Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Kerberos working on server, Client says Cannot resolve network address KDC

I have a new Leopard server setup and after a few errors with DNS, I have Kerberos showing as Running in Open Directory, General tab. sudo ipchange -checkhostname shows OK. I can resolve name and fully qualified name from both the workstation and the server. My REALM is the same as my fqdn server name but all CAPS.

If I open Directory on the workstation and try to add a new shared contact, I am prompted with "Directory requires that you type your Kerberos password". So I enter my name, my Realm in all CAPS, and my password. I have tried also entering the Realm in lowercase.

I get "Kerberos Login Failed: Cannot resolve network address for KDC in requested realm"

I don't see any DNS entries about KDC or SRV records in the DNS server, but I am not familiar enough with how Kerberos finds the KDC.

Any help is greatly appreciated. I've been searching these forums and googling for hours. I have also followed these documents:

http://docs.info.apple.com/article.html?path=ServerAdmin/10.5/en/c4od21.html
http://docs.info.apple.com/article.html?path=ServerAdmin/10.5/en/c4od20.html

Posted on Jun 28, 2008 1:31 PM

Reply
2 replies

Jul 1, 2008 12:22 AM in response to Zacharinas

Typically, a workstation gets the Open Directory and KDC addresses when you bind it to the directory. The KDC addresses are stored in /Library/Preferences/edu.kerberos.plist (or similar)

You can take a look at your workstation's Kerberos config by opening the Kerberos app located in /System/Library/CoreServices/

Once opened, you can Edit Realms (apple-E) and you should see your KDC info. You should try and avoid having to update each workstation. I can show you how to update the file that your server sends out to each workstation if need be.

Let me know how you go.

Kerberos working on server, Client says Cannot resolve network address KDC

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.