Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

(null cookie; hope that's ok)


devel / comp.protocols.kerberos / Re: How to view KVNO on slave

SubjectAuthor
o Re: How to view KVNO on slaveRuss Allbery

1
Re: How to view KVNO on slave

<mailman.2.1696696037.2263420.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=378&group=comp.protocols.kerberos#378

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: eag...@eyrie.org (Russ Allbery)
Newsgroups: comp.protocols.kerberos
Subject: Re: How to view KVNO on slave
Date: Sat, 07 Oct 2023 09:27:00 -0700
Organization: The Eyrie
Lines: 22
Message-ID: <mailman.2.1696696037.2263420.kerberos@mit.edu>
References: <ZSEweGP8vOXerlCH@lightning.iz.norgie.net>
<87wmvyv1nv.fsf@hope.eyrie.org>
Mime-Version: 1.0
Content-Type: text/plain
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="15197"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Gnus/5.13 (Gnus v5.13)
To: Mike via Kerberos <kerberos@mit.edu>
Authentication-Results: mit.edu;
dmarc=none (p=none dis=none) header.from=eyrie.org
Authentication-Results: mit.edu; arc=pass smtp.remote-ip=18.9.3.18
ARC-Seal: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1696696032; cv=pass;
b=yFvEoXEcppSccJoCrAln806EWll1M4cESQ+ohjGC1BVem1PUgL1TlStrEE62CXSNxTpR6HaVhLZbP3TIn//1ogy7yc6PYEtp7poAOaFhpRgJAtqpeF+3MMQXpkduiXaNDr1sWcPonrfvXfuvErCUqZZJ+ZLHpvy4kUzzOe9Ar/nHHx37rBvhrWmC4zlx80/Js2y1gTVOycRbMSSxHxlRQbKk74UQ10AVurlh5uwkcYAppVUsPolGYs8k8BPDx/ODK8DKZgQfJugjBIzaCzo0PxiABtfpXOSjn5Ig7sWCtLpfhaI0ERDPUIR4sKbi5mdLotiRdqARPKt4ExE1QIFnjQ==
ARC-Message-Signature: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1696696032;
c=relaxed/relaxed; bh=YiKEM4AiqSguaPgkMdAUux0XILUo2z1WG1BXTanFUV4=;
h=From:Subject:Date:Message-ID:MIME-Version:Content-Type;
b=ihC6VBCJBoGS5quFUZzk6kafRtjRt4QsQHhGkd7DnFyQDcpigb9imIRCuXv7joyeKsCvr7tteGVLSt/qPmhxFQRRPPmzgqrvq+7gKAxjir6THqCS3/npvbJtJmc8K31jeOx8dI1eX0BoUz1WbAVhiL6cfpZIzg+hxxOM310k4Wx6kzBzo11z3wrLb/SlsZhHd+UBQLvzJp5TQ3SO39o31V14bA0hekabFrienCpfVxQjY4N4GDn5rcqN2oFeggg3alBoXHTzr6PE2VN7dUFrOYI3jfAVAwI5z1xyDyCn/jivSTGgQX60FB6MaAyMObrsvud9DL429CnIYTEJ/Zplpg==
ARC-Authentication-Results: i=2; mit.edu; dkim=pass (1024-bit key;
unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=lV2vqw8U
Authentication-Results: mit.edu; dkim=pass (1024-bit key;
unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=lV2vqw8U
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=Dfup5lP+qPVycHnDfSGZE1gmeIS8UQ01cbWgxdwD9TyuRn9XdZw0cZRZtSWh1pgCZO77km2eHGUI08YG77l4LMfF2QJwFMyV+bb7E6XN6+Qtp2RG7/GpPG0DN0YQDnVevkzHVc6AQxxNjdzhO0FD1t09xVno48rw0+4nnZjuMrrIw2LEB4Rz8fpkEojmwPmBfFxAv0IbIN24rlMNfkjKR16X0QQkpBVOxW//1LSZm363JYrXXGWmTIJq4nOSBbaKNqMKkDXCP+UlZWTbxZnDFa+aYRcMs0ThbTd81lPfe30fwFADk7YZbemM6pne+iNVnQX7Btm/fL5lABIPPKYFTA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=YiKEM4AiqSguaPgkMdAUux0XILUo2z1WG1BXTanFUV4=;
b=h89UsO8ID6o1pWn35QUjGjl/BCYuib3GezaWvHu/3GDRasHajjBIwg8z6Dj2TjHGuxAVgrszMd+WdKI83+ZGZSfjpuI0uWTGcNNLArA0hyKPniZ3+B+1pa627oyYjkDvVQk0BbPzKjDts3kXEpgFTKLvJj3ATjcz4LOGf81uNy1damNL2uDG1yf0Dm9FHI8MqurlsKFMBw4sbon6fhwGwhQiH2uBW0Sw7WCwFIswHKKqjzCG0+hT3dMGjkHN+nEij2gFpv8VdNE0ZkWOM+OemsR8QNyWT/e94G3SJnSFAKgylQCu5GYtth9viy553dJZSYpPHoPCjszffBRy6c16NA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
166.84.7.159) smtp.rcpttodomain=mit.edu smtp.mailfrom=eyrie.org;
dmarc=bestguesspass action=none header.from=eyrie.org; dkim=none (message not
signed); arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=YiKEM4AiqSguaPgkMdAUux0XILUo2z1WG1BXTanFUV4=;
b=lV2vqw8URp46ucHrJA1oANIojZGY17VinE98Nv7yaglcar28WVl4039FhU0e0AB86hrS+agqHsNWeLxjG4Asb5ni4NeNkEh5b4ucYXNj/S1Sm1C3G1CuPN1zRq54KMveFfVqKYhXY35oR+JPRu8nAlVAndrFmOb9BNNswYOB9Jc=
