Mojave Security Update 2021-004 broke Kerberos for me

This is in regards to a mobile account...


After applying Mojave security update 2021-004 I lost the ability to connect to SMB shares hosted by a Mac Mini. In addition to this I cannot connect to anything with Apple Remote Desktop (it freezes), Outlook will usually freeze on quitting now, and if I need to unlock my account (say from the screensaver) it frequently freezes after I enter the password and I have to do a forced restart.


After a lot of trouble shooting I think the problem may be with my Kerberos cache. I've come to this conclusion because the Ticket View app also freezes on boot up before any tickets appear and has to be force quit. So my question is, how can I clear the Kerberos cache without ticket viewer? Or should I simple recreate this mobile account as a local on and hope for the best.


Thanks,

Scott Wirth

iMac Line (2012 and Later)

Posted on May 27, 2021 10:54 AM

Reply

Similar questions

38 replies

Jun 22, 2021 11:22 AM in response to Charles Wirth

THANK YOU!!!!


My work laptop has been a BRICK for the last few weeks. It's just been miserable. I couldn't connect to any of our file shares. I couldn't lock my screen without it freezing. If I hovered over the Enterprise Connect icon, my entire laptop would freeze and I would have to do a reboot. I tried so many different things, and this finally fixed it. My organization already hates supporting us devops weirdos that insist on using a MacBook to do our job, so I was a couple of weeks from trading it in for some $400 Windows laptop that let me do my job again. You're a lifesaver.

Jun 24, 2021 5:38 PM in response to Matt W (TechnicalMac)

Matt W (TechnicalMac) wrote:

I just installed this update on a Mojave iMac bound to OD working fine prior to the Security update. Took the machine offline for a day to fix


Thank you for posting this information. There are posts saying this problem only affected mobile users on AD but I'd been taking that information with a pinch of salt as nobody had confirmed there were no problems with other directory technology. I still use mobile users but migrated from OD to LDAP some time ago. It was purely by chance I spotted this thread at the beginning of the month just before updating.


In my opinion if Apple (or any developer for that matter) decide to stop supporting any functionality they need to tell users in advance so users can decide whether to migrate or to risk delaying/stopping updates. If this setup is no longer supported Apple have not done that. If it is supported then there is a serious bug in the update which for some reason they have neither fixed nor, as far as I can find, documented.

Jun 28, 2021 8:44 AM in response to Matt W (TechnicalMac)

Maybe this is dead tech (Server and OD,) and Apple's too inexperienced in their current workforce to care (or actively doesn't,) but a developer friend of mine commented that it seems Apple just doesn't know how to do proper testing anymore, or doesn't care.


I would lean towards Apple not caring too much about macOS in enterprise or even workgroup environments. As a side effect, that results in a workforce that doesn't know and doesn't care much about these environments.


This isn't the only Kerberos related bug either. In Big Sur DDNS is completely broken.

https://www.jamf.com/jamf-nation/discussions/38422/big-sur-problem-dinamic-registration-in-dns-server

Jun 28, 2021 9:20 AM in response to Charles Wirth

I have a local account, but if I log out of the computer and try to log back in, the login screen gets stuck, and I have to force a restart.


Also, the Screen Sharing app will hang when I try to connect to a remote Mac. Again, I can only fix it if I restart my Mac. However, if the Mac goes to sleep for a few hours and then I try to connect to one of the remote Macs, it will freeze again.

Jul 19, 2021 2:51 PM in response to pacificadmin

It's more to do with the computer industries obsession with rapid release cycles. Current IT guidance is to be at current release minus one or minus two. Anything beyond N-2 is losing vendor and manufacturer support. In a few months, Monterey will push Mojave to being N-3 and at that point, Apple likely won't release any more updates for it.


It is not just Apple, most all operating system vendors and software application developers have increased the pace of their releases.


Jul 21, 2021 9:20 PM in response to James Brickley

I just updated a Mojave machine that was affected by the last update and... the Kerberos issue seems to be fixed at first glance. Finally!


I just did a quick test to see if I could connect to a server via SMB and it worked, so I'm assuming the underlying issue is fixed. If not I'll report back.


When I get a chance I'll update a Big Sur machine to 11.5 and see if DDNS registration is working now too.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Mojave Security Update 2021-004 broke Kerberos for me

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.