home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.protocols.kerberos
- Path: sparky!uunet!mcsun!sunic!ugle.unit.no!news.uit.no!diplom0.cs.uit.no!orjanr
- From: orjanr@diplom0.cs.uit.no (╪rjan Robertsen)
- Subject: Kerberos on HP/Testing
- Keywords: Testing encryption, kadmin
- Sender: orjanr@diplom0.cs.uit.no (Orjan Robertsen)
- Organization: University of Troms°
- Date: Wed, 26 Aug 1992 13:40:04 GMT
- Message-ID: <1992Aug26.134004.27785@news.uit.no>
- Lines: 92
-
- Hello to everyone.
-
- I have some questions which I hope you can help me with:
-
- (Platform: HP 730 HP_UX 8.07)
-
- I have just compiled and installed eBones with patchlevel 9 (to put back the
- calls to the encryption routines), and put in the Kerberos compatible
- deslibrary written by Dana L. How. The kerberos server (kerberos) seems to
- be running all right, and so does kinit, klist and most of the other
- kerberos software. I am able to get an initial ticket and list this.
-
- My problems/questions is as follows:
-
- 1) How can I test that the communication really is encrypted properly ?
- (That is, how can I be sure that the deslibrary functions smooth with
- the rest of Kerberos ?)
- I do not have the verify program which the installation notes talks about.
-
- 2) The kadmind server seems to be running OK, but I experience problems
- with the kadmin program. Every time I try to execute a command I get the
- error message "kadm error: Can't find Kerberos ticket or TGT". This happens
- even if klist tells me I have a ticket for the admin instance. I have made
- sure that an admin instance is registered in the Kerberos database, and that
- the same instance appears on the /kerberos/admin_acl.{add,mod,get). The
- dump of the database, the relevant line of the accesslist, the listing
- from klist and a dump of /kerkeros/kerberos.log is shown below.
-
- DATABASE DUMP:
- changepw kerberos 255 1 1 1 7f000000 0 200001010459 199208251820 * *
- orjanr * 255 1 1 0 7f000000 0 200001010459 199208251822 * *
- K M 255 1 1 0 0 0 200001010459 199208251738 db_creation *
- krbtgt cs.UiT.No 255 1 1 0 7f000000 0 200001010459 199208251738 db_creation *
- changepw diplom0 255 1 1 0 7f000000 0 200001010459 199208251738 db_creation *
- default * 255 1 1 0 0 0 200001010459 199208251738 db_creation *
- orjanr admin 4 1 1 0 7f000000 0 200001010459 199208251822 * *
-
- ACCESSLIST FILES (3 equal ones):
- orjanr.admin@cs.UiT.No
-
- LISTING FROM klist:
- Ticket file: /tmp/tkt640
- Principal: orjanr@cs.UiT.No
-
- Issued Expires Principal
- Aug 26 15:00:39 Aug 26 23:00:39 krbtgt.cs.UiT.No@cs.UiT.No
-
- LISTING OF /kerberos/kerberos.log
- 26-Aug-92 14:48:37 Initial ticket request Host: 129.242.16.40 User: "orjanr" ""
- 26-Aug-92 14:48:37 Initial ticket request Host: 129.242.16.40 User: "orjanr" "admin"
- 26-Aug-92 14:48:40 Initial ticket request Host: 129.242.16.40 User: "orjanr" "admin"
- 26-Aug-92 14:48:40 INITIAL request from orjanr.admin for changepw.kerberos
-
- I have also tried with first getting an admin instance ticket by using
- "ksrvtgt orjanr admin" which gives me the following list from klist:
-
- Ticket file: /tmp/tkt640
- Principal: orjanr.admin@cs.UiT.No
-
- Issued Expires Principal
- Aug 26 15:02:46 Aug 26 15:07:46 krbtgt.cs.UiT.No@cs.UiT.No
-
- This doesn't change the error message from kadmin.
-
- 3) I also had another errormessage from kadmin saying that "principal so and so
- does not exist". This happened even if the principal in question was entered
- in the database and the access files. When this occured I noticed in the
- database log an message saying: UNKNOWN: "changepw" "kerberos", which led me
- to add an principal "changepw" with instance "kerberos" to the database.
- (Line 1 in the database dump above).
-
- Have I made a configuration error or what ?
- What is this changepw thing ? (Can't find it in the documentation).
- Any ideas of what can be wrong ? (Any ideas are welcome!!!!)
-
- 4) Anyway: Is there more documentation on operation of the system. How to do configuration,
- and how it is supposed to work. Specially documentation on kadmin/kadmind and the rest of
- the admin software.
-
-
- Any ideas are welcome, I have used all mine the couple of last days...
-
- Reply by email or post to the group.
-
- Thanks in advance
-
- orjanr
-
- --
- //// ╪rjan W. Robertsen |e-mail : orjanr@staff.cs.uit.no////
- ///Dept. of Computer Science, University|Home : +47-83-82897 ///
- // of Tromsoe, N-9000 TROMS╪, NORWAY |Phone/Fax: +47-83-44053/44580 //
-