$ KRB5_TRACE=/dev/stdout smbclient --use-kerberos=required --use-krb5-ccache=KCM: --client-protection=encrypt //asn.localkdc.test/homes
gensec_gse_iakerb_client_start: No password for user principal[testuser@AB.LOCALKDC.SITE]
[682] 1737890929.509988: Getting credentials testuser@AB.LOCALKDC.SITE -> cifs/asn.localkdc.test@AB.LOCALKDC.SITE using ccache KCM:1000:29129
[682] 1737890929.509989: Retrieving testuser@AB.LOCALKDC.SITE -> krb5_ccache_conf_data/start_realm@X-CACHECONF: from KCM:1000:29129 with result: -1765328243/Matching credential not found
[682] 1737890929.509990: Retrieving testuser@AB.LOCALKDC.SITE -> cifs/asn.localkdc.test@AB.LOCALKDC.SITE from KCM:1000:29129 with result: -1765328243/Matching credential not found
[682] 1737890929.509991: Retrieving testuser@AB.LOCALKDC.SITE -> krbtgt/AB.LOCALKDC.SITE@AB.LOCALKDC.SITE from KCM:1000:29129 with result: 0/Success
[682] 1737890929.509992: Starting with TGT for client realm: testuser@AB.LOCALKDC.SITE -> krbtgt/AB.LOCALKDC.SITE@AB.LOCALKDC.SITE
[682] 1737890929.509993: Requesting tickets for cifs/asn.localkdc.test@AB.LOCALKDC.SITE, referrals on
[682] 1737890929.509994: Generated subkey for TGS request: aes256-sha2/87C0
[682] 1737890929.509995: etypes requested in TGS request: aes256-sha2, aes128-sha2, aes256-cts, aes128-cts, camellia256-cts, camellia128-cts
[682] 1737890929.509997: Encoding request body and padata into FAST request
[682] 1737890929.509998: Sending request (1167 bytes) to AB.LOCALKDC.SITE
[682] 1737890929.509999: Sending TCP request to UNIX domain socket /run/localkdc/kdc.sock
[682] 1737890929.510000: Received answer (467 bytes) from UNIX domain socket /run/localkdc/kdc.sock
[682] 1737890929.510001: Terminating TCP connection to UNIX domain socket /run/localkdc/kdc.sock
[682] 1737890929.510002: Sending DNS URI query for _kerberos.AB.LOCALKDC.SITE.
[682] 1737890929.510003: No URI records found
[682] 1737890929.510004: No SRV records found
[682] 1737890929.510005: Response was not from primary KDC
[682] 1737890929.510006: Decoding FAST response
[682] 1737890929.510007: TGS request result: -1765328377/Server cifs/asn.localkdc.test@AB.LOCALKDC.SITE not found in Kerberos database
[682] 1737890929.510008: Requesting tickets for cifs/asn.localkdc.test@AB.LOCALKDC.SITE, referrals off
[682] 1737890929.510009: Generated subkey for TGS request: aes256-sha2/3F80
[682] 1737890929.510010: etypes requested in TGS request: aes256-sha2, aes128-sha2, aes256-cts, aes128-cts, camellia256-cts, camellia128-cts
[682] 1737890929.510012: Encoding request body and padata into FAST request
[682] 1737890929.510013: Sending request (1167 bytes) to AB.LOCALKDC.SITE
[682] 1737890929.510014: Sending TCP request to UNIX domain socket /run/localkdc/kdc.sock
[682] 1737890929.510015: Received answer (467 bytes) from UNIX domain socket /run/localkdc/kdc.sock
[682] 1737890929.510016: Terminating TCP connection to UNIX domain socket /run/localkdc/kdc.sock
[682] 1737890929.510017: Sending DNS URI query for _kerberos.AB.LOCALKDC.SITE.
[682] 1737890929.510018: No URI records found
[682] 1737890929.510019: No SRV records found
[682] 1737890929.510020: Response was not from primary KDC
[682] 1737890929.510021: Decoding FAST response
[682] 1737890929.510022: TGS request result: -1765328377/Server cifs/asn.localkdc.test@AB.LOCALKDC.SITE not found in Kerberos database
[682] 1737890929.510023: Getting credentials testuser@AB.LOCALKDC.SITE -> cifs/asn.localkdc.test@ASN.LOCALKDC.SITE using ccache KCM:1000:29129
[682] 1737890929.510024: Retrieving testuser@AB.LOCALKDC.SITE -> krb5_ccache_conf_data/start_realm@X-CACHECONF: from KCM:1000:29129 with result: -1765328243/Matching credential not found
[682] 1737890929.510025: Retrieving testuser@AB.LOCALKDC.SITE -> cifs/asn.localkdc.test@ASN.LOCALKDC.SITE from KCM:1000:29129 with result: -1765328243/Matching credential not found
[682] 1737890929.510026: Retrieving testuser@AB.LOCALKDC.SITE -> krbtgt/ASN.LOCALKDC.SITE@ASN.LOCALKDC.SITE from KCM:1000:29129 with result: 0/Success
[682] 1737890929.510027: Found cached TGT for service realm: testuser@AB.LOCALKDC.SITE -> krbtgt/ASN.LOCALKDC.SITE@AB.LOCALKDC.SITE
[682] 1737890929.510028: Requesting tickets for cifs/asn.localkdc.test@ASN.LOCALKDC.SITE, referrals on
[682] 1737890929.510029: Generated subkey for TGS request: aes256-sha2/E74D
[682] 1737890929.510030: etypes requested in TGS request: aes256-sha2, aes128-sha2, aes256-cts, aes128-cts, camellia256-cts, camellia128-cts
[682] 1737890929.510032: Encoding request body and padata into FAST request
[682] 1737890929.510033: Sending request (1189 bytes) to ASN.LOCALKDC.SITE
[682] 1737890929.510034: Sending DNS URI query for _kerberos.ASN.LOCALKDC.SITE.
[682] 1737890929.510035: No URI records found
[682] 1737890929.510036: Sending DNS SRV query for _kerberos._udp.ASN.LOCALKDC.SITE.
[682] 1737890929.510037: Sending DNS SRV query for _kerberos._tcp.ASN.LOCALKDC.SITE.
[682] 1737890929.510038: No SRV records found
gse_get_client_auth_token: gss_init_sec_context failed with [Unspecified GSS failure. Minor code may provide more information: Cannot find KDC for realm "ASN.LOCALKDC.SITE"](2529639066)
gensec_spnego_client_negTokenInit_step: gse_krb5: creating NEG_TOKEN_INIT for cifs/asn.localkdc.test failed (next[(null)]): NT_STATUS_LOGON_FAILURE
session setup failed: NT_STATUS_LOGON_FAILURE
With commit abbra@928652f we can create cross-realm trust between the two demo hosts. However, an attempt to connect to the other system using Kerberos TGT for a user from the local KDC does not work because
gss_init_sec_context()processing cannot complete and we cannot get the service ticket locally.