Windows 2008 AD 커버러스 서버와 Solaris10 커버러스 클라이언트에서 티켓을 받으려고 하는데
윈도우 2008 서버에서 ktpass 명령어시 문제가 발생합니다. ㅡㅡ;; 솔라리스 싸이트 이지만 1덜 넘게 해봐도 되질 않내요.
C:\Users\Administrator.ACTIVEDS.002>ktpass -princ cometo100/cometo100.com10@COEM
TO10.COM -mapuser cometo100 -pass cometo7 -out c:\krb5.keytab
DsCrackNames returned 0x2 in the name entry for cometo100.
ktpass:failed getting target domain for specified user.
메뉴얼을 보니
Note The following error is printed by ktpass if the named host principal does not exist in Active
Directory or if an incorrect principal name is specified:
DsCrackNames returned 0x2 in the name entry for host_hostname
-princ : host/사용자이름@dns이름을 대문자로
-mapuser : clientname(cometo100)
으로 알고 있습니다. 혹시 -princ 옵션 부분이 잘못된 부분이 있는건지 알고 싶습니다.
Windows 2008 커버러스 서버
전체 컴퓨터 이름 ActiveDS.cometo10.com
도메인 : cometo10.com
ip : 192.168.0.33
SOLARIS 10
# ifconfig -a
lo0: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu 8232 index 1
inet 127.0.0.1 netmask ff000000
e1000g0: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 2
inet 192.168.0.100 netmask ffffff00 broadcast 192.168.0.255
ether 8:0:27:bb:75:9a
# cat /etc/resolv.conf
nameserver 192.168.0.33
# cat /etc/krb5/krb5.conf
[libdefaults]
default_realm = COMETO10.COM
default_checksum = rsa-md5
[realms]
COMETO10.COM = {
kdc = cometo10.com
kpasswd_server = cometo10.com
kpasswd_protocol = SET_CHANGE
admin_server = cometo10.com
}
[domain_realm]
.cometo10.com = COMETO10.COM
cometo10.com = COMETO10.COM
[logging]
default = FILE:/var/krb5/kdc.log
kdc = FILE:/var/krb5/kdc.log
# ifconfig -a
lo0: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu 8232 index 1
inet 127.0.0.1 netmask ff000000
e1000g0: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 2
inet 192.168.0.100 netmask ffffff00 broadcast 192.168.0.255
ether 8:0:27:bb:75:9a
# cat /etc/hosts
#
# Internet host table
#
127.0.0.1 localhost
::1 localhost
192.168.0.100 cometo100.cometo10.com cometo100 loghost
#
# cat /etc/resolv.conf
nameserver 192.168.0.33
# # cat /etc/resolv.conf
nameserver 192.168.0.33
# nameserver: 없음
# vi ntp.conf
# ident "@(#)ntp.client 1.3 00/07/17 SMI"
#
# /etc/inet/ntp.client
#
# An example file that could be copied over to /etc/inet/ntp.conf; it
# provides a configuration for a host that passively waits for a server
# to provide NTP packets on the ntp multicast net.
#
#multicastclient 224.0.1.1
server 192.168.0.33
# svcs -a |grep ntp
disabled 17:41:56 svc:/network/ntp4:default
online 17:42:16 svc:/network/ntp:default
# ntpq -p
remote refid st t when poll reach delay offset disp
==============================================================================
192.168.0.33 .LOCL. 1 - 21h 64 0 1.92 -396.03 16000.0
# nslookup cometo10.com
Server: 192.168.0.33
Address: 192.168.0.33#53
Name: cometo10.com
Address: 192.168.0.33