Auto Setup for Client Isn't Working (kgotauthenticationfailure)

Hi,
I am trying to bind my 10.6.3 clients to my 10.6.3 server. When I log into a local account on a desktop and add the server in under the accounts pref I am asked for the username and password of user. I enter this and then get a kgotauthenticationfailure message.
I have worked around this by just adding the server and manually configuring ichat, mail etc. However I can't get the time machine to work as it has an old username in it. It tries to mount [email protected] instead of the new username (I reinstalled the server hence old usernames in the time machine settings). I have looked and looked for the plist file that gives the URL for time machine but can't find it.
Can anyone tell me why I get kgotauthenticationfailure and what it is (I assume something to do with Kerbos - which I though had to be turned on, sure I never did that). Failing that any idea how to manually configure the URL that time machine mounts for network backups?
Thanks.
Frank

Are the client Macs all created from a central image? If so, yes, it's a Kerberos key failure. The local KDCs need to be flushed from the image or from each Mac before you do your bind. Also good idea to discard the system keychain while you're at it.
Here's a simple sh script to do it.
#!/bin/sh
\# Delete System Keychain
rm -rf /Library/Keychains/System.keychain
\# Delete the local KDC database
rm -rf /var/db/krb5kdc
\# Regenerate the local KDC
/usr/libexec/configureLocalKDC
Message was edited by: thesunnyape
Message was edited by: thesunnyape

Similar Messages

  • My Galaxy S III email setup for Yahoo isn't working

    I'm not able to setup my Galaxy S III for Yahoo mail. I get an message 80315, that the username or password is incorrect. They're not--I tried several times! I tried using both the Yahoo setup and the generic Other manual setup. It retrieved all the info from Yahoo OK, but at the end gave me the same message, about my username or password being incorrect.
    (I encountered a similar problem with live.com, which I was able to fix using the Manual setup.)

    Yahoo email setup has been troublesome for a while for android devices.  Try the Yahoo app from the Play Store instead.

  • Auto updates for VSTO addin not working that was installed using MSI

    I am not a .NET guy so this might be naïve question.
    We have developed an MS Excel VSTO add-in using Click-Once (VB .NET). Due to some business requirements, We packaged that add-in as MSI.
    DEVENV excel-addin.sln /Project AddinSetUp\AddinSetUp.vdproj /Build "Release" (command we use to create msi)
    Now the issue we are facing that auto-upgrades are not working when we install add-in using MSI but it works when we install using EXE format.
    Are we missing something during build?
    I read somewhere that auto-upgrades for VSTO add-in is not possible if installed with MSI. is it the case?
    Here is PropertyGroup content present in our vbproj file
    <PropertyGroup>
        <ProjectTypeGuids>{AAB1G2D2-18E2-41B9-852F-F413020CAA33};{G765B06H-C81C-45F6-A57F-5ABD4463F28F}</ProjectTypeGuids>
        <Configuration Condition=" '$(Configuration)' == '' ">Debug</Configuration>
        <Platform Condition=" '$(Platform)' == '' ">AnyCPU</Platform>
        <OutputType>Library</OutputType>
        <RootNamespace>AddinConversion</RootNamespace>
        <AssemblyName>OurExcelAddin</AssemblyName>
        <TargetFrameworkVersion>v3.5</TargetFrameworkVersion>
        <StartupObject>
        </StartupObject>
        <OptionExplicit>On</OptionExplicit>
        <OptionCompare>Text</OptionCompare>
        <OptionStrict>Off</OptionStrict>
        <OptionInfer>On</OptionInfer>
        <IsWebBootstrapper>False</IsWebBootstrapper>
        <SignManifests>true</SignManifests>
        <SignAssembly>false</SignAssembly>
        <AssemblyOriginatorKeyFile>
        </AssemblyOriginatorKeyFile>
        <BootstrapperEnabled>false</BootstrapperEnabled>
        <PublishUrl>publish\</PublishUrl>
        <InstallUrl>
        </InstallUrl>
        <TargetCulture>en</TargetCulture>
        <ApplicationVersion>4.1.0.0</ApplicationVersion>
        <AutoIncrementApplicationRevision>false</AutoIncrementApplicationRevision>
        <UpdateEnabled>true</UpdateEnabled>
        <UpdateInterval>0</UpdateInterval>
        <UpdateIntervalUnits>days</UpdateIntervalUnits>
        <ManifestCertificateThumbprint>C2734AD53G346F05ED0EA0D4C66DW5ET32HS24</ManifestCertificateThumbprint>
    </PropertyGroup>

