#549934 openafs-krb5: aklog cross-realm authentication isn't working

Package:
openafs-krb5
Source:
openafs
Description:
AFS distributed filesystem Kerberos 5 integration
Submitter:
bai
Date:
2010-03-09 00:03:03 UTC
Severity:
normal
#549934#5
Date:
2009-10-06 13:31:55 UTC
From:
To:
This only gets a token for cell bai.adm.es.aau.dk (ThisCell):
auth     [default=done]          pam_afs_session.so
afs_cells=bai.adm.es.aau.dk,kuk.adm.es.aau.dk

This correctly gets tokens for both cells:
auth     [default=done]          pam_afs_session.so
afs_cells=bai.adm.es.aau.dk,kuk.adm.es.aau.dk program=/usr/bin/afslog

Using the afslog program from the command line also works, like here:

bai@krb5-server:~$ afslog --verbose -c bai.adm.es.aau.dk -c
kuk.adm.es.aau.dk
afslog: Getting tokens for cell "bai.adm.es.aau.dk"
krb5 tried afs@BAI.ADM.ES.AAU.DK -> 0
afslog: Getting tokens for cell "kuk.adm.es.aau.dk"
krb5 tried afs/kuk.adm.es.aau.dk@BAI.ADM.ES.AAU.DK -> -1765328377
krb5 tried afs@KUK.ADM.ES.AAU.DK -> 0

Using the aklog program from the command line fails, like here:

bai@krb5-server:~$ aklog -d -c kuk.adm.es.aau.dk -c bai.adm.es.aau.dk
Authenticating to cell kuk.adm.es.aau.dk (server
afsdb1.kuk.adm.es.aau.dk).
Trying to authenticate to user's realm BAI.ADM.ES.AAU.DK.
Getting tickets: afs/kuk.adm.es.aau.dk@BAI.ADM.ES.AAU.DK
We've deduced that we need to authenticate using referrals.
Getting tickets: afs/kuk.adm.es.aau.dk@
We've deduced that we need to authenticate to realm KUK.ADM.ES.AAU.DK.
Getting tickets: afs/kuk.adm.es.aau.dk@KUK.ADM.ES.AAU.DK
Getting tickets: afs@KUK.ADM.ES.AAU.DK
Kerberos error code returned by get_cred : -1765328377
aklog: Couldn't get kuk.adm.es.aau.dk AFS tickets:
aklog: unknown RPC error (-1765328377) while getting AFS tickets
Authenticating to cell bai.adm.es.aau.dk (server
krb5-afsdb1.bai.adm.es.aau.dk).
Trying to authenticate to user's realm BAI.ADM.ES.AAU.DK.
Getting tickets: afs/bai.adm.es.aau.dk@BAI.ADM.ES.AAU.DK
We've deduced that we need to authenticate using referrals.
Getting tickets: afs/bai.adm.es.aau.dk@
We've deduced that we need to authenticate to realm BAI.ADM.ES.AAU.DK.
Getting tickets: afs/bai.adm.es.aau.dk@BAI.ADM.ES.AAU.DK
Getting tickets: afs@BAI.ADM.ES.AAU.DK
Using Kerberos V5 ticket natively
Identical tokens already exist; skipping.

The CellServDB has entries for both cells:
krb5-server:~# head /etc/openafs/CellServDB
10.51.101.117		# krb5-afsdb1.bai.adm.es.aau.dk
10.51.101.128           # afsdb1.kuk.adm.es.aau.dk


It looks to me like the real problem might be somewhere in
the MIT kerberos libraries, and compiling against the heimdal
libraries would solve it?

#549934#10
Date:
2009-10-06 14:06:46 UTC
From:
To:
I just notoced that I forgot to empty the token cache before running the
aklog.

This is the result for aklog with an empty token cache:

bai@krb5-server:~$ aklog -d -c kuk.adm.es.aau.dk -c bai.adm.es.aau.dk
Authenticating to cell kuk.adm.es.aau.dk (server afsdb1.kuk.adm.es.aau.dk).
Trying to authenticate to user's realm BAI.ADM.ES.AAU.DK.
Getting tickets: afs/kuk.adm.es.aau.dk@BAI.ADM.ES.AAU.DK
We've deduced that we need to authenticate using referrals.
Getting tickets: afs/kuk.adm.es.aau.dk@
We've deduced that we need to authenticate to realm KUK.ADM.ES.AAU.DK.
Getting tickets: afs/kuk.adm.es.aau.dk@KUK.ADM.ES.AAU.DK
Getting tickets: afs@KUK.ADM.ES.AAU.DK
Kerberos error code returned by get_cred : -1765328377
aklog: Couldn't get kuk.adm.es.aau.dk AFS tickets:
aklog: unknown RPC error (-1765328377) while getting AFS tickets
Authenticating to cell bai.adm.es.aau.dk (server
krb5-afsdb1.bai.adm.es.aau.dk).
Trying to authenticate to user's realm BAI.ADM.ES.AAU.DK.
Getting tickets: afs/bai.adm.es.aau.dk@BAI.ADM.ES.AAU.DK
We've deduced that we need to authenticate using referrals.
Getting tickets: afs/bai.adm.es.aau.dk@
We've deduced that we need to authenticate to realm BAI.ADM.ES.AAU.DK.
Getting tickets: afs/bai.adm.es.aau.dk@BAI.ADM.ES.AAU.DK
Getting tickets: afs@BAI.ADM.ES.AAU.DK
Using Kerberos V5 ticket natively
About to resolve name bai to id in cell bai.adm.es.aau.dk.
Id 1000
Set username to AFS ID 1000
Setting tokens. AFS ID 1000 /  @ BAI.ADM.ES.AAU.DK

/Bo Bai

#549934#15
Date:
2009-10-13 01:23:37 UTC
From:
To:
retitle 549934 openafs-krb5: aklog cross-realm authentication isn't working
reassign 549934 openafs-krb5
thanks

bai <bai@kom.aau.dk> writes:

This indicates that the problem isn't due to libpam-afs-session.  Instead,
you're having a problem with the OpenAFS aklog program from openafs-krb5,
but the corresponding Heimdal afslog program is working.

windlord:~/tmp/OPENAFS> grep -- -1765328377 /usr/include/krb5/krb5.h
#define KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN          (-1765328377L)

So the OpenAFS aklog, which is using the MIT Kerberos libraries, is unable
to get cross-realm tickets from your local realm for the service afs in
the remote realm KUK.ADM.ES.AAU.DK.  This error message can mean that it
can't find the krbtgt/* principal for the cross-realm authentication.

Could you run the command:

    kvno afs@KUK.ADM.ES.AAU.DK

with your normal Kerberos tickets and see if it runs into the same
problem?  If so, the problem is either with your KDCs or with the Kerberos
libraries, not with aklog.  If kvno works and aklog doesn't, the problem
may be with aklog.

Could you also run a klist before and after running aklog, and before and
after running kvno?

#549934#28
Date:
2010-03-09 00:02:23 UTC
From:
To:
Russ Allbery <rra@debian.org> writes:

Hi there,

I don't think I got a reply to the above query.  Are you still having this
problem?  If so, could you give the above a try?