[OpenAFS] AFS + CrossRealm + FreeIPA + Migration

2014-11-07 Thread Andreas Ladanyi
Hi, i want to migrate my old Server System to a new environment. The Posix Users+Groups are migrated from the old LDAP system to the new FreeIPA LDAP system. I have the following situation: old server: MIT Kerberos 5 - Realm A OpenLDAP without Kerberos schemata OpenAFS Server 1.6 -

Re: [OpenAFS] AFS + CrossRealm + FreeIPA + Migration

2014-11-07 Thread Brandon Allbery
On Fri, 2014-11-07 at 11:41 +0100, Andreas Ladanyi wrote: Kerberos error code returned by get_cred : -1765328370 KRB5KDC_ERR_ETYPE_NOSUPP You are probably still using DES, and need allow_weak_crypto = true in [libdefaults] on clients and the KDC. An answer for the future (and possibly necessary

Re: [OpenAFS] AFS + CrossRealm + FreeIPA + Migration

2014-11-07 Thread Brandon Allbery
On Fri, 2014-11-07 at 15:42 +0100, Andreas Ladanyi wrote: Am 07.11.2014 um 14:46 schrieb Brandon Allbery: On Fri, 2014-11-07 at 11:41 +0100, Andreas Ladanyi wrote: Kerberos error code returned by get_cred : -1765328370 KRB5KDC_ERR_ETYPE_NOSUPP You are probably still using DES, and need

Re: [OpenAFS] AFS + CrossRealm + FreeIPA + Migration

2014-11-07 Thread Andreas Ladanyi
Am 07.11.2014 um 14:46 schrieb Brandon Allbery: On Fri, 2014-11-07 at 11:41 +0100, Andreas Ladanyi wrote: Kerberos error code returned by get_cred : -1765328370 KRB5KDC_ERR_ETYPE_NOSUPP You are probably still using DES, and need allow_weak_crypto = true in [libdefaults] on clients and the

Re: [OpenAFS] AFS + CrossRealm + FreeIPA + Migration

2014-11-07 Thread Andreas Ladanyi
Am 07.11.2014 um 15:49 schrieb Brandon Allbery: On Fri, 2014-11-07 at 15:42 +0100, Andreas Ladanyi wrote: Am 07.11.2014 um 14:46 schrieb Brandon Allbery: On Fri, 2014-11-07 at 11:41 +0100, Andreas Ladanyi wrote: Kerberos error code returned by get_cred : -1765328370 KRB5KDC_ERR_ETYPE_NOSUPP