f



kinit: Cannot contact any KDC for realm 'EXAMPLE.COM' while getting initial credentials

Hi!

I have set up a kerberos server srv.example.com. This server has
address 192.168.180.30. Address resolution works fine on the server
and client:

srv.example.com:
# host srv
srv.example.com has address 192.168.180.30
# host 192.168.180.30
30.180.168.192.in-addr.arpa domain name pointer srv.example.com.
# host client
client.example.com has address 192.168.180.6
# host 192.168.180.6
6.180.168.192.in-addr.arpa domain name pointer client.example.com
#

client.example.com:
# host srv
srv.example.com has address 192.168.180.30
# host 192.168.180.30
30.180.168.192.in-addr.arpa domain name pointer srv.example.com.
# host client
client.example.com has address 192.168.180.6
# host 192.168.180.6
6.180.168.192.in-addr.arpa domain name pointer client.example.com
#

Now from the server:
# kinit user
kinit: Cannot contact any KDC for realm 'EXAMPLE.COM' while getting
initial credentials

and from the client:
# kinit user
kinit: Cannot contact any KDC for realm 'EXAMPLE.COM' while getting
initial credentials

I am a bit lost what's going on here. In /etc/krb5.conf I have:
[libdefaults]
        default_realm = EXAMPLE.COM
        dns_lookup_kdc = true
        dns_lookup_realm = true

# The following krb5.conf variables are only for MIT Kerberos.
        krb4_config = /etc/krb.conf
        krb4_realms = /etc/krb.realms
        kdc_timesync = 1
        ccache_type = 4
        forwardable = true
        proxiable = true

[realms]
        EXAMPLE.COM = {
                kdc = srv.example.com
                admin_server = srv.example.com
                default_domain = example.com
        }

[domain_realm]
        .example.com = EXAMPLE.COM
        example.com = EXAMPLE.COM

[login]
        krb4_convert = true
        krb4_get_tickets = false

[logging]
        default = FILE:/var/log/kerberos/krb5lib.log

The dns-server returns for srv-queries:
# host -t srv _kerberos._tcp.example.com
_kerberos._tcp.example.com has SRV record 0 5 88 srv.example.com.

I'm a bit lost now. Turning dns_lookup_kdc on/off doesn't help.
kinit just keeps telling me It could not contact any kdc for this
realm (EXAMPLE.COM).

Any ideas?

-- 
Thomas
0
tps (39)
1/25/2011 4:54:16 PM
comp.protocols.kerberos 5541 articles. 1 followers. jwinius (31) is leader. Post Follow

4 Replies
6161 Views

Similar Articles

[PageSpeed] 19

On Tue, Jan 25, 2011 at 05:54:16PM +0100, Thomas Schweikle wrote:
> kinit just keeps telling me It could not contact any kdc for this
> realm (EXAMPLE.COM).
> 
> Any ideas?

Is your KDC running? Is your KDC firewalled off?

Try running tcpdump udp port 88 on both client and server, then kinit.

Regards,

Brian.
0
b.candler (2627)
1/25/2011 10:06:00 PM
Am 25.01.2011 23:06, schrieb Brian Candler:
> On Tue, Jan 25, 2011 at 05:54:16PM +0100, Thomas Schweikle wrote:
>> kinit just keeps telling me It could not contact any kdc for this
>> realm (EXAMPLE.COM).
>> 
>> Any ideas?
> 
> Is your KDC running? Is your KDC firewalled off?
> 
> Try running tcpdump udp port 88 on both client and server, then kinit.

kdc was running, no firewall settings, tcpdump on port 88 on client
and server gave communication between both.

At last I decided to reboot the server. After that it worked again :(

Looks a loot like Ubuntu is more and more some sort of Windows ;)


-- 
Thomas
0
tps (39)
1/26/2011 9:17:13 PM
How can I know if the KDC is running and if the KDC firewalled is off ?



--
View this message in context: http://kerberos.996246.n3.nabble.com/kinit-Cannot-contact-any-KDC-for-realm-EXAMPLE-COM-while-getting-initial-credentials-tp19145p37678.html
Sent from the Kerberos - General mailing list archive at Nabble.com.
0
Done
6/24/2013 7:57:01 AM
It's nothing about the firewalled. I tried the samba 2:3.5.6 and samba
2:3.6.6-2.
All kinds of small tips should notice. Good luck to all.



