#9978 Kerberos authentication of fedpkg not working for me on el7
Closed: Fixed by dwd. Opened by dwd.

Describe what you would like us to do:

Help me figure out why kerberos authentication isn't working in fedpkg on el7. Here's a trace:
$ KRB5_TRACE=/dev/stdout fedpkg build
[12581] 1621976845.25360: ccselect can't find appropriate cache for server principal HTTP/proxy-iad02.fedoraproject.org@
[12581] 1621976845.25361: Getting credentials dwd@FEDORAPROJECT.ORG -> HTTP/proxy-iad02.fedoraproject.org@ using ccache DIR::/run/user/3382/krb5cc/tktfwZFAl
[12581] 1621976845.25362: Retrieving dwd@FEDORAPROJECT.ORG -> HTTP/proxy-iad02.fedoraproject.org@ from DIR::/run/user/3382/krb5cc/tktfwZFAl with result: -1765328243/Matching credential not found (filename: /run/user/3382/krb5cc/tktfwZFAl)
[12581] 1621976845.25363: Retrying dwd@FEDORAPROJECT.ORG -> HTTP/proxy-iad02.fedoraproject.org@FEDORAPROJECT.ORG with result: -1765328243/Matching credential not found (filename: /run/user/3382/krb5cc/tktfwZFAl)
[12581] 1621976845.25364: Server has referral realm; starting with HTTP/proxy-iad02.fedoraproject.org@FEDORAPROJECT.ORG
[12581] 1621976845.25365: Retrieving dwd@FEDORAPROJECT.ORG -> krbtgt/FEDORAPROJECT.ORG@FEDORAPROJECT.ORG from DIR::/run/user/3382/krb5cc/tktfwZFAl with result: 0/Success
[12581] 1621976845.25366: Starting with TGT for client realm: dwd@FEDORAPROJECT.ORG -> krbtgt/FEDORAPROJECT.ORG@FEDORAPROJECT.ORG
[12581] 1621976845.25367: Requesting tickets for HTTP/proxy-iad02.fedoraproject.org@FEDORAPROJECT.ORG, referrals on
[12581] 1621976845.25368: Generated subkey for TGS request: aes256-cts/FDF1
[12581] 1621976845.25369: etypes requested in TGS request: aes256-cts, aes128-cts
[12581] 1621976845.25371: Encoding request body and padata into FAST request
[12581] 1621976845.25372: Sending request (971 bytes) to FEDORAPROJECT.ORG
[12581] 1621976845.25373: Resolving hostname id.fedoraproject.org
[12581] 1621976845.25374: TLS certificate name matched "id.fedoraproject.org"
[12581] 1621976845.25375: Sending HTTPS request to https 152.19.134.198:443
[12581] 1621976845.25376: Received answer (472 bytes) from https 152.19.134.198:443
[12581] 1621976845.25377: Terminating TCP connection to https 152.19.134.198:443
[12581] 1621976845.25378: Response was from master KDC
[12581] 1621976845.25379: Decoding FAST response
[12581] 1621976845.25380: TGS request result: -1765328377/Server HTTP/proxy-iad02.fedoraproject.org@FEDORAPROJECT.ORG not found in Kerberos database
[12581] 1621976845.25381: TXT record _kerberos.proxy-iad02.fedoraproject.org. not found
[12581] 1621976845.25382: TXT record _kerberos.fedoraproject.org. found: FEDORAPROJECT.ORG
[12581] 1621976845.25383: Requesting tickets for HTTP/proxy-iad02.fedoraproject.org@FEDORAPROJECT.ORG, referrals off
[12581] 1621976845.25384: Generated subkey for TGS request: aes256-cts/2B80
[12581] 1621976845.25385: etypes requested in TGS request: aes256-cts, aes128-cts
[12581] 1621976845.25387: Encoding request body and padata into FAST request
[12581] 1621976845.25388: Sending request (971 bytes) to FEDORAPROJECT.ORG
[12581] 1621976845.25389: Resolving hostname id.fedoraproject.org
[12581] 1621976845.25390: TLS certificate name matched "id.fedoraproject.org"
[12581] 1621976845.25391: Sending HTTPS request to https 38.145.60.20:443
[12581] 1621976845.25392: Received answer (472 bytes) from https 38.145.60.20:443
[12581] 1621976845.25393: Terminating TCP connection to https 38.145.60.20:443
[12581] 1621976845.25394: Response was from master KDC
[12581] 1621976845.25395: Decoding FAST response
[12581] 1621976845.25396: TGS request result: -1765328377/Server HTTP/proxy-iad02.fedoraproject.org@FEDORAPROJECT.ORG not found in Kerberos database
[12581] 1621976845.25402: ccselect can't find appropriate cache for server principal HTTP/proxy-iad01.fedoraproject.org@
[12581] 1621976845.25403: Getting credentials dwd@FEDORAPROJECT.ORG -> HTTP/proxy-iad01.fedoraproject.org@ using ccache DIR::/run/user/3382/krb5cc/tktfwZFAl
