From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ken Bass Subject: krb5 issues Date: Mon, 23 May 2016 11:21:53 -0400 Message-ID: <57432011.1060201@kenbass.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; Format="flowed" Content-Transfer-Encoding: 7bit Return-path: Received: from mx1.redhat.com (ext-mx03.extmail.prod.ext.phx2.redhat.com [10.5.110.27]) by int-mx14.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id u4NFLu8h028139 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for ; Mon, 23 May 2016 11:21:56 -0400 Received: from mail.kenbass.com (kenbass.com [216.127.139.130]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 7C7D27D0C8 for ; Mon, 23 May 2016 15:21:55 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail.kenbass.com (Postfix) with ESMTP id 75CBE3C4 for ; Mon, 23 May 2016 11:21:54 -0400 (EDT) Received: from mail.kenbass.com ([127.0.0.1]) by localhost (mail.kenbass.com [127.0.0.1]) (amavisd-new, port 10026) with LMTP id dK91iF2kWWfg for ; Mon, 23 May 2016 11:21:54 -0400 (EDT) List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com Hello, I enabled krb5 in my audisp-remote and audispd-remote reports "GSS-API error sending token length" and fails to log remotely. If I reboot the destination auditd server AFTER the clients are running it appears to work. But if I reboot any clients machine, logging from that rebooted machine fails. I created my service principals using freeipa - all systems are clean installs of Centos 7.2. For now, I disabled krb5, but that is not a good solution. Thank you, Ken