Hey everyone, I am trying to learn/setup a KRB5 domain in my home. But I am stuck on this one...
When I try to run kinit, this is what I get:
Code:
root@MediaServer:~$ kinit K/M@HQ
kinit: Clients credentials have been revoked while getting initial credentials
root@MediaServer:~$ kinit HQ
kinit: Client not found in Kerberos database while getting initial credentials
Here are my config files:
/etc/krb5.conf
Code:
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = HQ
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
forwardable = yes
[realms]
HQ = {
kdc = HQ.local:88
admin_server = HQ.local:749
default_domain = HQ.local
}
[domain_realm]
.local = HQ
local = HQ
[appdefaults]
pam = {
debug = false
ticket_lifetime = 36000
renew_lifetime = 36000
forwardable = true
krb4_convert = false
}
/etc/krb5kdc/kdc.conf
Code:
[kdcdefaults]
kdc_ports = 750,88
[realms]
HQ = {
database_name = /etc/krb5kdc/principal
admin_keytab = FILE:/etc/krb5kdc/kadm5.keytab
acl_file = /etc/krb5kdc/kadm5.acl
key_stash_file = /etc/krb5kdc/stash
kdc_ports = 750,88
max_life = 10h 0m 0s
max_renewable_life = 7d 0h 0m 0s
master_key_type = des3-hmac-sha1
supported_enctypes = aes256-cts:normal arcfour-hmac:normal des3-hmac-sha1:normal des-cbc-crc:normal des:normal des:v4 des:norealm des:onlyrealm des:afs3
default_principal_flags = +preauth
}
/etc/hosts
Code:
192.168.20.5 MediaServer # Added by NetworkManager
127.0.0.1 localhost.localdomain localhost
::1 MediaServer localhost6.localdomain6 localhost6
192.168.20.5 HQ HQ.HQ HQ.Local
# The following lines are desirable for IPv6 capable hosts
::1 localhost ip6-localhost ip6-loopback
fe00::0 ip6-localnet
ff00::0 ip6-mcastprefix
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
ff02::3 ip6-allhosts
Now, I have been goofing with this thing, and these are my most current configs. So these config files may have some uneeded junk in them...
Any help would be appreciated! And I am very interested in learning the details, so feel free to educate me.
I have looked around a LOT and tried a lot of things, but nothing has worked.