wrote: which says that I have to create a keyfile with des-cbc-crc:v4 salt, after some struggle with IPA I finally created the keyfile with des-cbc-crc:v4. It did not help, I still get the same error.

[OpenAFS] Re: IPA + OpenAFS

2012-07-12 Thread Andrew Deason
On Thu, 12 Jul 2012 11:16:55 -0400 Qing Chang wrote: > As recommended, you should create an AFS service principal as > afs/DOMAIN@REALM, eg, afs/sri.utoronto.ca. IPA does not allow a > service principal to be created if there is no corresponding host > principal. Hence, I have to have this: afs/o

[OpenAFS] Re: IPA + OpenAFS

2012-07-12 Thread Andrew Deason
On Thu, 12 Jul 2012 11:16:55 -0400 Qing Chang wrote: > which says that I have to create a keyfile with des-cbc-crc:v4 salt, > after some struggle with IPA I finally created the keyfile with > des-cbc-crc:v4. It did not help, I still get the same error. Did you just extract a keytab, or did you