Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Attempting to Kerberize Open Directory Master

*Moved to 10.6 forum, sorry about that! *

Hi All,

I'm attempting to get an XServe prepped for Podcast Producer use running 10.6.4. After a clean install, and creating an Open Directory Master, I'm unable to "Kerberize" the Open Directory Master. When I click Kerberize..., a window pops up asking for username and password, along with the Kerberos Realm already populated. No username or password works here, and when I check the Password Service Server Log, I get these lines each time I attempt to Kerberize:


AUTH2: {0x4cd86f944305f1dd0000000700000007, aswift} DHX authentication failed, SASL error -13 (password incorrect).
AUTH2: {0x4cd86f944305f1dd0000000700000007, aswift} DIGEST-MD5 authentication succeeded.
RSAVALIDATE: success.

I've made sure that forward and reverse DNS lookups are correct, and have even setup the DNS service on the XServe with an entry for the server IP and DNS name. I'm also able to manually create Kerberos tickets using the Ticket Viewer app using the same username as trying to Kerberize.

Ultimately, I need to Kerberize the Open Directory Master to run Xgrid and Podcast Producer. Does anyone have any insight as to why I would be getting a "DHX authentication failed" error?

Thanks

Message was edited by: aswift1

Message was edited by: aswift1

Mac OS X (10.6.4)

Posted on Nov 9, 2010 12:41 PM

Reply
1 reply

Nov 9, 2010 3:42 PM in response to aswift1

Hi

Once you've promoted to Open Directory Master that's it. Whatever services are capable of supporting Single Sign On and therefore Kerberos will already be kerberised. You're getting the error because there's nothing to kerberise. You should be aware that not all services can be kerberised. The Open Directory Admin Manual should list what services are SSO 'aware'.

Tony

Attempting to Kerberize Open Directory Master

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.