--
View this message in context: http://kerberos.996246.n3.nabble.com/kinit-Cannot-contact-any-KDC-for-realm-EXAMPLE-COM-while-getting-initial-credentials-tp19145p37771.html
Sent from the Kerberos - General mailing list archive at Nabble.com.
0
Done
7/10/2013 2:03:50 AM
Reply:

Similar Artilces:

'example.com' == 'example.com.' => false... is this intended?
Hi Tanaka, I don't understand why DNS::Name#== requires both to be absolute if one is. Is this really necessary/useful? It surprises me. Also, I have a set of comparison operations for Resolv::DNS::Name. I copied the style (and docs) from Module/hierarchy comparisons, because I think there is some similarity. Comments? If you will accept, I will send patch and changelog. Thanks, Sam Below is implementation, followed by unit test so you can see behaviour. # DNS names are hierarchical in a similar sense to ruby classes/modules, and the # comparison operators are defined si...

kinit: Cannot contact any KDC for requested realm while getting initial credentials
Hi, I am having problems with using kinit, with keytab and username/password. When issuing the kinit command I get the following error: kinit: Cannot contact any KDC for requested realm while getting initial credentials There is a firewall between the webservers where I issue the command from and the domain controller. The webservers are able to connect to the domain controller on port 88 over UDP. The webservers are able to resolve themselves and the domain controller, both forward and reverse lookup. Do any of you guys out there have an idea of what is going wrong? Many thanks, Celia ________________________________________________ Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos ...

I don't get why '>' doesn't get printed in the following example
When I do a here-document, the '>' character shows up to indicate the start of a newline. [cdalten@localhost ~]$ cat << EOF > My current directory is dir $PWD > EOF My current directory is dir /home/cdalten [cdalten@localhost ~]$ What prevents the '>' characters from showing up in the final output? On Jul 3, 10:35 am, Chad <cdal...@gmail.com> wrote: > When I do a here-document, the '>' character shows up to indicate the > start of a newline. > > [cdalten@localhost ~]$ cat << EOF> My current directory is dir $PWD > &...

permitted_enctypes = "des-cbc-crc" triggers 'kinit: Generic error (see e-text) while getting initial credentials'
I have this in my Suse 11.3 /etc/krb.conf for libdefaults: allow_weak_crypto = true # permitted_enctypes = "des-cbc-crc arcfour-hmac des3-cbc-sha1 aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha1-96" permitted_enctypes = "des-cbc-crc" Now if I try to kinit I get this error: kinit kinit: Generic error (see e-text) while getting initial credentials Why? Wendy ...

'^=' and '~='?
Hello, What is the difference between '^=' and '~='? Thanks, Duckhye ...

to get my ''PLP''
I tried to install the MATLAB in my computer but idon't have my personal license password.i would like how to get my PLP? buy it Hi, http://www.mathworks.com/support/solutions/data/1-16LU2.html J�r�me ...

get(get(gca,'Children'),'xdata')
hi everybody i use get and gca to find the points of a plot by below m-file : syms x y B=0.3;d=1;m1=0.5;m2=1-m1; u=x-m1*x/(x^2+y^2)-m2*(x-B*m1*x/(x^2+y^2)-d)/((x-B*m1*x/(x^2+y^2)-d)^2+(y-B*m1*y/(x^2+y^2))^2); v=y-m1*y/(x^2+y^2)-m2*(y-B*m1*y/(x^2+y^2))/((x-B*m1*x/(x^2+y^2)-d)^2+(y-B*m1*y/(x^2+y^2))^2); k11=diff(u,x); k12=diff(u,y); k21=diff(v,x); k22=diff(v,y); det=k11*k22-k12*k21; subplot(2,1,1); ezplot(det,[-2,2],[-2,2]); t=get(get(gca,'Children'),'xdata') my problem is this for some value of B (for example B=2) it give the xdata of plot in form of array [1,n] .it is ok u...

'static initialization' vs. 'dynamic initialization'
What are the definitions of 'static initialization' and 'dynamic initialization'? Does 'static initialization', mean "compile/link time rather than run time" whereas 'dynamic initialization' is the converse? Is 'dynamic initialization' mean everything that is initialized before main() is entered but after compile/link time? My confusion stems from the following excerpt from "The Design and Evolution of C++" (1994) by B. Stroustrup, pg. 96: "Such initialization cannot in general be done completely a compile time or at link time...

