Issue getting Kerberos and SSO to work

jramos

Registered
So I’ve been following the instructions on afp548 AD-OD integration pdf and
I’m running into a problem.

I want to have my users to login to their Macs with AD accounts and have
their home dirs be on the Xserve. I have been able to bind the Xserve to AD
and add it to the AD Kerberos realm but the users are still be prompted to
authenticate when they try to mount a afp share on the Xserve. Now here is
the strange part, their home dirs are being shared over afp on that same
server?!? This leads me to believe Kerberos is working over afp because the
home dir mounts at login, also smb is working since they don’t get prompted
when they mount a share on one of the window server in the domain.

On the client I have the AD plugin configured to use the UNC path from AD
for network homes over afp and force local homes is NOT check.

Any help would be appreciated,

Jorge.
 
Check with klist to see that you actually have a kerberos ticket when you login to begin with. Also, check to see how long the expiration time is set to. Could be that some of your folks are leaving machines logged in past the ticket's life, so a new ticket is needed. Also, check your authentication methods accepted for the AFP shares.

Michael
 
Thanks for the reply.

klist shows that I'm getting a ticket from AD but I don't see a ticket for AFP.
Expiration is showing 9:59
Jorge.
 
Back
Top