Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Mobile User Slow Login Off Network

I am running server 10.58 with mobile user accounts. I have upgraded three laptops to Snow Leopard and when they are off the network any login or password entry for things like changing a sys pref takes over 1 minute. If i remove the network account server bind from the user account in sys prefs, the login is back to normal. I read of similar problems in 10.5 that was the result of a search domain being listed in the DNS settings of the client machine. However, my DHCP server provides the DNS and search domain listings so this is not listed in the client machines when they are off the network.

My domain name is miniserv.companydomain.net and the search domain in the server is companydomain.net - but again, this DNS info is not listed in the client machines. companydomain.net is a FQDN that only runs locally. Could the client be looking for companydomain.net on the WAN?

The console log reads as follows:

authorizationhost[1965] k5_authenticate(): got -1765328228 (Cannot contact any KDC for requested realm) on /SourceCache/SecurityAgent/SecurityAgent-37013/plugins/krb5/krb5_operations.c:8 4

authorizationhost[1965] -[SFBuiltinAuthenticate performDSPasswordAuth](): got -1765328228 (Cannot contact any KDC for requested realm) on /SourceCache/SecurityAgent/SecurityAgent-37013/authhostbuiltins.m:1039


Any guidance appreciated.

MacBook Pro, Mac OS X (10.6)

Posted on Sep 4, 2009 2:38 PM

Reply
118 replies

Sep 4, 2009 9:55 PM in response to TheChinaMac

Yes, it is probably a DNS issue. KDC = Key Distribution Center. The server becomes a KDC when using Kerberos authentication, as Kerberos (krb5) uses key cryptography. The client can't find the server. Make sure the clients have the proper DNS servers setup.

Sep 24, 2009 3:54 PM in response to TheChinaMac

Did you ever get this resolved? I have the same problem.

I found that if I turn off all network interface, then login is flawless.

Also, I think the behavior in Leopard was that off network mobile users do not sync at login/logout, because they can't find the server. But when my SL clients logout, they still want to sync. This makes me think it's because the client somehow still thinks it's in the network.

Oct 16, 2009 11:50 AM in response to TheChinaMac

I seem to have solved this problem for us by *switching off* the "Server Side File Tracking for Mobile Home Sync" setting in Server Admin. Now the Sync process no longer hangs indefinitely at login or logout (or shows Checking "~/" forever), but unfortunately the actual sync itself has slowed down as when it happens the entire folder structure is compared for changes. I guess I replaced the problem of an unreliable sync that forced users to force-power-off their machines into a reliable but slow one... realised

By the way, as I was debugging this problem I that it was the "ssh yourserver ... FileSyncAgent" process that seemed to be hanging indefinitely. Your cause may be different therefore this solution might not work... Good luck.

Dec 31, 2009 6:16 AM in response to DirkTheDog

I thought this thread was in reference to waiting forever to login when away from your office network. We don't do any sync at login/logout but it still takes forever at home. All syncing while at work has been perfect, especially since 10.6.2.

I sure hope Apple fixes this soon as it is holding up our deployment of Snow Leopard.

May 6, 2010 2:02 AM in response to mrbofus

Sync issues and AD issues aside.

I too am seeing this delay of around 2 minutes during login in the following scenario which I believe the OP was experiencing: -

• Mac OS 10.6.x
• PHD / Mobile Account.
• Computer CAN coonnect to internet.
• Computer CANNOT connect to OD Master (eg. offsite, not vpn etc).

As mentioned, my logs show KDS returning errors after a long wait (around 1:30 - 2 mins in my case) while it hunts for a KDC for the realm.

My current thinking is: -

• Can we reduce the KDC timeout via a conf / plist / dscl value someplace?
• If this only happens when a internet connection is up, can we script a pull down of the internet connection in a boot script to skip it?

May 6, 2010 8:16 AM in response to Codeus

I would like to add some support to this thread. I have the same problem, with ~2.5min delay during login. This is the time from when the mouse first appears after boot until the user logon screen is displayed. Fine when within office network, problems when away from domain.

I found this article: http://www.macenterprise.org/articles/fixingactivedirectorytimeoutvalues
which discusses changing the LDAP timeout. I found it referenced from a couple other articles which say that this worked fine for Tiger but not for Leopard or SL. I can confirm that changing the timeout value in my activedirectory.plist from the original "90" to "10" made no difference at all.
I have also seen people saying that disabling Bonjour helped or stopping mDNSresponder but that essentially 'switches off' the internet...

This is a real inconvenience and I hope that someone can come up with a solution/apple fix this as soon as possible.

Mobile User Slow Login Off Network

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.