kerberos "client and server clocks must be synchronized"
Posted on 2004-09-28
I am having an issue on AIX 4.3.3 with kerberos and sp complex,
after I built new keys on the control workstation which are under /tftpboot and place the new krb-srvtab files on all the systems I start haveing errors show up like the following:
(the xxx has been put in place of real names)
rcmdtgt: 2502-052 Error getting service ticket for rcmd.xxx@xxx.COM
2504-037 Kerberos error: client and server clocks must be synchronized.
2502-603 You do not have Kerberos credentials.
kdestroy: 2502-000 No tickets to destroy.
checking the date shows i was off by as much as 40 minutes apart on 3 systems.. out of 10.
2 nodes on frame 1 and 1 of the nodes on frame 2, so its not frame specific.
after issuing the command on the cws # dsh -av date 09281200.0004 to synchronize all the times and dates, I noticed after 15 minutes that those 3 systems are now 2 minutes behind still.
I issued the command on those nodes
# ntpdate –d <CWS en0 IP address>
# xntpdc -p
(they all came back with no errors)
still now after 30 minutes i show 3 minutes lost and counting on those nodes.
xntp is running on the cws. as well as all the nodes.
they were all rebooted 13 hours ago.
I also noticed that the /etc/ntp.drift file shows a very large negative number like
-28527.43530 and -28527.42709 and -28527.43530 for those 3 nodes.
versus a node that is stiill in sync. with a ntp.drift of 8.23453
can someone help???