Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Misconfiguration detected in hash Kerberos

Hi Guys,


im getting some errors in my Open Directory Logfile and i have really no idea how to fix this.

The server is a Lion 10.7.2 Server with an Open Directory Master (no Replicas)


When i use dscl to list the users in the directory (list LDAPv3/127.0.0.1/Users/) every user is shown correctly in the list.


Connecting to a share on that server works but we get the following errors:


2011-11-03 11:16:24.493 CET - Module: SystemCache - Misconfiguration detected in hash 'Kerberos':

User 'user1.domain' (/LDAPv3/127.0.0.1) - ID 1053 - UUID B3189A5D-77EA-4A1C-91BB-DDD9CCF5A958 - SID S-1-5-21-2553502104-2799725507-638401443-3106

User 'user2.domain' (/LDAPv3/127.0.0.1) - ID 1058 - UUID F7D98082-D682-446B-BF2C-840901B8E623 - SID S-1-5-21-2553502104-2799725507-638401443-3116

2011-11-03 11:20:16.750 CET - Module: SystemCache - Misconfiguration detected in hash 'Kerberos':

User 'user6.domain' (/LDAPv3/127.0.0.1) - ID 1025 - UUID 197D5942-72BA-4AC1-B11C-5154F0CC05C0 - SID S-1-5-21-2553502104-2799725507-638401443-3050

User 'user2.domain' (/LDAPv3/127.0.0.1) - ID 1058 - UUID F7D98082-D682-446B-BF2C-840901B8E623 - SID S-1-5-21-2553502104-2799725507-638401443-3116

2011-11-03 11:22:43.093 CET - Module: SystemCache - Misconfiguration detected in hash 'Kerberos':

User 'user5.domainr' (/LDAPv3/127.0.0.1) - ID 1075 - UUID C3CBB296-1A6A-452D-BEB8-8AC7ABE52E44 - SID S-1-5-21-2553502104-2799725507-638401443-3150

User 'user2.domain' (/LDAPv3/127.0.0.1) - ID 1058 - UUID F7D98082-D682-446B-BF2C-840901B8E623 - SID S-1-5-21-2553502104-2799725507-638401443-3116

2011-11-03 11:24:34.487 CET - Module: SystemCache - Misconfiguration detected in hash 'Kerberos':

User 'user4.domain' (/LDAPv3/127.0.0.1) - ID 1074 - UUID D5C3278F-9597-41F1-9B47-1E2865F01545 - SID S-1-5-21-2553502104-2799725507-638401443-3148

User 'user2.domain' (/LDAPv3/127.0.0.1) - ID 1058 - UUID F7D98082-D682-446B-BF2C-840901B8E623 - SID S-1-5-21-2553502104-2799725507-638401443-3116


Thanks for every useful hint to get rid of these errors.

Patrick

Mac mini, Mac OS X (10.7.2)

Posted on Nov 3, 2011 3:41 AM

Reply
13 replies

Dec 11, 2011 5:46 PM in response to schoysi

+1 on freshly installed Lion Server 10.7.2, newly created network accounts, no migration whatsoever.


Here's what dscl shows on the newly created network account 'fubar'. Note the funky Kerberos email id "untitled_1@HOST.DOMAIN.COM". Workgroup Manager always comes up with the default account name Untitled_1 before you edit anything. Does this persist? Is this the issue?


$ sudo dscl

Entering interactive mode... (type "help" for commands)

> cd /LDAPv3/127.0.0.1/Users/fubar

/LDAPv3/127.0.0.1/Users/fubar > ls

/LDAPv3/127.0.0.1/Users/fubar > read

dsAttrTypeNative:objectClass: person inetOrgPerson organizationalPerson posixAccount shadowAccount top extensibleObject apple-user

AltSecurityIdentities: Kerberos:untitled_1@HOST.DOMAIN.COM

AppleMetaNodeLocation: /LDAPv3/127.0.0.1

AppleMetaRecordName: uid=fubar,cn=users,dc=host,dc=domain,dc=com

AuthenticationAuthority:

;ApplePasswordServer;0xf00 root@host.domain.com:10.0.1.2

GeneratedUID: bar

LastName: fubar

MCXFlags:

<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">

<plist version="1.0">

<dict>

<key>simultaneous_login_enabled</key>

<true/>

</dict>

</plist>


NFSHomeDirectory: 99

Password: {CRYPT}*

PrimaryGroupID: 20

RealName: fubar


RecordName: fubar

RecordType: dsRecTypeStandard:Users

UniqueID: 1027

UserShell: /bin/bash

Jan 17, 2012 1:34 PM in response to realzcubed

After doing a fresh install of Server 10.7.2 and noticing the property

AltSecurityIdentities: Kerberos:untitled_1@HOST.DOMAIN.COM on all network users created with Workgroup Manager were causing the error: Misconfiguration detected in hash 'Kerberos', to be displayed in the Open Directory Log and System Log, I used Directory Utility (part of Server.app) to modify the AltSecurityIdentities property for those users.


I will monitor if this fixes the error messages.

Jul 10, 2012 6:58 AM in response to schoysi

"After doing a fresh install of Server 10.7.2 and noticing the property

AltSecurityIdentities: Kerberos:untitled_1@HOST.DOMAIN.COM on all network users created with Workgroup Manager were causing the error: Misconfiguration detected in hash 'Kerberos', to be displayed in the Open Directory Log and System Log, I used Directory Utility (part of Server.app) to modify the AltSecurityIdentities property for those users."



Could someone please give more info on where this setting is located in Directory Utility? I am new to OS X server and having this exact same issue. Thanks.

Jul 10, 2012 7:05 AM in response to guitarkid55

Hi guitarkid55,


first you have to autheticate in the directory Utility with your directory credentials (diradmin)


Then switch to Users (Viewing) and select the user with the problem.

On the righ side you can select the "AltSecurityIdentities" and edit this setting. An click "save".


Hope this helps solving your problem.


Greetings

schoysi

Misconfiguration detected in hash Kerberos

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.