Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Your token has a limited lifetime, which is 8 hours at CNF. To check your
token's expiration date, do the following:

 Windows

 

         Click the lock icon in your system tray. Select the "Tokens" tab
        if it is not already selected. If there is no lock icon in your
        system tray, from the Start Menu, choose All Programs, OpenAFS, then
        Authentication.

Do not use the Kerberos for Windows application to obtain new tokens. Use the AFS client (lock icon).

 Linux

         From the "Applications" menu on CNF SunRays, choose "afstokens". Your tokens are
        displayed in the box labeled "My AFS Tokens".

Use the AFS "Authentication" application to obtain new AFS tokens or view your current tokens. Check your system tray for two lock icons, possibly with a red 'x' over them.  

Of the potentially two lock icons, the correct one for AFS authentencation is the one that says "AFS Client" when you mouse over the icon. The other one will mention AFS and its version number and is not the correct one – this will start the related and separate Keberos for Windows application if you click it.

If you don't see the correct lock icon in your system tray, you can start the AFS Authentication application from the Windows start menu ... Start - O - OpenAFS - Authentication .

In the AFS Authentication application window, to obtain new tokens, click "Obtain new tokens"... your username will be formatted as one of two ways depending on if you have a Cornell NetID or Cornell GuestID:

both are case sensitive... the part after the '@' symbol must be all caps. While your netid or guestid itself must be lowercase.

If you run into problems where the Windows AFS GUI throws an error and will not give you tokens, and you have verified you are using the correct username format and correct password, see the General - Windows AFS GUI Login Error section below.

 Linux

Open an XTerm by choosing from the menus: Applications - CNF - XTerm .

From         Or from the commandline, type "tokens" to see your tokens.

To obtain new tokens, either use the GUI application or from the commandline type in kinit <username> followed by aklog. See below for proper formatting of your username.

Newer versions of the gui krb5-auth-dialog application have the ability to obtain and renew AFS tokens.

again open an XTerm from the menus via Applications - CNF - XTerm and type in: kinit followed followed by pressing return... your identity will autopopulate based on your linux login. When entering in your password, the cursor will not move. After pressing return, if you do not receive an error, type in: aklog  .  There will not be any output after pressing return if there are not any errors. Type in "tokens" again to see your new tokens and expiration time. 

On CNF Thin, AFS Tokens will generally auto renew for up to 8 days after you re-connect to your session.

On Korat and Minx, Tokens will generally auto renew for up to 8 days after you first connect. After those 8 days are up, you will need to use the kinit and aklog commands as mentioned above to obtain new tokens.

You can view the final expiration time of your Kerberos tickets (AFS Tokens are derived from Kerberos tickets either with the aklog command or automatically) by typing in the command: klist


Macintosh

The built-in System Preferences panel for managing AFS tokens does not work properly in the CNF environment if your system is not configured correctly. Do not use it without talking to CNF IT.

We suggest using the GUI AFSLog application . This application will first open the Kerberos Ticket Viewer. After logging into Kerberos, exit the Kerberos Ticket Viewer. In approximately 5 seconds, the AFSLog application will either bounce for your attention or pop up a new window. The new window will show you your AFS tokens.

...

 You can both destroy your existing tokens and obtain new tokens using the above
Windows and Linux applications.

When obtaining new tokens, if If using a Cornell netidGuestID (gid-xxxx), your username must be
formatted as:
        netid@CIT.CORNELLguestid@CORNELL.EDU (@CIT.CORNELL@CORNELL.EDU must be all caps).

If using a Cornell GuestIDNetID, your username must be formatted as:
        guestid@GUEST.CORNELL        netid@CORNELL.EDU (@GUEST@CORNELL.CORNELL.EDU must be all caps).

Windows AFS Gui Login Error

We have seen some problems when attempting to obtain AFS Tokens using the Windows AFS client GUI. To work around this, you can use the Windows Powershell to get AFS Tokens:

  1. Open a Powershell prompt
  2. Type in the following:
    Code Block
    languagepowershell
    PS> cd "C:\Program Files\MIT\Kerberos\bin"
    PS> .\kinit <netid_or_guestid>@CORNELL.EDU
    (make sure to capitalize "CORNELL.EDU" ) . 
    You will be prompted for your netid or guestid password. The cursor will not move while you type in your password. Hit return when done.
  3. Now type in the following:
    Code Block
    languagepowershell
    PS> cd "c:\Program Files\OpenAFS\Client\Program"
    PS> .\aklog -d
    you will see some debug output showing that you have successfully obtained AFS tokens.
  4. The AFS GUI will now show your tokens.

 Access Control Lists

 An Access Control List (ACL) is the AFS mechanism which let you access
directories and files. This access mechanism works as follows:

...

 Working with AFS Protection Groups

 Windows

...


        Open up a command prompt (Start - Run - cmd). View your group
        membership with the following command:

        pts membership

 Linux

         From the AFSTokens application (under the Applications menu), click
        "PTS (Group Mgmt)". To view groups of which you are a member, click
        the "Group Membership" button. To work with groups that you own, click
        the "Groups I Own" button. Groups you own will be named either:
        netid@cit.cornell.edu:groupname or guestid@guest.cornell.edu:groupname

 From a terminal (XTerm from the Applications - CNF Applications menu on CNF Thin, or simply a terminal on your own Linux box), type in (all lower case):

   pts membership netid@cit.cornell.edu
or for a GuestID:
   pts membership gid-guestid@cornell.edu

Substituting your netid or guestid for "netid" and "gid-guestid" above        When adding a new group, the part of the groupname before the colon is
        automatically filled in.

 Working with Directory ACLs

...

         Right click on a folder in AFS. Choose AFS, and then choose Access
        Control Lists. You may edit ACLs on folders for which you have "all"
        (rlidwka) permissions (for example, those in your AFS home directory)

 Linux

         From the Applications menu, choose "afs acl mgr". Click the "Open"
        button, and browse to the directory for which you want to view/edit
        AFS ACLs. The application defaults to your home directory... afs-land
        can be found under "Filesystem" in the leftmost pane. After selecting
        a directory in AFS, click "OK".

        If you prefer to use the         Use the linux commandline...

        From a terminal, use fs la directory and fs sa directory acl. For
        example:

...

                 Located at /afs/cnf.cornell.edu/shares/public/outside_users
                Only staff can write to this share.
                Files in this share can be read by anyone anywhere in the world.