and the authfile maps the realm to AFS-KRB authentication. When I test with radpwtst, I can see a KDC request go out to the right place (/etc/krb.conf has been set up), and a non-error KDC reply come back. The unencrypted part of the reply looks good, but radpwtst always reports an authentication failure. Trying MIT-KRB in place of AFS-KRB changes nothing. Any tips? __________________________________________________________________ Matt Crawford crawdad@fnal.gov Fermilab PGP: 0x566F63C5 - D5 27 83 7A 25 25 7D FB 09 3C BA 33 71 C4 DA 6A ++ Ascend Users Mailing List ++ To unsubscribe: send unsubscribe to ascend-users-request@bungi.com To get FAQ'd: <<A HREF="http://www.nealis.net/ascend/faq">http://www.nealis.net/ascend/faq</A>> </PRE> <!--X-MsgBody-End--> <!--X-Follow-Ups--> <!--X-Follow-Ups-End--> <!--X-References--> <!--X-References-End--> <!--X-BotPNI--> <HR> <UL> <LI>Prev by Date: <STRONG><A HREF="msg09762.html">Re: (ASCEND) NetWarp Pro and Linux</A></STRONG> </LI> <LI>Next by Date: <STRONG><A HREF="msg09761.html">(ASCEND) Generating Reports from Access Control</A></STRONG> </LI> <LI>Prev by thread: <STRONG><A HREF="msg09761.html">(ASCEND) Generating Reports from Access Control</A></STRONG> </LI> <LI>Next by thread: <STRONG><A HREF="msg09764.html">Re: (ASCEND) Ascend Access Control RADIUS <--> Kerberos</A></STRONG> </LI> <LI>Index(es): <UL> <LI><A HREF="mail11.html#09760"><STRONG>Main</STRONG></A></LI> <LI><A HREF="thrd206.html#09760"><STRONG>Thread</STRONG></A></LI> </UL> </LI> </UL> <!--X-BotPNI-End--> <!--X-User-Footer--> <!--X-User-Footer-End--> </BODY> </HTML>