'''''''''''''The Running Update/Append Queries Using VBA code Ordeal''''''''''''''
Hello fellow programmers, I am trying to run an append/update query from code, a command button on a form initiates the queries. the format i am using is; _____________________________________________________ SELECT "criteria" FROM "criteria" WHERE "criteria" UPDATE/APPEND "field selections" RecordSource "qryExample" = above text strings" _______________________________________________________________________ When i am running a SELECT query in this manner it works fine with no problems, and accepts the values of specified linked for...

'''''''''''''The Running Update/Append Queries Using VBA code Ordeal'''''''''''''' #2
Hi, Thanks for ur help there HJ. I know how to do the tasks you specified there. I would like for the update query to use field values from some of the fields on the form (frmInvoices) such as InvoiceNumber, DateFrom, DateTo. My problem is that an append/update query can't find the values in the open Form (frmInvoices) when I specify them as; [Forms]![frmInvoices]![InvoiceNumber] a select query has no problem finding the field values on a form. please help. Aaron Hi Aaron, Could you post the entire code that you are having trouble with? Now it is not possible to see what goes wrong. HJ "Aaron" <aaron@rapid-motion.co.uk> wrote in message news:260d7f40.0408120245.2f3d01f8@posting.google.com... > Hi, > > Thanks for ur help there HJ. > > I know how to do the tasks you specified there. > > I would like for the update query to use field values from some of the > fields on the form (frmInvoices) such as InvoiceNumber, DateFrom, > DateTo. My problem is that an append/update query can't find the > values in the open Form (frmInvoices) when I specify them as; > > [Forms]![frmInvoices]![InvoiceNumber] > > a select query has no problem finding the field values on a form. > > please help. > > Aaron First off, if you are not always using all the parameters specified in your form, then you have to add parameters to your query on the fly. Also, you can't just do something like qdf.SQL = "SE...

if str_mo not in ('','.') and str_da not in ('','.') and str_yy not in ('','.') Any shorter ?
Hi, there. =20 I'm just curious if it ever dawned on anybody how to abbreviate this line : if str_mo not in ('','.') and str_da not in ('','.') and str_yy not in ('','.')=20 =20 Igor Kurbeko Clinical Programmer Analyst 678 336 4328 ikurbeko@atherogenics.com =20 no brain no pain =20 how about: if not (str_mo in ('','.') or str_da in ('','.') or str_yy in ('','.')) OR if not (missing(str_mo) or missing(str_da) or missing(str_yy)) Eric On 22 Oct 03 21:13:37 GMT, ikurbeko@ATHER...

How to browse all PropertyName for 'get' and 'set' function'?
hello all: Is there a way that I could browse all PropertyName for function 'get' and 'save'. For example: I want to know screen size then I use scrsz = get(0,'ScreenSize'); However, sometimes I don't know the correct propertyName(here is 'ScreenSize') for the function get or set. Thank you -Daniel Mark set(0) or h=handle(0); Then double click 'h' in workspace browser. Stuart "Daniel Mark" <danielmarkhot@Hotmail.com> wrote in message news:eee5db3.-1@webx.raydaftYaTP... > hello all: > > Is there a way that I could br...

Cannot contact any KDC for requested realm while getting initial credentials
Hi all, I'm having a very strange problem below that I cannot figure out. Any advice would be great to hear. First a block showing the problem, then a block showing that a different machine works perfectly fine (and others I've tested but not showing here for briefness). Basically, the master KDC, rcf-kdc1.foo.com, can't seem to do jack. ============================================================ rcf-kdc1# grep hosts /etc/nsswitch.conf hosts: files dns rcf-kdc1# rcf-kdc1# cat /etc/krb5.conf [libdefaults] default_realm = RCF.FOO.COM forwardable = yes ticket_lifetime = 7d [appdefaults] forwardable = yes [domain_realm] .foo.com = RCF.FOO.COM [realms] RCF.FOO.COM = { kdc = rcf-kdc1.foo.com kdc = rcf-kdc2.foo.com kdc = rcf-kdc3.foo.com admin_server = rcf-kdc1.foo.com } [logging] kdc = FILE:/var/adm/krb5kdc.log admin_server = FILE:/var/adm/kadmin.log default = FILE:/var/adm/krb5lib.log rcf-kdc1# uname -n rcf-kdc1.foo.com rcf-kdc1# nslookup rcf-kdc1.foo.com Server: 1xx.xx.xx.xxx Address: 1xx.xx.xx.xxx#53 Name: rcf-kdc1.foo.com Address: 1xx.xx.xx.yyy rcf-kdc1# kinit -p jblaine kinit(v5): Cannot contact any KDC for realm 'RCF.FOO.COM' while getting initial credentials rcf-kdc1# ps -ef | grep krb5kdc root 6837 1 0 13:21 ? 00:00:00 /var/rcf-kdc1-krb5/sbin/krb5kdc root 14166 2856 0 16:57 pts/0 00:00:00 grep krb5kdc...

