Hi all, I have two servers with brand new VDI 3.1 installation plus SSGD.

 

Everything is configured, and working ok only for SOME users, awesome L

 

My krb5.conf file looks like the following:

 

[libdefaults]

        default_realm = DOMAIN.COM

        default_checksum = rsa-md5

 

[realms]

        DOMAIN.COM = {

                kdc = server1

                kdc = server2

                admin_server = server1

                kpasswd_server = server1

                kpasswd_protocol = SET_CHANGE

        }

                

[domain_realm]

rectorat.url.es = DOMAIN.COM

.rectorat.url.es = DOMAIN.COM

 

[logging]

        default = FILE:/var/krb5/kdc.log

        kdc = FILE:/var/krb5/kdc.log

        kdc_rotate = {

 

# How often to rotate kdc.log. Logs will get rotated no more

# often than the period, and less often if the KDC is not used

# frequently.

 

                period = 1d

 

# how many versions of kdc.log to keep around (kdc.log.0, kdc.log.1, ...)

 

                versions = 10

        }

 

[appdefaults]

        kinit = {

                renewable = true

                forwardable= true

        }

        gkadmin = {

                help_url =
http://docs.sun.com:80/ab2/coll.384.1/SEAM/@AB2PageView/1195

        }

 

Kinit authentication works for ALL users, but only some users will
authenticate SSGD (configured for AD) and Sun Ray.

 

Even trying /opt/SUNWvda/lib/vda-client –u USER will work only for some
users, and other not.

 

If I create a test user in AD, it will not work.

 

Restarting servers, cacaoadm, etc... does not solve the issue...

 

Any ideas? I can test at nights, as this is in production with old version
(using Virtual Machines)

 

Thanks a lot!

 

------------------------------------------------------------------------

Víktu Pons i Colomer

------------------------------------------------------------------------

 

_______________________________________________
SunRay-Users mailing list
[email protected]
http://www.filibeto.org/mailman/listinfo/sunray-users

Reply via email to