Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Does anyone know how to configure Kerberos with Lion?

It was bad enough that kerberos changed from 10.5 to 10.6, but now they've completely removed MIT Kerberos and replaced it with Heimdal in 10.7. So my existing kerberos configuration, which worked great in 10.6, no longer works in 10.7. This is a real show-stopper for me, until I can find some docs or other information on how to configure OS X as a kerberos client (the KDC is a Red Hat Enterprise Linux box).


Has anyone figured out how to do this? Whenever I try to get a ticket, it tells me that it cannot reach the KDC, but it's failing so fast that I don't think it's even trying to actually talk to my KDC (and I see no traffic to the KDC), so I don't think it knows the address for the KDC. According to the Heimdal manpages and other information, the /etc/krb5.conf file should be where this is defined, and the format should be the same as an MIT Kerberos client, but it just keeps failing miserably.


Any pointers would be highly appreciated!

Posted on Jul 20, 2011 7:54 AM

Reply
49 replies

Jun 25, 2012 11:34 AM in response to tmcmurtr

I only have the default_principal entry in pam.d/authorization (as described above) and a minimum krb5.conf as follows:


[libdefaults]

default_realm = O815.LOCAL

allow_weak_crypto = true



[realms]

O815.LOCAL = {

admin_server = kdc.o81.5

kdc = kdc.o81.5

default_domain = o81.5

}



[domain_realm]

.o81.5 = O815.LOCAL

o81.5 = O815.LOCAL

Using this setup I get a ticket on login automatically (can be shown using klist on console or within ticketviewer) but I don't run a daemon since the ticket usually lasts for my session and for the rare cases it doesn't Im not bothered to run kinit manually.

Does anyone know how to configure Kerberos with Lion?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.