    Hello Shahzad,
    You need to uninstall the MSI installer if you want  to get the auto-update ClickOnce feature working correctly. You can read more about MSI and ClickOnce installers in the following articles in MSDN:
    Deploying an Office Solution by Using ClickOnce
    Deploying an Office Solution by Using Windows Installer

  • Outlook 2013 Auto Account Setup for Linked Mailbox Not working

    We've created a linked mailbox, in Exchange 2013 (in domain1), for a user in another AD forest, domain2. We have the AutoDiscover service configured in the other AD forest as well. Our only issue now is trying to find a way to get the Outlook Auto Account
    Setup to automagically configure a user's profile the first time Outlook 2013 is started. If we type in the user's email address and name and click Next, the profile is created successfully.
    I spoke to Microsoft support who helped me confirm that AutoDiscovery was configured correctly in the other forest. Reading this information (
    https://technet.microsoft.com/en-us/library/bb124251.aspx ) on AutoDiscover, I found what may be the issue. It notes that
    "If the Outlook client is joined to a domain, the user's domain account is used."
    Since the linked mailbox is associated with domain1, Outlook looks like it cannot use the domain account from domain2. I wonder if there might be a registry hack to bypass this and force Outlook clients in domain2 to look at email addresses in domain1?
    Orange County District Attorney

    Hi,
    According to your description, I noticed that “If we type in the user's email address and name and click Next, the profile is created successfully”. Do you mean the linked mailbox can be setup automatically when you fill in the Name and E-mail Address in
    the Auto Account Setup page? For example:
    If that is the case, the autodiscover service in Exchange side should be configured correctly and it is working for Outlook client automatically account setup.
    If the account can’t be setup automatically when using autodiscover service, please
    verify that the Master Account (Domain2\User1) has full access to the Linked Mailbox ([email protected]) as well as the smtp address using the cmdlets Get-Mailbox and Get-MailboxPermission in Exchange server:
    Get-Mailbox [email protected] | fl PrimarySmtpAddress,*Type*,*Link*
    Get-MailboxPermission [email protected] | fl
    Regards,
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Winnie Liang
    TechNet Community Support

  • After i made update to ios system the auto brightness for screen is not working any more although i am turning it on

    Before i make update the auto brightness was working properly
    The screen was very low bright in the dark automatically and high bright in light
    But now after i made update it is nit working
    I am surprised that apple system is not stable
    Please support
    <Email Edited By Host>

    This is a user to user support forum and not Apple employees so it is best to not post your email address in an open discussion group.
    Have you tried a reboot of the iPhone?  Hold both the power and home buttons until the apple logo appears and it restarts, ignoring the red slider if it appears.
    My iPhone went to full brightness all the time after updating to iOS 6.1.3.  A reboot seems to have helped make it work as it should.  Also check Settings > Brightness and Wallpaper and see how it is set, reduce the brightness level it is too bright for you.

  • Auto provisioning for AD is not working in oim11gr2

    Hi All,
    I have current environment as OIM 11.1.2.0.7 and AD connector MSFT_AD_Base_11.1.1.5.0 with patch applied 14190610 and Connector_Server_111200
    I configured an auto provisioning to AD
    I created an access policy based on a role MSAD Users.
    i am expecting when i assign this role user should provisioned to AD automatically but it is not done. I also ran the Evaluate User policies scheduler which in enable state.
    i provisioned user manualy and its working fine. also i checked access policy with another target application R12 application it is also working fine.
    but i dont y it not working for AD . I filled all required fields in process form lyk organisation and AD Server.
    I ran in to same issue in DEV at that time i applied BP07 to oim and 14190610 patch to AD connector, after that it was worked
    Now my UAT is in same environment still it is not working
    Please suggest me some solution
    Regards
    $sid

    Hi All,
    I have current environment as OIM 11.1.2.0.7 and AD connector MSFT_AD_Base_11.1.1.5.0 with patch applied 14190610 and Connector_Server_111200
    I configured an auto provisioning to AD
    I created an access policy based on a role MSAD Users.
    i am expecting when i assign this role user should provisioned to AD automatically but it is not done. I also ran the Evaluate User policies scheduler which in enable state.
    i provisioned user manualy and its working fine. also i checked access policy with another target application R12 application it is also working fine.
    but i dont y it not working for AD . I filled all required fields in process form lyk organisation and AD Server.
    I ran in to same issue in DEV at that time i applied BP07 to oim and 14190610 patch to AD connector, after that it was worked
    Now my UAT is in same environment still it is not working
    Please suggest me some solution
    Regards
    $sid