[12581] 1621976845.25404: Retrieving dwd@FEDORAPROJECT.ORG -> HTTP/proxy-iad01.fedoraproject.org@ from DIR::/run/user/3382/krb5cc/tktfwZFAl with result: -1765328243/Matching credential not found (filename: /run/user/3382/krb5cc/tktfwZFAl)
[12581] 1621976845.25405: Retrying dwd@FEDORAPROJECT.ORG -> HTTP/proxy-iad01.fedoraproject.org@FEDORAPROJECT.ORG with result: -1765328243/Matching credential not found (filename: /run/user/3382/krb5cc/tktfwZFAl)
[12581] 1621976845.25406: Server has referral realm; starting with HTTP/proxy-iad01.fedoraproject.org@FEDORAPROJECT.ORG
[12581] 1621976845.25407: Retrieving dwd@FEDORAPROJECT.ORG -> krbtgt/FEDORAPROJECT.ORG@FEDORAPROJECT.ORG from DIR::/run/user/3382/krb5cc/tktfwZFAl with result: 0/Success
[12581] 1621976845.25408: Starting with TGT for client realm: dwd@FEDORAPROJECT.ORG -> krbtgt/FEDORAPROJECT.ORG@FEDORAPROJECT.ORG
[12581] 1621976845.25409: Requesting tickets for HTTP/proxy-iad01.fedoraproject.org@FEDORAPROJECT.ORG, referrals on
[12581] 1621976845.25410: Generated subkey for TGS request: aes256-cts/8FC8
[12581] 1621976845.25411: etypes requested in TGS request: aes256-cts, aes128-cts
[12581] 1621976845.25413: Encoding request body and padata into FAST request
[12581] 1621976845.25414: Sending request (971 bytes) to FEDORAPROJECT.ORG
[12581] 1621976845.25415: Resolving hostname id.fedoraproject.org
[12581] 1621976845.25416: TLS certificate name matched "id.fedoraproject.org"
[12581] 1621976846.65431: Sending HTTPS request to https 140.211.169.206:443
[12581] 1621976846.65432: TLS certificate name matched "id.fedoraproject.org"
[12581] 1621976846.65433: Sending HTTPS request to https 209.132.190.2:443
[12581] 1621976847.205964: Received answer (472 bytes) from https 209.132.190.2:443
[12581] 1621976847.205965: Terminating TCP connection to https 140.211.169.206:443
[12581] 1621976847.205966: Terminating TCP connection to https 209.132.190.2:443
[12581] 1621976847.205967: Response was from master KDC
[12581] 1621976847.205968: Decoding FAST response
[12581] 1621976847.205969: TGS request result: -1765328377/Server HTTP/proxy-iad01.fedoraproject.org@FEDORAPROJECT.ORG not found in Kerberos database
[12581] 1621976847.205970: TXT record _kerberos.proxy-iad01.fedoraproject.org. not found
[12581] 1621976847.205971: TXT record _kerberos.fedoraproject.org. found: FEDORAPROJECT.ORG
[12581] 1621976847.205972: Requesting tickets for HTTP/proxy-iad01.fedoraproject.org@FEDORAPROJECT.ORG, referrals off
[12581] 1621976847.205973: Generated subkey for TGS request: aes256-cts/7940
[12581] 1621976847.205974: etypes requested in TGS request: aes256-cts, aes128-cts
[12581] 1621976847.205976: Encoding request body and padata into FAST request
[12581] 1621976847.205977: Sending request (972 bytes) to FEDORAPROJECT.ORG
[12581] 1621976847.205978: Resolving hostname id.fedoraproject.org
[12581] 1621976847.205979: TLS certificate name matched "id.fedoraproject.org"
[12581] 1621976847.205980: Sending HTTPS request to https 209.132.190.2:443
[12581] 1621976847.205981: Received answer (472 bytes) from https 209.132.190.2:443
[12581] 1621976847.205982: Terminating TCP connection to https 209.132.190.2:443
[12581] 1621976847.205983: Response was from master KDC
[12581] 1621976847.205984: Decoding FAST response
[12581] 1621976847.205985: TGS request result: -1765328377/Server HTTP/proxy-iad01.fedoraproject.org@FEDORAPROJECT.ORG not found in Kerberos database
Kerberos authentication fails: unable to obtain a session
Could not execute build: Could not login to https://koji.fedoraproject.org/kojihub

When do you need this to be done by? (YYYY/MM/DD)

I don't have a particular date because I'm working around it by running fedpkg on a separate el8 VM.


Check /etc/krb5.conf and make sure you have: "rdns = false"

That's it, thanks. Darn, this has happened to me at least once before and I keep forgetting the solution. My krb5.conf gets helpfully overwritten from time to time, and krb5.conf.d is ignored.

Metadata Update from @dwd:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

Metadata