Kerberos Error

When authenticating for an AFP share point I am getting this error:
Kerberos Login Failed
Generic error (see e-text)

what is the e-text? Mind you this client is not bound to the server, and I am guessing it is showing becuase of that correct? In order for Kerberos to work 100% correct the client needs to bind to OD? OR am I way off?

ACTC, ACHD, ACDT, ACPT, Mac OS X (10.4.8)

Posted on Jul 9, 2007 6:44 PM

Reply
11 replies

Jul 17, 2007 12:05 PM in response to rkovelman

Hi

If you run kinit -V and you get this error message:

kinit: Unable to create principal for current user: Configuration file does not specify default realm
kinit: Error getting initial tickets: Operation not permitted

Then there is either no KDC present on the network, or there is a problem with the edu.mit.Kerberos file in /Library/Preferences or a problem creating this file. You can inspect tickets as well as the realm by launching the Kerberos application in /System/Library/CoreServices. Tickets Menu > Get Tickets > Realms. If you can select a Realm or see one there then use an account that is defined in your OD directory node to get a ticket. If you see nothing listed then there is no KDC providing tickets.

Launch Server Admin > AFP > Settings > Access and select Standard or Any Method if it has been set to Kerberos. This will force clients to use PasswordServer rather than looking for service tickets from a KDC that is either not there or not configured correctly.

Just an observation but as an ACTC you should know at least some of this, even if you can’t remember everything, Kerberos is such an important part of OSX Server that it is something worth making a note of. There is at least one question regarding this in the Server Essentials Exam.

Tony

Jul 17, 2007 12:28 PM in response to Antonio Rocco

Your attitude needs to change on here. You have a lot of good information but your coming accross like we are all idiots. This is the 1st time I am experiancing and issue with KDC out of 10 OS X servers I run. Issues I rarely see or hear about I forgot how to fix, everyone is the same way, no one knows everything!

BTW the errors you posted I am not seeing please read my post

Jul 23, 2007 11:03 AM in response to rkovelman

Hi

For your information: My attitude is fine and no I don’t think you are all idiots. I agree no one knows everything and yes you do forget things . . . but if you run the amount of servers that you say you run then you must have some idea of what Kerberos is. You must at least be aware of the edu.mit.Kerberos file as you would be dealing with this every day as users renew their service tickets. It would be as if you forgot how to log on.

When I posted a reply your other post had not displayed so I did not have a chance to read it.

What I have a problem with is when you post a question you either respond in one of two ways:

You already knew the answer but wanted confirmation.

So why post if you already knew? Have the courage of your own training and experience and deal with the issue yourself. Post if you genuinely want help or genuinely don’t know. Don’t demean advice given in good faith or make it seem worthless with an attitude that (to me) seems to say ‘yeah I thought it was that, just checking if you guys knew anyway.’

The other way you respond is to take the opposite stance to what everyone else is advising even when your position is erroneous. When it is pointed out to you that your position is not quite right you rarely have the good grace to give credit to helpful or correct advice.

I do hope you sort out your problem. <edited by host - see [url=http://discussions.apple.com/help.jspa#terms]Terms of Use, section 4.2.2[/url]>
.

Tony

Jul 17, 2007 7:15 PM in response to Antonio Rocco

If you find your most recent post ok then I cant help you but starting out with "for your information" does not sound appealing.

I know what Kerberos is, and not every server I run has it running, nor is it needed in those instances.

I asked the question becuase I never saw it before, so I was looking for some answers to help me solve the issue quickly and effecentialy instead of looking all over the place.

And the advice in 2 posts I had questioned about neither helped me but make me see why some people dont see this forum useful. If I or anyone else post a question its not to make converstation, I could do that on myspace. I post on here for an answer to a problem even if I second guess myself.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Kerberos Error

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.