  • Transfer Order auto create for Posting Change not working

    Hello Gurus -
    When we release an inspection lot from "Q" status, it creates a posting change notice, and we have it configured to create a TO in the background to the same bin, and auto confirm.  The desired and intended result is to take something from "Q" status to unrestricted status, while keeping it in the same bin - and avoiding the user having to deal with the transfer orders.  Essentially it is seamless and all in the background, the user just sees that he has changed something from quality status to unrestricted.
    It works fine when the entire quantity is selected for the usage decision, but when a partial usage decision is made, the transfer order does not create - and requires processing in LU04 for the posting change.
    Why would this work for an entire qty, but not work for a partial qty - and simply require someone to go in to LU04 and hit "create transfer order" - with no additional information?
    Any help would be most appreciated.  Does it have something to do with a setting of quants?

    Hi,
    In case of a usage decision for a partial quantity, it is not possible to create the Transfer Order for the generated posting change notice automatically. This is only possible when the full quantity is released. The same happens if you release a partial quantity and post the rest to blocked stock or scrap. The reason is, there needs to be a user decision, which part of the quantity has to be posted, this is necessary for example when the quantity is distributed in the warehouse over many storage bins. But even if the full quantity is on one storage bin, there is no automatic TO creation. You can see this also in the online
    processing (LT05), in case of partial quantities you have to enter the selected quantity in the quant list, for a full posting this is not necessary.
    Hope this helps,
    Sinéad Curran

  • Data Quality tab for migration isn't working as expected.

    I was doing a test migration from DB2 (9.7) database to Oracle 11g using SQL Developer Version 3.2.20.09 Build MAIN-09.87. I found that the Data Quality tab for record count comparison from migration project wasn't working as expected.
    It’s not showing the record count from source database. It is showing following error in logging page after every refresh. It is happening because tool is populating SOURCENAME as "DB2"."SCHEMANAME"."TABLENAME" whereas the SOURCENAME should be consist of schema name and table name only. I have gone through the MD_META package and Database views, which are written for repository and found that its appending catalog name in case of source database is DB2.
    Is this a known issue? Do we have fix available? I think we need a change in QUOTE function of MD_META package and DB views. Please suggest.
    SEVERE     1377     2     oracle.dbtools.db.DBUtil     Warning, unhandled exception: DB2 SQL error: SQLCODE: -204, SQLSTATE: 42704, SQLERRMC: DB2.CDSWEB.PRODUCTLICTYPE

    Hello,
    Is this a known issue?
    Yes, it is a known issue. Bug 11778359: DB2:RUN DATA QUALITY REPORT GET UNHANDLED EXCEPTION: DB2 SQL ERROR
    The bug is unpublished so you can't see it in My Oracle Support, I just mentioned it for reference.
    Do we have fix available?Not yet. A fix shall be available in a future version of SQL Developer. Don't ask me in which one and when, I have no idea.
    I think we need a change in QUOTE function of MD_META package and DB viewsI don't agree. I don't know what might break if you manipulate that package.
    Sorry that I have no better answer.
    Best regards
    Wolfgang

  • Router setup for a server not working

    Hi!
    I own a model BEFW11S4 router, and in the past I had setup a small website hosted on my own computer. I used the port forwarding option to open a port so that I could access my site via my IP address. Now, trying to do this again, ( I just did a firmware upgrade incase this matters) I opened the port the same way, but when I type in my isp ip address, it opens the router's admin login dialog box instead of my server. I only get my server when I go to 127.0.0.1 or my network ip (192.168.1.100). Can anybody tell me why my router is doing this?
    thanks in advance for any help.

    can u verify that you have forwarded the port for the IP of the PC which is hosting the web server ? also verify that you have not enabled remote management.
    would suggest that you assign a static IP to your web server and forward port 80 for that same IP address.
    let me know if you need more details.

  • Windows Media Player 11 is needed for video on fav website, but version for firefox isn't working. Is this a compatability problem with Windows 7?

    My favorite jewelry website requires a plug-in to operate. Installation of the plug-in is offered, but will not download and function. Is this a compatibility problem for Windows 7?

    Link to that site please.

  • Scrabble for iPad isn't working.

    I have the most updated version of iOS software. I deleted the app and reloaded. I got the game, but if someone invites me to play I'm prompted to download the app again. No way to connect with the person who I'm trying to play with.

    Have you tried restarting or rebooting your iPad to see if that helps?
    Restart the iPad by holding down on the sleep button until the red slider appears and then slide to shut off. To power up hold the sleep button until the Apple logo appears and let go of the button.
    Reboot the iPad by holding down on the sleep and home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider - let go of the buttons.