A function with 'and' , 'not' , 'null' , 'car' and 'cdr'
What's this ? (defun enigma (x) (and (not (null x)) (or (null (car x)) (enigma (cdr x))))) "I suppose I should learn Lisp, but it seems so foreign." - Paul Graham, Nov 1983 On Wed, Oct 07 2015, CAI GENGYANG wrote: > What's this ? > > > (defun enigma (x) > (and (not (null x)) > (or (null (car x)) > (enigma (cdr x))))) Bad taste? It returns T if the list X contains nil as an element. It would be clearer to write (some #'null x). Helmut CAI GENGYANG ...

error: expected '=', ',', ';', 'asm' or '__attrib
Hi I'm trying to compile an ADC Driver & come acrosss the following error. I've no experience writing drivers before, and hence have no clue how to fix it. Hope someone out there has encountered the problem & suggesst a fix for the same. The Error is I get is : qadc.c: At top level: qadc.c:97: error: expected '=', ',', ';', 'asm' or '__attribute__' before 'qadc_read' make: *** [qadc.o] Error 1 [root@localhost qadc]# ########################################################################### ADC Driver Code ########################################################################### #define MODULE #define __KERNEL__ #include <linux/config.h> #include <linux/module.h> #include <linux/kernel.h> /* printk */ #include <linux/fs.h> / #include <linux/errno.h> /* error codes */ #include <linux/types.h> /* size_t */ #include <linux/proc_fs.h> /* proc file system */ #include <linux/fcntl.h> #include <asm/system.h> /* cli, flags */ #include <asm/uaccess.h> /* copy from/to user */ /*Registers to get qadc access*/ volatile unsigned short * qadcmcr = (unsigned short *)0x40190000; volatile unsigned short * qacr0 = (unsigned short *)0x4019000a; volatile unsigned short * qacr1 = (unsigned short *)0x4019000c; volatile unsigned short * qacr2 = (unsigned short *)0x4019000e; volatile unsigned short * qasr0 = (unsigned short *)0x40190010; volatile unsigned short * qasr1...

error: expected '=', ',', ';', 'asm' or '__attrib
Hi I'm trying to compile an ADC Driver & come acrosss the following error. I've no experience writing drivers before, and hence have no clue how to fix it. Hope someone out there has encountered the problem & suggesst a fix for the same. The Error is I get is : qadc.c: At top level: qadc.c:97: error: expected '=', ',', ';', 'asm' or '__attribute__' before 'qadc_read' make: *** [qadc.o] Error 1 [root@localhost qadc]# ########################################################################### ADC Driver Code ##...

Override 'and' and 'or'
Is it possible to override 'and' and/or 'or'? I cannot find a special method for it... __and__ and __rand__ and __or__ and __ror__ are for binary manipulation... any proposals? Have marvelous sunday, Marco Dekker <m.aschwanden@gmail.com> wrote: > Is it possible to override 'and' and/or 'or'? I cannot find a special > method for it... __and__ and __rand__ and __or__ and __ror__ are for > binary manipulation... any proposals? If you want to customize the truth value testing you have to implement __nonzero__ " __nonzero__( self) Call...

logical to 'on' / 'off'
Hi, is there a function implemented doing this conversion? my Problem is, that I want to use the following code: set(handles.edit_curr_trq_sl,'Enable',get(hObject,'Value')) where get(hObject,'Value') gives the state of a checkbox thank you! function [str]=tf2oo(logic) switch logic case 0 str='off'; case 1 str='on'; end%switch end%function tf2oo() while i do not know a built in function, I use my own:) meisterbartsch wrote: > > > function [str]=tf2oo(logic) > switch logic > case 0 > str='off'; &g...

