Mac OS X Server : cannot login

I have a Mac OS X server 10.9.5.

Since a recent update of the Server App, I have the following problems :

- cannot login via imap and smtp to my server

- cannot "connect as" my self in Finder any more to see my home directory on the server from an Imac Server running also OS X 10.9.5


my server is accessed for the email as mail.agilebuild.com and when I connect from the IMac it is known as "agilebuild.local".


I think that I might have called the server ilantoutseul.agilebuild.com back when I set up Open Directory.


I see the following messages in /var/log/system.log


Any help will be appreciated.


Antoine


Dec 7 14:03:12 192.168.1.79 kdc[57]: Got a canonicalize request for a LKDC realm from local-ipc

Dec 7 14:03:12 192.168.1.79 kdc[57]: Asked for LKDC, but there is none

Dec 7 14:03:12 192.168.1.79 kdc[57]: Got a canonicalize request for a LKDC realm from local-ipc

Dec 7 14:03:12 192.168.1.79 kdc[57]: Asked for LKDC, but there is none

Dec 7 14:03:12 192.168.1.79 kdc[57]: AS-REQ antoine@ILANTOUTSEUL.AGILEBUILD.COM from 192.168.1.71:55075 for krbtgt/ILANTOUTSEUL.AGILEBUILD.COM@ILANTOUTSEUL.AGILEBUILD.COM

Dec 7 14:03:12 --- last message repeated 1 time ---

Dec 7 14:03:12 192.168.1.79 kdc[57]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ

Dec 7 14:03:12 192.168.1.79 kdc[57]: AS-REQ antoine@ILANTOUTSEUL.AGILEBUILD.COM from 192.168.1.71:55063 for krbtgt/ILANTOUTSEUL.AGILEBUILD.COM@ILANTOUTSEUL.AGILEBUILD.COM

Dec 7 14:03:12 --- last message repeated 1 time ---

Dec 7 14:03:12 192.168.1.79 kdc[57]: Client sent patypes: ENC-TS

Dec 7 14:03:12 192.168.1.79 kdc[57]: Too large time skew, client time 2014-12-07T13:53:17 is out by 595 > 300 seconds -- antoine@ILANTOUTSEUL.AGILEBUILD.COM

Dec 7 14:03:12 192.168.1.79 kdc[57]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ

Dec 7 14:03:12 192.168.1.79 kdc[57]: AS-REQ antoine@ILANTOUTSEUL.AGILEBUILD.COM from 192.168.1.71:49655 for krbtgt/ILANTOUTSEUL.AGILEBUILD.COM@ILANTOUTSEUL.AGILEBUILD.COM

Dec 7 14:03:12 --- last message repeated 1 time ---

Dec 7 14:03:12 192.168.1.79 kdc[57]: Client sent patypes: ENC-TS

Dec 7 14:03:12 192.168.1.79 kdc[57]: Too large time skew, client time 2014-12-07T13:53:17 is out by 595 > 300 seconds -- antoine@ILANTOUTSEUL.AGILEBUILD.COM

Dec 7 14:03:12 192.168.1.79 kdc[57]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ

Dec 7 14:03:12 192.168.1.79 kdc[57]: AS-REQ antoine@ILANTOUTSEUL.AGILEBUILD.COM from 127.0.0.1:52952 for krbtgt/ILANTOUTSEUL.AGILEBUILD.COM@ILANTOUTSEUL.AGILEBUILD.COM

Dec 7 14:03:12 --- last message repeated 1 time ---

Dec 7 14:03:12 192.168.1.79 kdc[57]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ

Dec 7 14:03:12 192.168.1.79 kdc[57]: AS-REQ antoine@ILANTOUTSEUL.AGILEBUILD.COM from 127.0.0.1:54789 for krbtgt/ILANTOUTSEUL.AGILEBUILD.COM@ILANTOUTSEUL.AGILEBUILD.COM

Dec 7 14:03:12 --- last message repeated 1 time ---

Dec 7 14:03:12 192.168.1.79 kdc[57]: Client sent patypes: ENC-TS

Dec 7 14:03:12 192.168.1.79 kdc[57]: ENC-TS pre-authentication succeeded -- antoine@ILANTOUTSEUL.AGILEBUILD.COM

Dec 7 14:03:12 192.168.1.79 kdc[57]: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, des3-cbc-sha1, arcfour-hmac-md5, using aes256-cts-hmac-sha1-96/aes256-cts-hmac-sha1-96

Dec 7 14:03:12 192.168.1.79 kdc[57]: Requested flags: forwardable

Dec 7 14:03:12 192.168.1.79 kdc[57]: TGS-REQ antoine@ILANTOUTSEUL.AGILEBUILD.COM from 127.0.0.1:49155 for host/192.168.1.79@ILANTOUTSEUL.AGILEBUILD.COM [canonicalize, forwardable]

Dec 7 14:03:12 192.168.1.79 kdc[57]: Searching referral for 192.168.1.79

Dec 7 14:03:12 192.168.1.79 kdc[57]: Server not found in database: krbtgt/168.1.79@ILANTOUTSEUL.AGILEBUILD.COM: no such entry found in hdb

Dec 7 14:03:12 192.168.1.79 kdc[57]: Failed building TGS-REP to 127.0.0.1:49155

Dec 7 14:03:12 192.168.1.79 kdc[57]: TGS-REQ antoine@ILANTOUTSEUL.AGILEBUILD.COM from 127.0.0.1:57454 for krbtgt/168.1.79@ILANTOUTSEUL.AGILEBUILD.COM [forwardable]

Posted on Dec 7, 2014 11:07 AM

Reply
6 replies

Dec 7, 2014 12:10 PM in response to antoinell

Hi Antoine,


According to this log at least the time between the server and client is off.


Dec 7 14:03:12 192.168.1.79 kdc[57]: Too large time skew, client time 2014-12-07T13:53:17 is out by 595 > 300 seconds -- antoine@ILANTOUTSEUL.AGILEBUILD.COM


Verify that both the client and the server have the same time, otherwise kerberos will not work.


Then open the terminal.app on your server and show us the output of:

sudo changeip -checkhostname

It will not change anything just give a reply about the hostname of your server.

That will give us more info on how to fix your problem.

Goodluck


Jeffrey

Dec 7, 2014 12:17 PM in response to jepping

Thanks Jeffrey.


I have changed the time on the server to be the same like on the Imac.


192:~ root# changeip -checkhostname


Primary address = 192.168.1.79


Current HostName = 192.168.1.79

DNS HostName = 192.168.1.79


The names match. There is nothing to change.

dirserv:success = "success"


Looks like my DNS host name is the IP address, that's not what I expected but changeip -checkhostname does not complain.

Dec 7, 2014 12:31 PM in response to antoinell

Good to see time has been fixed.


As for DNS, that doesn't look quite right. It should give you a FQDN name instead of an IP address.

What do you get when type "host 192.168.1.79" in the terminal.app?


It should give you a DNS address otherwise reverse dns isn't setup right.


Can you use command+K and fill in the IP address to get a connection? Can you login with your current credentials?

Dec 7, 2014 12:53 PM in response to jepping

192:~ root# host 192.168.1.79

79.1.168.192.in-addr.arpa domain name pointer 192.168.1.79.


I have tried command + K and entering as URL aftp://192.168.1.79 and I am also not able to login, the messages in /var/log/system.log are similar.


This gave me the idea to change the server name in the top pane of server app where it was showing 192.168.1.79. Trying to set it to ilantoutseul.agilebuild.com


Now I can connect in finder from the IMac to the server.


I still need to do some work to have my access for Imap and Smtp working again.

Dec 7, 2014 12:53 PM in response to antoinell

So there is no DNS running that is why kerberos is failing, it needs a FQDN.

Changing the servername or using the server.app to set a Fully Qualified Domain Name would be best.

So try to set up the hostname first.


At this time expect the worst, please make a backup/copy, this might take some time to get it right.

Export the OpenDirectory first, so you can go back to an earlier state when everything was still ok.

Select Open Directory and click on the gear box.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Mac OS X Server : cannot login

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.