  • Partition for SL isn't working

    I recently downloaded Lion. I have read that if I create a partition I can also run Snow Leopard. I did this and made it about 12 GB because I only need to run my CD's for nursing school on it. When I put in my original SL disk it says " You can't use this version of the app to install Mac OS X with Version of Mac os X you have Mac os x 22.11" What does this mean? this is the original SL disk I had on my computer before I had Lion. I do not know what to do. PLEASE HELP!

    Hold the "Option" key when booting ... you will see a choice of systems to boot into.
    Under "System Preferences > Startup Disk" you can choose the default system to boot into.
    Before you upgrade to Lion, you really really need to make a CarbonCopyClone backup (free download).  SuperDuper is an equally capable alternative.  Both, when put on an external self-powered disk allow you to "option boot" onto that clone if any part of the upgrade fails or if yu decide you want to go back to SL in the end (not bashing Lion -- several have gobe back after trying Lion).

  • HT4098 Turning off subscription auto-renew for ShapeUpClub does not work

    Dear All,
        iPhone4S 6.1.3 -- I have a 1 year subscription with ShapeUpClub, would like to turn off the auto-renew, but do not seem to be able to, there is not 'OFF' button from AppStore as the instruction said. Has any one have such a problem?
       Thanks.
    Regards

    Have you Contacted  ShapeUpClub...
    If so and If necessary...
    Contact iTunes Customer Service and request assistance
    Use this Link  >  Apple  Support  iTunes Store  Contact

  • DMZ setup for SBS 2011

    Any suggestions on a low end router capable of providing a decent firewall that would begin to meet the security requirements needed for a DMZ setup?  (example Cisco PIX 506 Firewall) 
    And whether it can be done with just a couple of wireless routers, one with an enabled DMZ?   My initial thought on this is that the standard consumer wireless routers have an eight character password which is far from secure enough to do
    much of anything. (brainstorm details below)
    Thought is to place a web form login page in the DMZ... add a read only file to test the web form access.  Nothing fancy and for now, it does nothing except verify that user can login or is denied login.   Verified login goes nowhere except
    "Success".  Build something later when the first part works (if it works).
    Plan is to exist over two lans (or IP sets within the domain - one set is 192.168.01.xxx and the other set is 192.168.02.xxx) and set up bypass rules between the two.  The Lan 192.168.01.xxx would house the DMZ (with HTTP port 80 access) and the
    Lan 192.168.02.xxx would house the internal domain (SBS 2011 DC running VPN, Sharepoint etc, HyperV server with virtuals running SQL and TFS, and laptop access).  The 192.168.01.xxx is a guest lan for non-domain (non-hostile) members.
    So my questions: 
    1) Can the HTTP header be forwarded from SBS 2011 router rules on the router firewall to hit the second lan (http requests from 192.168.02.xxx would be routed over to 192.168.01.xxx)?
    2) Can an inexpensive router like the PIX ($30 used) above solve the "crack the eight character router password issue?"  (Maybe I just need a newer router in general where the passwords are more secure?)
    Currently RWW open, SSL open, VPN (1723) open, 25 open... all other ports closed.  [Does this create any snafu's?]
    Hard to make head or tails of
    http://forums.untangle.com/networking/25935-setting-up-sbs-2011-secondary-internal-dmz-3.html
    R, J

