Description of problem: After a run of system-config-authentication, GSSAPI does not work for CVS and fetchmail. Version-Release number of selected component (if applicable): authconfig-5.2.3-2 How reproducible: 100% Steps to Reproduce: 1. Run system-config-authentication 2. Specify kerberos.corp.redhat.com for DC and Admin Server 3. Run kinit (it succeeds) 4. Run a test application (cvs -d :gserever:cvs.devel.redhat.com co bash) Actual results: Authentication fails Expected results: Authentication succeeds Additional info: Hand-editing is required. Adjusting default_domain in [realms] and having [domain_realm] with redhat.com seems to help. Minimally edited krb5.conf is to be attached. I am of the opinion that we ought to eat our own dogfood.
Created attachment 130047 [details] Working krb5.conf
Actually adding the [domain_realm] mapping should be enough. I think it's safe to add.