Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Kerberos Replication

Status
Not open for further replies.

bdw238

MIS
Dec 15, 2005
52
0
0
GB
When trying to replication the master krb database, the following occurs:

[halo]: /usr/krb5/sbin # ./config.krb5 -P -r VENTURA-UK.COM -d ventura-uk.com>
Creating host/halo.ventura-uk.com@VENTURA-UK.COM...
Principal "host/halo.ventura-uk.com@VENTURA-UK.COM" created.
Creating /etc/krb5/krb5.keytab...
Creating a dump of the database...
Propagating the database to the slave KDC, seahawk ...
Unable to send database block starting at 0.
Status 0x20 - There is no process to read data written to a pipe..
/usr/krb5/sbin/kprop unsuccessful, cleaning and exiting.
The command completed with errors.

Does anyone know what causes the above error message in Aix 5.3 krb5.server.rte environment?

The debug output from kpropd on the secondary server is:


[seahawk]: /usr/krb5/sbin # ./kpropd -S -d
Connection from halo.ventura-uk.com
krb5_recvauth(4, kprop5_01, host/seahawk.ventura-uk.com@VENTURA-UK.COM, ...)
authenticated client: host/halo@VENTURA-UK.COM (etype == Triple DES cbc mode with HMAC/sha1)
 
Hello all,

Solved this issue.

The problem is caused by configuration scripts not inserting a correct principle definition of the master server in the kpropd.acl.

e.g

Kerberos Database contains:

host/testserver@REALM

Configuration script inserts:

host/testserver.dnsdomain@REALM

Regards

Brian
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top