'!' vs. '.'
Is there an advantage to using the '!' notation to represent form/ control relationships? (eg. Me!text1 vs Me.text1) I am currently using the '.' notation exclusively (for code completion in the VB Editor), but much of the high-quality code that I've seen (in Duane Hookom's Query-by-Form db, for example) uses the other. Here's one opinion for you: http://doc.advisor.com/doc/05352 robert.waters wrote: >Is there an advantage to using the '!' notation to represent form/ >control relationships? (eg. Me!text1 vs Me.text1) > >I am currently using the '.' notation exclusively (for code completion >in the VB Editor), but much of the high-quality code that I've seen >(in Duane Hookom's Query-by-Form db, for example) uses the other. -- HTH - RuralGuy (RG for short) acXP WinXP Pro Please post back to this forum so all may benefit. Message posted via AccessMonster.com http://www.accessmonster.com/Uwe/Forums.aspx/databases-ms-access/200704/1 Here's my $0.02 worth on this. I tend to copy the notation style and naming conventions that I see being used in the Help files. That would be Me![text1] for a control on a form. I am of the belief that this notation explicitly refers to a control itself rather than a field in the form's recordset. Here's an example: I have a parts inventory app that uses a "Line" code, which is usually a 3-character abbreviation for a brand name, and is the na...

Replacing ',' with '.'
Hello, I have a huge amount of numbers in a .txt file. The numbers are in the form 2,43252e+1. I need to replace the , with . How should I do this? I'd prefer some import method that does this during the import procedure. -Janne Hi, I guess you import the data as text and convert it then to numbers. Try 'strrep' before you convert the text to numbers. Tobias Jake the Snake schrieb: > Hello, > > I have a huge amount of numbers in a .txt file. The numbers are in the form 2,43252e+1. I need to replace the , with . How should I do this? I'd prefer some import method...

Diff between '{..}' and {'..'}
Hi, Could anyone tell me the difference between ......| awk '{.......}' AND ......| awk {'......'} And also when(in what situation) these are used? Thanks in advance, Anil. 2005-01-12, 22:37(-08), Anil: > Hi, > > Could anyone tell me the difference between > > .....| awk '{.......}' > > AND > > .....| awk {'......'} > > > And also when(in what situation) these are used? > Thanks in advance, [...] The second one should never be used. The difference is at the shell level, not at the awk level. '...' are stro...

'[OFF]' as in 'offensive'???
Hi, given that 'off-topicness' is indicated as '[OT]' and taking a look at those postings that started the threads indicated as '[OFF]' (which may both be seen as being somewhat offensive) may lead to the conclusion that '[OFF]' stands for offensiveness. I don't think that this is the intended meaning so what actually *does* '[OFF]' mean? I never came across that abbreviation before (although I have been around on the USENET for quite some time) but maybe it is worth knowing? Josef 'Jupp' Schugt NOTE: mails >100 KiB ...

Re: '^=' and '~='?
Duckhye, According to the doc ( http://xrl.us/befwjx ) they, and one other set of characters, and the mnemonic 'NE' all represent 'NOT EQUAL'. Art ------- On Wed, 11 Feb 2009 16:52:40 -0600, Duck-Hye Yang <dyang@CHAPINHALL.ORG> wrote: >Hello, >What is the difference between '^=' and '~='? > >Thanks, >Duckhye ...

replacement for '{' and '}' ?
I am still playing around with what kind of syntax I would like to mark up my documents. Are there equivalent long substitutes for { and } when they are not used to describe arguments to functions? Something like \begin{group} and \end{group}. In other words, if I could force myself to write, say, \begin{group} \it ... \end{group} instead of {\it ... }, then I believe I could identify from the markup context what is an argument that belongs to a just invoked macro and what is text. {Of course, in this context, \textit{...} would be better.} No more ambiguity whether a in \myfunction{a} i...

Web resources about - kinit: Cannot contact any KDC for realm 'EXAMPLE.COM' while getting initial credentials - comp.protocols.kerberos

Resources last updated: 3/10/2016 9:34:21 PM