bkpippert

Q: Why can't network user accounts login to the Open Directory from the local network?

I am looking for a little help/direction in deciphering the below Server 3.0 system logs and resolving this problem. The logs are generated when any local network user account attempts to login to the Open Directory from a 10.9 client Mac on the local network. Any local network account can successfully login to the Open Directory when using the computer hosting the Server 3.0.

 

Background info:

All devices have a fresh installed of 10.9

Using a registered domain

The server has the following services running

- Caching (working great!)

- File Sharing (have tried both AFP and SMB)

- Profile Manager (no profiles established yet)

- DNS (Tested DNS using dig -x (ip and hostname) and sudo changeip -checkhostname. Results show everything working as desired)

- Open Directory

- Software Update

Using apple networking devices

 

The device and domain name information has been changed in the below logs to server.example.com and 4example

 

Nov  3 12:51:32 --- last message repeated 1 time ---

Nov  3 12:51:32 server.example.com kdc[9240]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ

Nov  3 12:51:32 server.example.com kdc[9240]: AS-REQ Brian@server.example.com from 192.168.2.11:62610 for krbtgt/server.example.com@server.example.com

Nov  3 12:51:32 --- last message repeated 1 time ---

Nov  3 12:51:32 server.example.com kdc[9240]: Client sent patypes: ENC-TS

Nov  3 12:51:32 server.example.com kdc[9240]: ENC-TS pre-authentication succeeded -- Brian@server.example.com

Nov  3 12:51:32 server.example.com kdc[9240]: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, des3-cbc-sha1, arcfour-hmac-md5, using aes256-cts-hmac-sha1-96/aes256-cts-hmac-sha1-96

Nov  3 12:51:32 server.example.com kdc[9240]: Requested flags: forwardable

Nov  3 12:51:32 server.example.com kdc[9240]: TGS-REQ Brian@server.example.com from 192.168.2.11:53369 for host/4example.local@server.example.com [canonicalize, forwardable]

Nov  3 12:51:32 server.example.com kdc[9240]: Searching referral for 4example.local

Nov  3 12:51:32 server.example.com kdc[9240]: Server not found in database: krbtgt/LOCAL@server.example.com: no such entry found in hdb

Nov  3 12:51:32 server.example.com kdc[9240]: Failed building TGS-REP to 192.168.2.11:53369

Nov  3 12:51:32 server.example.com kdc[9240]: TGS-REQ Brian@server.example.com from 192.168.2.11:56684 for krbtgt/LOCAL@server.example.com [forwardable]

Nov  3 12:51:32 server.example.com kdc[9240]: Server not found in database: krbtgt/LOCAL@server.example.com: no such entry found in hdb

Nov  3 12:51:32 server.example.com kdc[9240]: Failed building TGS-REP to 192.168.2.11:56684

OS X Mavericks (10.9)

Posted on Nov 3, 2013 10:43 AM

Close

Q: Why can't network user accounts login to the Open Directory from the local network?

  • All replies
  • Helpful answers

  • by bkpippert,Solvedanswer

    bkpippert bkpippert Nov 4, 2013 6:33 PM in response to bkpippert
    Level 1 (15 points)
    Nov 4, 2013 6:33 PM in response to bkpippert

    I solved my own problem, hopefully these steps resolve the problems others are having.

     

    Rebooted server, during start-up pressed Command-R, to start from the recovery system

    Ran the disk utility first “Repair Disk” (no errors were found)

    Ran the disk utility again “Repair Disk Permissions” noticed numerous permission problems fixed to include two files relating to ldap.

    On the client machines under system preferences - users & groups - login options - edit network account server remove existing OD

    On the client machines under system preferences - network - advanced… - DNS tab, remove all DNS IPs but the Open Directory Server (which is running DNS), if the Open Directory IP is not listed added it.

    On the client machines under system preferences - users & groups - login options - edit network account server add the Open Directory

  • by Dr. Rick,

    Dr. Rick Dr. Rick Nov 6, 2013 9:46 PM in response to bkpippert
    Level 1 (9 points)
    Nov 6, 2013 9:46 PM in response to bkpippert

    this worked great for me. Thank you

  • by LondonServer,

    LondonServer LondonServer Nov 13, 2013 4:33 AM in response to bkpippert
    Level 1 (0 points)
    Nov 13, 2013 4:33 AM in response to bkpippert

    Thank you, I tried that on our server and it seems to have solved many of our issue. However system logs still show errors such as kdc failed and kdc: Server not found in database, do you get any of that?

  • by Doogy,

    Doogy Doogy Nov 17, 2013 6:33 PM in response to bkpippert
    Level 1 (95 points)
    Nov 17, 2013 6:33 PM in response to bkpippert

    Its more of a name resolution issue with mavericks. 

    10.8.5 mac working fine here

    10.8.5 client to 10.9 server ok

    10.9 client to 10.9 server issue

     

    at times lookup get an error on 10.9 machines: kcferrordomaincfnetwork

     

    also lookup no more displays full details in 10.9

     

    and for whatever reason network utility is more easily accessible!!

  • by SBAUK,

    SBAUK SBAUK Jan 21, 2014 2:53 AM in response to bkpippert
    Level 1 (0 points)
    Jan 21, 2014 2:53 AM in response to bkpippert

    Cheers, I only needed the remove OD server and re add and trust, but it did the trick (10.9 server and clients, all upgraded from working 10.6)

  • by HyteRaph,

    HyteRaph HyteRaph May 14, 2014 8:38 AM in response to bkpippert
    Level 1 (0 points)
    May 14, 2014 8:38 AM in response to bkpippert

    wonderful! after a great amount of threats regarding this (or a very similar) problem, that answer finally fixed it for me!

    thank you very much!