OD Master Kerberos is stopped
Just upgraded from 10.6.8 to 10.7.2. Was going well until I accidently used Directory Util to bind to OD (got confused about where things were and what I was actually clicking on, quite embarrasing really)
Now, as per the title, I'm unable to open the OD node on my OD Master in Workgroup Manager (The node /LDAPv3/127.0.0.1 couldn’t be opened because an unexpected error of type -14006 occurred.), or indeed log on using any accounts stored in OD.
In Server Admin\Open Directory, Kerberos marked as stopped.
In the Kerberos Server Logs I see the following:
2011-11-26T10:01:28 label: OSXSERVER.PRIVATE
2011-11-26T10:01:36 dbname: od:/LDAPv3/ldapi://%2Fvar%2Frun%2Fldapi
2011-11-26T10:01:43 mkey_file: /var/db/krb5kdc/m_key.OSXSERVER.PRIVATE
2011-11-26T10:01:43 acl_file: /var/db/krb5kdc/acl_file.OSXSERVER.PRIVATE
2011-11-26T10:01:46 label: LKDC:SHA1.4AFF64EDFC760474C4AF1B5E024CD5C384C40DD5
2011-11-26T10:01:46 dbname: od:/Local/Default
2011-11-26T10:01:46 mkey_file: /var/db/krb5kdc/m-key
2011-11-26T10:01:46 acl_file: /var/db/krb5kdc/kadmind.acl
2011-11-26T10:01:46 WARNING Found KDC certificate (O=System Identity,CN=com.apple.kerberos.kdc)is missing the PK-INIT KDC EKU, this is bad for interoperability.
2011-11-26T10:01:46 listening on IPv6::: port 88/udp
2011-11-26T10:01:46 FAILED listening on IPv4:0.0.0.0 port 88/udp
2011-11-26T10:01:46 listening on IPv6::: port 88/tcp
2011-11-26T10:01:46 FAILED listening on IPv4:0.0.0.0 port 88/tcp
2011-11-26T10:01:46 FAILED listening on IPv6::: port 88/udp
2011-11-26T10:01:46 listening on IPv4:0.0.0.0 port 88/udp
2011-11-26T10:01:47 FAILED listening on IPv6::: port 88/tcp
2011-11-26T10:01:47 listening on IPv4:0.0.0.0 port 88/tcp
2011-11-26T10:01:47 KDC started
2011-11-26T10:02:10 label: default
2011-11-26T10:02:10 dbname: od:/Local/Default
2011-11-26T10:02:11 mkey_file: /var/db/krb5kdc/m-key
2011-11-26T10:02:11 acl_file: /var/db/krb5kdc/kadmind.acl
...
2011-11-26T10:02:23 Server not found in database: host/osxserver.private@OSXSERVER.PRIVATE: no such entry found in hdb
I have wiki's and blogs that are linked to OD accounts so this is quite a problem.
I'm guessing that what I need to do (other than roll the whole thing back to 10.6) is to completely reset the Kerberization of the OD Master. However I understand that the kerberos implementation has completely changed since 10.6 making most of the existing guidance obsolete.
Any help would be greatly appreciated!
Nick
Mac OS X (10.7.2)