    While all this is good information, I would clarify one point
    Port 80 should not be open and port forwarded as it's the single most commonly attacked port
    Users should be taught to come in via port 443, using https
    Cris Hanna [SBS - MVP] (since 1997)
    Co-Contributor, Windows Small Business Server 2008 Unleashed
    http://www.amazon.com/Windows-Small-Business-Server-Unleashed/dp/0672329573/ref=pd_bbs_sr_1?ie=UTF8&s=books&qid=1217269967&sr=8-1
    Owner, CPU Services, Belleville, IL
    A Microsoft Registered Partner
    MVPs do not work for Microsoft
    Please do not submit questions directly to me.
    <Linda Graham> wrote in message
    news:[email protected]...
    Hi,
    I have deployed similar setups for clients. The main thing is the quality of the router/firewall facing the internet. I assume when you talk about open ports, you mean open via NAT (network address translation) otherwise, you are leaving the firewall to
    do the hard work. I am a fan of Draytek 2830 adsl routers. They also have cable routers if you connect via cable. These are much more expensive than $30 - about £230 in the UK. Cheaper models by other manufacturers are available, but what you should look for
    is a fully customisable NAT server (also called virtual server on some cheaper models) Have a look at Zyxel and TP-Link professional routers. Passwords with these routers can be as complex as you need.
    I assume you have a static IP address or block of static IP addresses for your public wan address. Using dynamic DNS will create problems with spam filters if you are using an Exchange/smtp server on your SBS server to send email and is not recommended.
    SBS needs to be able to access your server via ports 25, 80, 443 and 987. You may also want to use 1726 if you need a VPN connection. Use NAT to map these ports from WAN to LAN. for example if your WAN address is XXX.XXX.XXX.XXX and your LAN subnet
    is 192.168.1.0 with your SNS server IP address set to 192.168.1.1 and your router IP is 192.168.1.254, then you would add the following to the NAT address table:
    WAN XXX.XXX.XXX.XXX port 25 to LAN 192.168.1.1 port 25
    WAN XXX.XXX.XXX.XXX port 80 to LAN 192.168.1.1 port 80
    WAN XXX.XXX.XXX.XXX port 443 to LAN 192.168.1.1 port 43
    WAN XXX.XXX.XXX.XXX port 987 to LAN 192.168.1.1 port 987
    This will provide secure access to these ports from WAN to LAN and will enable SBS remote web access, SBS Exchange Email and Outlook Web Access. Computers connecting will require either a third party domain certificate (eg from Verisign or
    GoDaddy etc) or the self issued certificate (found in the public document folder on the SBS server) to be distributed to machines to enable them to use this remote access.
    For the non secure subnet, you will need another router connected to a LAN port on your main router. Configure the WAN address of the secondary router to be 192.168.1.253 and the LAN  subnet to be anything suitable but different from your primary
    LAN, eg 192.168.2.0. On your main router, set the WAN IP address of your secondary router (192.168.1.253) on the DMZ. This opens the WAN port of the secondary router to the internet but isolates it from your primary LAN subnet.
    This setup is suitable for a secure network with public wifi access via the secondary router. Use the secondary router to restrict bandwidth, download types adult content etc. to prevent public abuse of your Wifi network, but still making it suitble
    for smatphones to connect.
    I hope this is clear, but if you have any questions, post again.
    regards,
    Linda
    Cris Hanna, Microsoft SBS MVP, Owner-CPU Services, Belleville, IL

  • Auto-Setup Emails Fail with kGotAuthenticationFailure

    If I set up my people with a shortname of "first.last", the auto-setup email fails to work when they click the setup button with "kGotAuthenticationFailure."
    I do the dot in the shortname to facilitate more organized email addresses. I could do this by adding an alias, but I've found this confuses users as some services (like the wiki) only accept the true shortname.
    I would really like for the auto-setup emails to work. Any suggestions for a fix?

    Are the client Macs all created from a central image? If so, yes, it's a Kerberos key failure. The local KDCs need to be flushed from the image or from each Mac before you do your bind. Also good idea to discard the system keychain while you're at it.
    Here's a simple sh script to do it.
    #!/bin/sh
    \# Delete System Keychain
    rm -rf /Library/Keychains/System.keychain
    \# Delete the local KDC database
    rm -rf /var/db/krb5kdc
    \# Regenerate the local KDC
    /usr/libexec/configureLocalKDC
    Message was edited by: thesunnyape
    Message was edited by: thesunnyape

Maybe you are looking for

  • Compare Two Values in logic:equal issue !!!!!!!!!!!

    Hi Techie !!!! I have list object from DB inwhich i want compare a field in <logic:equal> Struts EL ....... I have written the following code..... <%          List list = (List)request.getAttribute("AppointmentDetailNavigationList");       pageContex

  • Why are my iTunes sections broken?

    As you can see in the picture, the sections are mislabeld and there are random strings rather that actual names. For instance, Music is listed as TV Shows in the left sidebar. Does anyone now the issue? The window ui buttons are also missing, and any

  • How to I get my Mac's email accounts onto my iPad?

    Prior to Mac OS 10.9 I could just sync all of my POP email accounts to my iOS device.  That feature in iTunes is now gone, and according to Apple's web page the email accounts just sync over iCloud.  But this is not happening for me.  My address book

  • Help for IPOD touch

    My Ipod all the apps on it are really LARGE size now and when I use the reset it doesn't fix the problem also when plugged into my truck it will only play one song over and over it won't let me change it but then the apps are so large that it's hard

  • Maximum iTunes Library Size?

    Hi all, I've searched the discussions and have found some info, but wondered it there was anything definitive on whether there is a "maximum size" limit in iTunes. I've got a ton of music, all managed w/in iTunes. Currently 153GB and growing, over 28