Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Very long (10min+) logon time on clients

Hi!

Around 2 weeks ago our employees started to report that some macbooks/imac's (with maverick ob board) have very long logon time - 10min+ "spinning wheel" after home sync.

Issue is related only to couple of client machines. Upgrade from Maverick To Yosemite fix the issue, but only for couple of days! Then issue re-occuring on the machines again. It's not related to the mobile profile, sync is very fast, "spinning wheel" appear after the sync and spiining for another 10+ minutes.


Our infrastructure:

- OS X Maverick (10.9.4) + Server 3.1.2

- clients machines - 30+ machines, maverick and couple of yosemites.

- Open Directory/File Sharing/Profile Manager on Server

- Mobile Profiles on clients with enabled syncing during logon/logoff only.


I noticed those errors during the "spinning wheel" (log gathere on server, not client):


Nov 13 11:10:28 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:56766 for host/johns-2014-macbook-pro.local@ODMASTER.OURDOMAIN.COM [canonicalize, forwardable]

Nov 13 11:10:28 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:10:28 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:54978 for krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM [forwardable]

Nov 13 11:10:28 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:10:29 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:63166 for host/johns-2014-macbook-pro.local@ODMASTER.OURDOMAIN.COM [canonicalize, forwardable]

Nov 13 11:10:29 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:10:29 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:51181 for krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM [forwardable]

Nov 13 11:10:29 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:16:32 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:54374 for host/johns-2014-macbook-pro.local@ODMASTER.OURDOMAIN.COM [canonicalize, forwardable]

Nov 13 11:16:32 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:16:32 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:50691 for krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM [forwardable]

Nov 13 11:16:32 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:16:33 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:58251 for host/johns-2014-macbook-pro.local@ODMASTER.OURDOMAIN.COM [canonicalize, forwardable]

Nov 13 11:16:33 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:16:33 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:53871 for krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM [forwardable]

Nov 13 11:16:33 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb


—————————————————


Nov 13 11:16:32 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:16:32 odmaster.OURDOMAIN.com kdc[54]: TGS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:50691 for krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM [forwardable]

Nov 13 11:16:32 odmaster.OURDOMAIN.com kdc[54]: Server not found in database: krbtgt/LOCAL@ODMASTER.OURDOMAIN.COM: no such entry found in hdb

Nov 13 11:16:33 odmaster.OURDOMAIN.com kdc[54]: AS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:64393 for krbtgt/ODMASTER.OURDOMAIN.COM@ODMASTER.OURDOMAIN.COM

Nov 13 11:16:33 --- last message repeated 1 time ---

Nov 13 11:16:33 odmaster.OURDOMAIN.com kdc[54]: AS-REQ john_smith@ODMASTER.OURDOMAIN.COM from 192.168.1.232:65181 for krbtgt/ODMASTER.OURDOMAIN.COM@ODMASTER.OURDOMAIN.COM

Nov 13 11:16:33 --- last message repeated 1 time ---



Please advise. We would like to not upgrade/migrate to Yosemite for now.

Mac mini, OS X Mavericks (10.9.4), SERVER 3.1.2

Posted on Nov 13, 2014 11:32 AM

Reply
1 reply

Nov 13, 2014 8:05 PM in response to fs_sew

Many Open Directory problems can be resolved by taking the following steps. Test after each one, and back up all data before making any changes.

1. The OD master must have a static IP address on the local network, not a dynamic address.

2. You must have a working DNS service, and the server's hostname must match its fully-qualified domain name. To confirm, select the server by name in the sidebar of the Server application window, then select the Overview tab. Click the Edit button on the Host Name line. On the Accessing your Server sheet, Domain Name should be selected. Change the Host Name, if necessary. The server must have at least a three-level name (e.g. "server.yourdomain.com"), and the name must not be in the ".local" top-level domain, which is reserved for Bonjour.

3. The primary DNS server used by the server must be itself, unless you're using another server for internal DNS. The only DNS server set on the clients should be the internal one, which they should get from DHCP if applicable.

4. Follow these instructions to rebuild the Kerberos configuration on the master.

5. If you use authenticated binding, check the validity of the master's certificate. The common name must match the hostname and domain name. Deselecting and then reselecting the certificate in Server.app has been reported to have an effect in some cases. Otherwise delete all certificates and create new ones.

6. Unbind and then rebind the clients in the Users & Groups preference pane. Use the fully-qualified domain name of the master.

7. Reboot the master and the clients.

8. Don't log in to the server with a network user's account.

9. Disable any internal firewalls in use, including third-party "security" software.

10. If you've created any replica servers, delete them.

11. As a last resort, export all OD users. In the Open Directory pane of Server, delete the OD server. Then recreate it and import the users. Ensure that the UID's are in the 1001+ range.

If you get this far without solving the problem, then you'll need to examine the logs in the Open Directory section of the log list in the Server app, and also the system log on the clients.

Very long (10min+) logon time on clients

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.