Follow us on...
Follow us on Twitter Follow us on Facebook
Register
Results 1 to 6 of 6
  1. #1
    b4tn's Avatar
    b4tn is offline Registered User
    Join Date
    Jun 2001
    Location
    California
    Posts
    171
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Probably a stupid question.

    I am logging into an an OSX 10.4 ODM with an OSX 10.4 machine

    I have Kerberos enabled and and all seems to work but the only way I can access any kind of AFP share is if AFP guest access is turned on. If I disable kerberos authintication AFP works fine if guest access is turned off. Is there a reason I have to have guest access on for Kereros authintication to work?
    PC IT pro by day MacAddict by night

  2. #2
    Go3iverson is offline Registered User
    Join Date
    Mar 2003
    Location
    Chicago, IL
    Posts
    1,071
    Thanks
    0
    Thanked 3 Times in 3 Posts
    Shouldn't be. Are you sure that Kerberos is working?

    On the client, type klist in the Terminal right after logging in. You should have a TGT from the KDC responsible for the network. If you don't, or it is invalid, stop there, that means you have something going on with your KDC itself. If you do, then login to the AFP server. Run klist again and confirm that you have a service ticket from the AFP server. If you don't, again, that could be your issue.

    If you don't get that AFP ticket, ssh into the AFP server and run sudo klist -kt to dump out the service principals for the server itself that are stored in the keytab file. If that file is invalid, missing or just generally gunked up, you have an issue.

    Michael

  3. #3
    b4tn's Avatar
    b4tn is offline Registered User
    Join Date
    Jun 2001
    Location
    California
    Posts
    171
    Thanks
    0
    Thanked 0 Times in 0 Posts
    This is getting really frustrating! I have never had so much troubles setting up a server before. Granted I know nothing about unix or the mac server environment :lol:

    I wanted to check what you said but I delated the user account. I went to create a new one and now I cant create accounts. After authinticating to the LDAp directory all the user controls are greyed out. I cant add remove or change users now.
    PC IT pro by day MacAddict by night

  4. #4
    Go3iverson is offline Registered User
    Join Date
    Mar 2003
    Location
    Chicago, IL
    Posts
    1,071
    Thanks
    0
    Thanked 3 Times in 3 Posts
    Wow. Ummmm...

    Are you authenticated as a directory administrator, which is by default, the shortname diradmin to the directory? After logging in via WGM, look right underneath the button bar to see the directory to which you are authenticated. You may need to go all the way to the right, click the lock and add authenticate as diradmin.

    That wasn't the account you deleted, right?

    Michael

    PS: Out of curiosity, are you setting this up for your own hobby/gratification, or are you doing this professionally for someone?

  5. #5
    b4tn's Avatar
    b4tn is offline Registered User
    Join Date
    Jun 2001
    Location
    California
    Posts
    171
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Something is wrong with the diradmin account. I cant find where this account actually is created either. This is not the first time this has happened. It seems to be related to me joining a windows computer to the directory. Last time I re-installed the server lol. I dont want to re-install again. Basically I can authenticate, the password is accepted, but the create user button is grayed out as well as any other account options. The password reset option is available though. The lock in the corner shows unlocked. Take a look at the log snipit, all in the same second it authenticates then disconnects however the lock stays unlocked.

    As for why I am setting up. A little of both, I am a long time mac user but have never worked in a network environment with a mac. All of my work experience is with windows. We are going to be setting up a classroom with an OSX server in the near future at work. I was the only one of the 3 SA's that wanted to touch an apple system. I have a spare G4 sitting at home so I am trying to teach my self through trial and error the ways to set this up.

    Jun 18 2006 07:20:41 RSAVALIDATE: success.
    Jun 18 2006 07:20:41 AUTH2: {0x00000000000000000000000000000001, diradmin} DHX authentication succeeded.
    Jun 18 2006 07:20:41 KERBEROS-LOGIN-CHECK: user {0x00000000000000000000000000000001, diradmin} is in good standing.
    Jun 18 2006 07:20:41 QUIT: {no user} disconnected.
    Jun 18 2006 07:20:41 KERBEROS-LOGIN-CHECK: user {0x00000000000000000000000000000001, diradmin} authentication succeeded.
    Jun 18 2006 07:20:41 QUIT: {no user} disconnected.
    PC IT pro by day MacAddict by night

  6. #6
    b4tn's Avatar
    b4tn is offline Registered User
    Join Date
    Jun 2001
    Location
    California
    Posts
    171
    Thanks
    0
    Thanked 0 Times in 0 Posts
    I created a more detailed and related thread here

    http://macosx.com/forums/showthread....12#post1314412

    thanks
    PC IT pro by day MacAddict by night

 

 

Similar Threads

  1. Stupid question
    By Cam@cshbe.com in forum Software Programming & Web Scripting
    Replies: 2
    Last Post: June 8th, 2004, 06:18 AM
  2. Stupid question on tv-out
    By iscaro in forum Hardware & Peripherals
    Replies: 0
    Last Post: April 27th, 2003, 01:02 AM
  3. Stupid Question!
    By Jason in forum Mac OS X System & Mac Software
    Replies: 4
    Last Post: December 19th, 2002, 12:46 AM
  4. Stupid question
    By jeepster485 in forum Mac OS X System & Mac Software
    Replies: 1
    Last Post: November 12th, 2002, 04:27 PM
  5. Ok, this may be a stupid question, but...
    By buc99 in forum Mac OS X System & Mac Software
    Replies: 7
    Last Post: December 13th, 2001, 01:37 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •