Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

OS X server 10.8 Mail server. Kerberos authentication not working.

Open Directory enabled and configured. Mail server enabled and configured ("Authentication" set to "Open Directory"). Mail-client app cannot connect to server using Kerberos ("MD5" and "plain text" – OK).


Example from server log:

Feb 6 10:09:29 srv.pvt log[18069]: imap-login: Disconnected (disconnected while authenticating): method=GSSAPI, rip=192.168.1.2, lip=192.168.1.1, TLS

OS X Server

Posted on Feb 6, 2013 12:04 AM

Reply
6 replies

May 11, 2014 4:34 AM in response to Justin William Smith

I am on Mavericks Server and I am unable to get this working.


Can you guys be more specific because I tried doing what the article mentions and then rebooting but no change. I also tried putting the FQDN instead of the "ALL$" and that didn't work either. Am I supposed to be uncommenting anything else in there?


Everything else seems ok in terms of Kerberos, I am using the right Realm from klist, I can get a valid ticket with Ticket Viewer, I forced an authenticated bind on the client but I can't get Single Sign-On to work.

May 11, 2014 8:49 AM in response to tim_r_66

No when using klist my principal is: username@FQDN and on the client Mail > Preferences I have the FQDN as incoming/outgoing.


In server App, I have all authentication methods checked including Kerberos.


I've started my own thread here: https://discussions.apple.com/thread/6204162


but I thought that because the solutions posted here seemed to have worked I would give it a try.

OS X server 10.8 Mail server. Kerberos authentication not working.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.