I'm having difficulty integrating Solaris 11 machines, into an existing working kerberos infrastructure.
Technically, I think it is an "mit" kerberos master server and slaves.
The interesting point is, copying over the krb5.conf from our solaris 10 machines, I CAN do kinit, either as a regular user, or as the "admin" user.
However, I cannot do "kadmin -p (adminuser)".
how does kadmin fail when kinit works?
Similarly, I try using kclient.
but it fails with
KDC is unreachable, exiting.
---------------------------------------------------
Setup FAILED.
According to snoop, it seems to be doing some kind of DNS lookups.
It does a lookup for a slave, but then decides to go try looking for
KDC.our.domain. which does not exist.
Our kerberos slaves are referenced by CNAME. is that a problem?
Any ideas would be appreciated.
I would also appreciate seeing the functional pam.conf entries that kclient creates on success.
|
|
0
|
|
|
|
Reply
|
phil178 (85)
|
6/15/2012 6:33:54 PM |
|