Re: Packagers - Flag day 2016 Important changes

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 2016-12-12 00:34, Dennis Gilmore wrote:
Greetings. 

As previously announced, releng has made a number of changes as part of
it's 2016 "flag day". 

All package maintainers will want to make sure they have updated to
the 
following package versions (some may be in testing as of this email):

     python-cccolutils-1.4-1
     fedpkg-1.26-2
     fedora-packager-0.6.0.0-1
     pyrpkg-1.47-3
     koji-1.11.0-1

Please also see the following links for up to date information: 

https://fedoraproject.org/wiki/ReleaseEngineering/FlagDay2016

The following changes were made:

* koji and the source lookaside were changed to use kerberos
authentication
instead of ssl certificates. All maintainers will need to:

kinit YOUR-FAS-ACCOUNTNAME@xxxxxxxxxxxxxxxxxx

There's an extra "A" in there.

Anyway, it's not working for me and it's a different error than others are seeing:

$ KRB5_TRACE=/dev/stdout kinit pghmcfc@xxxxxxxxxxxxxxxxx
[27827] 1481545109.731971: Getting initial credentials for pghmcfc@xxxxxxxxxxxxxxxxx [27827] 1481545109.732034: Sending request (198 bytes) to FEDORAPROJECT.ORG
[27827] 1481545109.732115: Resolving hostname id.fedoraproject.org
[27827] 1481545109.822525: TLS certificate name matched "id.fedoraproject.org" [27827] 1481545109.854766: Sending HTTPS request to https 2001:4178:2:1269::fed2:443 [27827] 1481545110.569521: Received answer (192 bytes) from https 2001:4178:2:1269::fed2:443 [27827] 1481545110.569530: Terminating TCP connection to https 2001:4178:2:1269::fed2:443
[27827] 1481545110.570113: Response was not from master KDC
[27827] 1481545110.570138: Received error from KDC: -1765328361/Password has expired
[27827] 1481545110.570145: Retrying AS request with master KDC
[27827] 1481545110.570148: Getting initial credentials for pghmcfc@xxxxxxxxxxxxxxxxx [27827] 1481545110.570190: Sending request (198 bytes) to FEDORAPROJECT.ORG (master)
[27827] 1481545110.570781: Principal expired; getting changepw ticket
[27827] 1481545110.570788: Getting initial credentials for pghmcfc@xxxxxxxxxxxxxxxxx [27827] 1481545110.570807: Setting initial creds service to kadmin/changepw [27827] 1481545110.570821: Sending request (170 bytes) to FEDORAPROJECT.ORG
[27827] 1481545110.570832: Resolving hostname id.fedoraproject.org
[27827] 1481545110.664742: TLS certificate name matched "id.fedoraproject.org" [27827] 1481545110.697029: Sending HTTPS request to https 2001:4178:2:1269::fed2:443 [27827] 1481545111.424567: Received answer (265 bytes) from https 2001:4178:2:1269::fed2:443 [27827] 1481545111.424576: Terminating TCP connection to https 2001:4178:2:1269::fed2:443
[27827] 1481545111.425176: Response was not from master KDC
[27827] 1481545111.425191: Received error from KDC: -1765328359/Additional pre-authentication required
[27827] 1481545111.425237: Processing preauth types: 136, 19, 2, 133
[27827] 1481545111.425240: Selected etype info: etype aes256-cts, salt "-8?z9]S;Kc ?!en@", params ""
[27827] 1481545111.425243: Received cookie: MIT
Password for pghmcfc@xxxxxxxxxxxxxxxxx:
[27827] 1481545118.11305: AS key obtained for encrypted timestamp: aes256-cts/08C0 [27827] 1481545118.11332: Encrypted timestamp (for 1481545117.893053): plain 301AA011180F32303136313231323132313833375AA105020 30DA07D, encrypted E16FD65250AA2EFF0BD08D498BC6BA6B914C548CB3D4CC87581D4DF6BAC457734C5B918FE2ED255C4408112F35118B7752C9A95C3EF
BDC70
[27827] 1481545118.11343: Preauth module encrypted_timestamp (2) (real) returned: 0/Success
[27827] 1481545118.11345: Produced preauth for next request: 133, 2
[27827] 1481545118.11357: Sending request (265 bytes) to FEDORAPROJECT.ORG
[27827] 1481545118.11380: Resolving hostname id.fedoraproject.org
[27827] 1481545118.103859: TLS certificate name matched "id.fedoraproject.org" [27827] 1481545118.136932: Sending HTTPS request to https 2001:4178:2:1269::fed2:443 [27827] 1481545118.895882: Received answer (748 bytes) from https 2001:4178:2:1269::fed2:443 [27827] 1481545118.895890: Terminating TCP connection to https 2001:4178:2:1269::fed2:443
[27827] 1481545118.896445: Response was not from master KDC
[27827] 1481545118.896469: Processing preauth types: 19
[27827] 1481545118.896474: Selected etype info: etype aes256-cts, salt "-8?z9]S;Kc ?!en@", params ""
[27827] 1481545118.896478: Produced preauth for next request: (empty)
[27827] 1481545118.896483: AS key determined by preauth: aes256-cts/08C0
[27827] 1481545118.896501: Decrypted AS reply; session key is: aes256-cts/0DA7
[27827] 1481545118.896507: FAST negotiation: available
[27827] 1481545118.896523: Attempting password change; 3 tries remaining
Password expired.  You must change it now.
Enter new password:
Enter it again:
[27827] 1481545129.754725: Creating authenticator for pghmcfc@xxxxxxxxxxxxxxxxx -> kadmin/changepw@xxxxxxxxxxxxxxxxx, seqnum 0
, subkey aes256-cts/D9E0, session key aes256-cts/0DA7
kinit: Cannot find KDC for realm "FEDORAPROJECT.ORG" while getting initial credentials
$

I tried logging into FAS and that worked but didn't help. It didn't prompt me to change password either. I don't know if the "password expired" thing is the source or a symptom of the problem.

Paul.
_______________________________________________
devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux