image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X Server

Reply
 
LinkBack Thread Tools
  #1  
Old August 15th, 2009, 05:28 AM
Registered User
 
Join Date: May 2008
Posts: 12
Thanks: 0
Thanked 2 Times in 2 Posts
chrisgrange is on a distinguished road
Kerberos KDCs

We've setup the appropriate ports on our firewall so that our clients can get kerberos tickets off-site - the plan was to authenticate to our VPN this way.

We have 2 kdcs (kdc1 and kdc2) and I've made kdc1 externally accessible. Everything worked well when I tested yesterday afternoon, I could get a ticket and authenticate to the VPN. However when I tried again later I got the error message:-

Kerberos Login Failed: Cannot contact any KDC for requested realm

From watching TCP Dump it appears that it's now trying to talk to kdc2, perhaps as a result of being connected to the VPN and pulling down some prefs.

I've tried specifying the kdc in edu.mit.Kerberos like so:-

[realms]
DOMAIN.NET = {
kdc = "kdc1.domain.net:88"
}

but it still appears to be trying to talk to kdc2. Running

sudo tcpdump -v -i en1 dst kdc2.domain.net

reports kerberos traffic whilst running

sudo tcpdump -v -i en1 dst kdc1.domain.net

reports 0 packets. So why is the machine ignoring the kdc specified in the pref file. Is there another way to force a specific kdc or am I going to have to make kdc2 externally accessible as well?
Reply With Quote
  #2  
Old August 16th, 2009, 12:11 PM
Registered User
 
Join Date: May 2008
Posts: 12
Thanks: 0
Thanked 2 Times in 2 Posts
chrisgrange is on a distinguished road
I've investigated further. The test machine is bound into our AD/OD cylinder. If I create an edu.mit.Kerberos file on a machine which is not bound it works fine so I'm guessing the AD plugin is somehow overriding my Kerberos settings. Any ideas on how I can stop this?
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump


All times are GMT -5. The time now is 03:17 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2
Copyright 2000-2010 DigitalCrowd, Inc.