Authentication-Results: spf=pass (sender IP is 166.84.7.159)
smtp.mailfrom=eyrie.org; dkim=none (message not signed)
header.d=none;dmarc=bestguesspass action=none header.from=eyrie.org;
Received-SPF: Pass (protection.outlook.com: domain of eyrie.org designates
166.84.7.159 as permitted sender) receiver=protection.outlook.com;
client-ip=166.84.7.159; helo=haven.eyrie.org; pr=C
In-Reply-To: <ZSEweGP8vOXerlCH@lightning.iz.norgie.net> (Mike via Kerberos's
message of "Sat, 7 Oct 2023 11:18:32 +0100")
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: CO1PEPF000044F9:EE_|CH0PR01MB7077:EE_
X-MS-Office365-Filtering-Correlation-Id: a2666445-6a39-466d-2adf-08dbc7523e18
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: O75ZXV0SJOX0rzcbBLPzHhbUQ/xMipo1Rfh3OZRygR8lngp3tUmzhwHrGaJMZTJ8Nrp5ykXWvNKK6ww//UvqTzcBbmZtpbp9XLfRdWHQIr5zPDHryCeuveOHZH+BTnJG+6Yt09/tbCm8bwiXveq4WX7JSahddCYzQAyocFbTjdFMXLSR2tK/hOEYe5EHWexABTZWUuFsP2DaYDaUwXFGTwfa2kCNB6w/P2t+JN5G/87W44+8C/kNwVtMkR1kRU+NnEkQkSJszMaFAkri+j0Z0qib9r7cqP14BTa5BuGc9DaZ4pYKPRIwqpsk7vOEP2lzmIim8xX42E9E/3+/0pJbU0E1nOEylVjk9DfBgo9tDBSk444EcYOdWOj5X8YTC2Y4EdLzSljionbPJMru0YnI/d7y8tekquEMfVLkslZanHxiEzVaBPChX1l4VSCoBWlkkf73YgHUkIc0VqKwjg2Axv/tFLzuL4Yl2FqnbM3llMD4wwD/L9kNvvNl4w/VXBu1Qji3AKuNnszUr0wyQloNZzq++hJ1F057EqHc35wHrN4nuZOx1hX90H159MvukXqnwtcf/mhvvIQ0eUxshrqxc/ybXVEmd0GLfRK3xI4gDbzN3mjatBthca/eeutw6tjwYOSAZpXYUQgl5wNDQkZi7g==
X-Forefront-Antispam-Report: CIP:166.84.7.159; CTRY:; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:haven.eyrie.org; PTR:haven.eyrie.org; CAT:NONE;
SFS:(13230031)(4636009)(376002)(346002)(396003)(136003)(39860400002)(451199024)(61400799006)(48200799006)(64100799003)(356005)(7596003)(7636003)(5660300002)(4326008)(8676002)(6862004)(86362001)(2906002)(36916002)(83380400001)(426003)(26005)(336012)(107886003)(6266002)(42186006)(68406010)(70586007)(498600001)(786003)(316002);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 07 Oct 2023 16:27:04.3730 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: a2666445-6a39-466d-2adf-08dbc7523e18
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: CO1PEPF000044F9.namprd21.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CH0PR01MB7077
X-OriginatorOrg: mitprod.onmicrosoft.com
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <87wmvyv1nv.fsf@hope.eyrie.org>
X-Mailman-Original-References: <ZSEweGP8vOXerlCH@lightning.iz.norgie.net>
 by: Russ Allbery - Sat, 7 Oct 2023 16:27 UTC

Mike via Kerberos <kerberos@mit.edu> writes:

> I'm surmising that the issue might be that the service principle may not
> have replicated corerctly to the slave server, which is used by the
> Apache host. I can see the ticket details on the master using
> kadmin.local and getprinc and I can see the keytab info using ktutil.
> My question is this: How does one view the KVNO in the Slave DB? I
> imaine it's probably available via kdb5_util dump but unfortunatly I
> have not found any documents explaining the fields in the dump.

You can use kadmin.local on the slave the same way that you use it on the
master, I'm fairly sure. It's been a while since I've done this, but I'm
pretty sure the database is the same and the tool doesn't have any idea
whether you're running it on a master or a slave.

I would expect you to get replication errors if there was a replication
problem. If you're only doing incremental replication and you think
something may have gone wrong, you can always do a full replication, which
guarantees that the slave is identical to the master.

--
Russ Allbery (eagle@eyrie.org) <https://www.eyrie.org/~eagle/>

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor