10.3.9 Kerberos hand cranked : PASSWORD INCORRECT

After a long newbie ride of AFP548 handcranking Kerberos & Kadmin I now do recieve tickets for kadmin/admin@REALM and root@REALM - trying all other princs turns back: Password Incorrect.
My dns log has no complains.
How do I turn all my users and their advanced passwords into the Kerberos? ktadd and cpw from kadmin doesn't seem to help.
Best regards Ole

Thank you for help Leland ! Here's a few questions
more. Hope you can answer them some time.
Still I recieve tickets using kinit in the terminal
or the GUI Kerberos Application.
Mail application brings up the kerberos login window
- but I cant auth.
If you do a klist after the failure, are you getting a service ticket for the mail server?
pop, smtp, or imap?
When I try to connect with AFP I get a message that a
system error occoured.
Using WGM to : change user passwordtype to crypt-give
a new password-save-refresh the screen-change back to
open directorytype-type new password-save
works! After this procedure kadmin :
getprincs shows that a princ for the user is added.
Is there some steps in this procedure that is not
needed ?
Not that I know of.
I haven't found the slapconfig way to bring users to
princs.
slapconfig kerberize should (according to the man page) create the proper principals.
I have huntch that my attributes for some of the the
princs are wrong ?
Are these attributes functionally :
normal-user-shortname@REALM has REQUIRESPREAUTH
all the service principals/realm@REALM has no
attributes
kadmin/admin@REALM has DISALLOWTGTBASED
krbtgt/REALM@REALM hos no attributes
kadmin/changepw@REALM has DISALLOWTGTBASED
PWCHANGE_SERVICE
Those all look ok.
My POSTFIX main.cf has :
smtpdsasl_localdomain = REALM
smtpdrecipientrestrictions =
permitsasl_authenticated,permit_mynetworks,rejectuna
uth_destination,permit
smtpdpw_server_securityoptions = cram-md5,gssapi
smtp_principal = smtp/realm@REALM
smtpdclientrestrictions =
permitsasl_authenticated,permit_mynetworks,rejectrbl
_client sbl-xbl.spamhaus.org,rejectrblclient
relays.ordb.org,rejectmapsrbl,permit
mtpdhelorequired = yes
smtpdtls_certfile = /etc/postfix/server.pem
smtpdtls_keyfile = /etc/postfix/server.pem
smtpdtlsCAfile = /etc/certs/demoCA/cacert.pem
smtpdtls_askccert = yes
smtpdtls_receivedheader = yes
smtpdtls_session_cachetimeout = 3600s
smtpdtlsloglevel = 2
smtpsasl_authenable = yes
smtpusetls = yes
smtptls_note_starttlsoffer = yes
enableserveroptions = yes
Are these postfix setting OK for kerberos ?
I'll have to ask around. Look in /etc/MailServicesOther.plist and see if the
following keys contain the correct info:
smtp_principal, imap_principal, pop_principal.
I don't know where entrys for
pop/realm@REALM
imap/realm@REALM
should be placed?
they should be pop/fqdn@REALM (though the fully qualified domain name could be the same as the realm)
Hope this helps
- Leland

Similar Messages

  • I have updated my iOS and now my hotmail will not verify my password through apple mail app.  I have reset password - tried new password and old password and it still gives me password incorrect.  Hotmail works fine on Mac.  Has anyone had this difficulty

    I have updated my iOS and now my hotmail will not verify my password through apple mail app.  I have reset password - tried new password and old password and it still gives me password incorrect.  Hotmail works fine on Mac.  Has anyone had this difficulty and been able to resolve it?

    Did you try deleting the mail account, then adding it back?   I've read a lot of times that is what needs to happen in order for it to work properly.

  • I upgraded my 4s to 7.0.4 and now I can't access hotmail through my main mail app. When I open it a pop up says password incorrect even after I put my password in it pops up again. How do I fix this please help

    I upgraded my 4s to 7.0.4 and now I can't acicess hotmail through my main mail app. When I open it a pop up says password incorrect even after I put my password in it pops up again. How do I fix this please help

    After I upgraded to Mavericks I was also having this message when I tried to update. There was a previous post about this problem which offered this simple solution which worked for me:
    b0n0b0
    Re: Recently upgraded to Maverick from SnowLeopard. Unable to get updates from App store.
    Mar 15, 2014 9:05 AM (in response to Terence Devlin)
    Got it! Thanx.  What I did was go to my account, check that they had my new ID and Password which they did, then hit reset button. All fixed.

  • I'm trying to connect to my home wifi with my imac gh5. After I enter the password it says connection timeout or password incorrect. I know there's no issue with the connection but I don't know what else to do. Does anyone know how to fix this problem?

    I'm trying to connect to my home wifi with my imac gh5. After I enter the password it says connection timeout or password incorrect. I know there's no issue with the connection but I don't know what else to do. Does anyone know how to fix this problem?

    What is the make & model of your home Wi-Fi router that you are attempting to connect your G5 iMac to? Which exact model of iMac do you have?
    What wireless security type is your router using: WEP, WPA, or WPA2? If you temporarily disable wireless security, can the iMac connect to it now?

  • Password incorrect. i dont have a password?

    hi i just got the 8gb iphone an hour ago and already ive been having problems. when i press the phone icon a screen pops up and says password incorrect. well i havent set a password and when i try to it says old password incorrect. how do i get rid of my voicemail password or how do i reset it. thats my first and my second one is when ppl call me i cant hear it even though the ringer is on and the volume is up i randomly pick my phone up and the screen says incoming call and when i go to answer it is already too late.

    hey thanks for the response i just posted this like 5sec ago. i recently posted that my 4gb iphone had a touchscreen deadzone u guys told me to bring it to apple they replaced it and gave me the 8gb model and i just brought it home and my friends said that they called my phone but it went to my voicemail and it didnt ring. then i noticed when i touch the phone icon a screen would pop up and say voicemail password incorrect type password and i would just press cancel and it would go away. but everytime i would press the phone icon that **** screen would pop up

  • 1st Generation iphone, 2.1 iPhone OS and password incorrect exchange prompt

    I have a 1st generation (non 3G) phone and I upgraded to 2.1 (5F136) recently. Dont exactly remember when I upgraded the OS. All of a sudden, I am getting password incorrect exchange prompts. What the **** is happening? The password is correct and I enter it and can send/get email. But I have to do this like 10 times in a day. Unbelievable!
    Where is this amnesia coming out of? Is this a known bug? Any known fixes? Have rebooted enough number of times. This is happening when I am on my wi-fi as well continuously. My gmail account is just fine. Whats going on Apple?

    I have seen this with misconfigured Exchange/IIS ActiveSync setups on the server side. Have you checked with your exchange peeps to see if they changed anything?

  • Hotmail Password Incorrect - nothing works!  dang it!

    Hi,
    Looking for help after updating an iPod to iTunes 10.5.  Hotmail email account no longer works. 
    I have deleted the email account on the iPod and tried to re-establish the Hotmail account in the Add Account section using 3 methods: Microsoft Exchange, Windows Live Hotmail, and Other.  In all three cases, I received the "Password Incorrect" error message.
    I have also reset my Hotmail password on desktop computer, and this didn't change anything. 
    I also wiped & restored the iPod in an attempt to start from scratch, but still got the same error message.
    Not sure what else to try since I'm getting same error message using every conceivable way to establish the Hotmail account on my iPod.  Again, it worked perfectly prior to recent 10.5 update. 
    Also, fyi, haven't been able to establish my iCloud account yet, either, which may be related to this as well?  not sure. 
    Thanks in advance for specific recommendations (beyond the methods I've already tried).  Thanks!!!!!!!!!!

    Hi, just to clarify, the iPod was recently updated, now running iOS 5.0

  • Username and/or password incorrect

    hi all, im new here this is my first post, i have a nokia 6720 Classic on Telstra (Next G) whenever i trry to log into the Ovi Store on my mobile i receive "Username and/or password incorrect" i have registered and can log into Ovi on the internet with my details no problems whatsoever, can anyone help???
    cheers
    Daren

    Same thing happening to me and changed my bb I'd thinking that would help but now am locked out. I took out my media card as to not lose pics... But now what?

  • I sign out of my imessage and i tried logging back in and it keeps saying my password incorrect but i know for a fact im using my right password i dont what to do its just not letting me log in

    I sign out of my imessage and i tried logging back in and it keeps saying my password incorrect but i know for a fact im using my right password i dont what to do its just not letting me log in

    Updating Snow Leopard won't help.  You need to Upgrade OS X to Lion or higher if your system will support it.  First check to see if your system meets the system requirements to upgrade.
    Lion system requirements are:
    Mac computer with an Intel Core 2 Duo, Core i3, Core i5, Core i7, or Xeon processor
    2GB of memory
    OS X v10.6.6 or later (v10.6.8 recommended)
    7GB of available space
    Mountain Lion and Mavericks requirements are the same, and are shown here: http://support.apple.com/kb/HT5842.
    If you can run Mavericks, you can download a free upgrade from the Mac App Store.  If your system can only run Lion, or you need Mountain Lion rather than Mavericks for software compatibility reasons, youcan contact the online store at the number shown at the bottom of this page and purchase a redemption code to download it from the Mac App Store.
    After upgrading, you will find iCloud in System Preferences>iCloud on your Mac, and can set it up as explained here: http://www.apple.com/icloud/setup/mac.html.
    Before upgrading, you should be aware that PPC programs such as AppleWorks will not run on Lion or above.  You may want to check the compatibility of your existing programs by checking here: http://roaringapps.com/apps:table.

  • Emails - "Password Incorrect" keeps popping up - never had to enter password before for exchange account, Emails - "Password Incorrect" keeps popping up - never had to enter password before for exchange account

    When I go into Mail "Password Incorrect"  for exchange account pops up.  Never had to put in this password before. How do I get rid of this?

    Go to iforgot.apple.com to recover the password for the Apple ID.

  • Password incorrect -exchange account.

    I have tryed to sing in to my ipad2 and cannot sign in so cannot get to my settings , mail, or anything. I have a box that shows password incorrect. Says to enter the password for the Exchange Account"hotmail".
    I do not understand this as before I could always sign in with my password with no problems. How do I solve this. I do not have an iphone. My ipad is the last version befoe the newest came out.
    Robin

    This may help - I won't be able to try it until after work though
    http://support.apple.com/kb/DL1358
    Multiple bug fixes including:
    • Resolves an issue authenticating with some enterprise web services

  • Error message when uploading to youtube..password incorrect?

    trying to upload a video from imovie to youtube and I get an error message "username or password is incorrect".  I have reset my password in youtube but still get this message.  How do I clear it and reset it in imovie or quicktime?
    Youtube have recently changed to google..  the movie is shorter than 10mins also...   cant figure out how to change/check the youtube password in imovie..
    thanks in advance of your help..

    Thank you -   that is what I have been doing.  I dont know what has changed, but I get that error message - username and password incorrect.      Where else are the settings in Imovie or Quicktime - so that I can check or change the password there.   
    I have entered my gmail account -  and deleted it .. and reentered it  - but it still doesnt work.    Ive even been into my gmail and youtube settings and made sure they were both the same...
    and still it doesnt work....   
    its particularly frustrating because it always used to work and was so simple.
    Any other tips or clues.

  • Apple ID Not found/Password incorrect

    Hiya,
    I am constantly receiving an error when I try to login to the app store/ itunes. I can access my account online so my password isn't incorrect. I have reset it nevertheless but still I continue to receive the 'Apple ID Not found/Password Incorrect' error.
    I was wondering if anybody else has had such problems?
    Thanks in advance!

    Ahh, so it isn't just me? I had asked a few friends to check and they say that they have been able to login successfully. Perhaps it's an internal error. Thank you for replying
    Edit:
    Yes, I am putting the correct Apple ID in. It was working up until 5 minutes ago. I can login on the Apple website fine but not via my iTunes, app store or the iTunes on my iPhone and iPad

  • Anywhere Access - CERTIFICATE NOT VALID OR PASSWORD INCORRECT

    Setting up Server Essentials 2012.  During the "Anywhere Access" wizard I followed a link to get an SSL for the company's URL that is directed at the server.  I chose one of the two options that was presented during setup and purchased a "SSL
    Cert for SSL Certificate - Comodo Essential" from Enom Inc.
    Once I got the certificate in email, and continued the wizard I get the following error:
    CERTIFICATE NOT VALID OR PASSWORD INCORRECT
    Either the certificate is not supported or the password is incorrect.  Please try again.
    I've tried everything I can to get it in the wizard to no avail.  If I manually push it into the certificate manager it accepts it there properly but the Essentials Dashboard still thinks it's no installed so I believe I have to complete this wizard.  I
    cannot find ANY support on this currently on the internet on searching.  Anyone able to help?
    (By chance the server is also unable to install two critical updates.  I am taking things one at a time in the order they come right now though.)
    KevenD.

    The PFX file is only allowed in the wizard if you are importing a previously created SSL.  Here's the steps that got me to the dead end I'm in:
    Step 1 - Setup process - Set up Anywhere Access
    Step 2 – It asks what domain name we have pointing to the server, configures the firewall routing services etc and then gets to the SSL portion which I will depict below.
    Step 3 – Domain Set up in the Anywhere Access wizard: Entering name of our domain to use.
    Step 4 – SSL Certificate set up.  I select “I want to purchase..”, clicked on the two links provided, decided on one from eNomCentral and made the purchase.
    Step 5 – Cert request is issued and a link to GoDaddy and eNomCentral are given.  It was eNomCentral which sold me on the Comodo SSL.
    Step 6 – Park and wait. 
    The next time I go into the wizard to continue (once the certificate was issued) I get the errors I earlier depicted from the wizard stating:
    CERTIFICATE NOT VALID OR PASSWORD INCORRECT
    Either the certificate is not supported or the password is incorrect.  Please try again.
    I get two methods of importing it, copy/paste or upload.  I've tried both methods and each generates a different error.
    KevenD.

  • HT5622 When I try to download an app from app store, it is asking for Cloud ID and Password.....but though i submitted correct password...it is not allowing to download....stating "Password incorrect". What is the way out...!!

    Suggest a way out for download an app, when phone shows a message-----password incorrect; though i gave correct password. Even i have logged into icloud and ensured the password is correct.

    You may have to either sign in to the website to confirm your account details (or do that through iTunes on the computer) or go to iforgot.apple.com to reset your password again.

Maybe you are looking for

  • Which camcorder is compatible without the need to render?

    Hi there, just swapped from PC to Apple, and just like a few other posts on here I am having problems in deciding which camcorder to buy to use with FCE4, I am ideally looking for a budget camera prefer SD/HC or HDD with a max price about £300. I hav

  • Deleting Record from Database in PHP

    I'm trying to figure out how to delete a record from my database. I already have a recordset with my form selected. But when I try to add "Delete Record," I can never seem to figure out why it won't delete anything when I load the page in a browser,

  • Will an iPod Touch work with the iPod Hi Fi???

    Hi I want to upgrade my iPod Classic to an iPod Touch and was wondering if the Touch will work okay with the Hi Fi??? Thanks.

  • Faces is now a per-Library setting

    According to this KB article: Faces In Aperture, it is possible to turn off faces on a per-library basis. I'm still seeing the old preferences checkbox, but having turned it off in one Library and opened another, the checkbox was checked.  So apparen

  • Dual WAN and Log mail SMTP on RV082 ?

    I use a RV082 with dual Wan and I cannot configure two SMTP. Without authentication; a SMTP is specific of the provider. When WAN1 comes down, SMTP to be used is the SMTP corresponding to WAN2 and vice versa. Implementation of authentication with the