Can login, but can't get Kerberos ticket

Hi,
This is on OS X Server 10.5.8, all up to date, and an OS X Client 10.6.4, all up to date.
One user in particular can login, however they can't get a kerberos ticket (iChat and other apps fail to login). They can use the Ticket Viewer app to see that there is no ticket, but then add an identity manually and it all works fine.
If I change the password via Workgroup Manager they can login with that new password. I also ticked "change password at next login", however the client didn't pick that up (although they logged in with the new password).
Also, when trying to change the password via System Prefs, it says the old (current) password is incorrect, even though its the same as they logged on with.
I'm pretty sure the problems are to do with the Kerberos login check failing (as seen in the log below) - but why would the user be able to login, yet fail the kerberos authentication check?
Output from password server log:
Nov 2 2010 10:24:52 RSAVALIDATE: success.
Nov 2 2010 10:24:52 AUTH2: {0x46ac8ee739c0ff000000000e0000000e, nhankey} DHX authentication succeeded.
Nov 2 2010 10:24:52 KERBEROS-LOGIN-CHECK: user {0x46ac8ee739c0ff000000000e0000000e, nhankey} authentication failed.
Nov 2 2010 10:24:52 GETPOLICY: user {0x46ac8ee739c0ff000000000e0000000e, nhankey}.
Nov 2 2010 10:24:52 GETPOLICY: user {0x46ac8ee739c0ff000000000e0000000e, nhankey}.
Nov 2 2010 10:24:55 RSAVALIDATE: success.
Nov 2 2010 10:24:55 AUTH2: {0x46ac8ee739c0ff000000000e0000000e, nhankey} DIGEST-MD5 authentication succeeded.
Nov 2 2010 10:24:56 RSAVALIDATE: success.
Nov 2 2010 10:24:56 AUTH2: {0x46ac8ee739c0ff000000000e0000000e, nhankey} DHX authentication succeeded.
Nov 2 2010 10:24:56 KERBEROS-LOGIN-CHECK: user {0x46ac8ee739c0ff000000000e0000000e, nhankey} authentication failed.
Nov 2 2010 10:24:56 RSAVALIDATE: success.
Nov 2 2010 10:24:56 AUTH2: {0x46ac8ee739c0ff000000000e0000000e, nhankey} DHX authentication succeeded.
Nov 2 2010 10:24:56 KERBEROS-LOGIN-CHECK: user {0x46ac8ee739c0ff000000000e0000000e, nhankey} authentication failed.
Is there a way to see which tickets have been issued on the server?
Thanks for any help.
Regards,
Steve

... bump ...

Similar Messages

  • My password is not workin i can login but i cant get updates...

    suddenly my passwork it seems like broke i login in the account no problem and when i want to get updates or download a new program and require my password not let me do it says check again... whats going on i change password and it let me do but when i go to perform something requires no let me do what should i do please help/___sbsstatic___/migration-images/migration-img-not-avail.png

    OK, Could be many things, we should start with this...
    "Try Disk Utility
    1. Insert the Mac OS X Tiger Install disc that came with your computer, then restart the computer while holding the C key.
    2. When your computer finishes starting up from the disc, choose Disk Utility from the Installer menu. (In Mac OS X 10.4 or later, you must select your language first.)
    Important: Do not click Continue in the first screen of the Installer. If you do, you must restart from the disc again to access Disk Utility.
    3. Click the First Aid tab.
    4. Select your Mac OS X volume.
    5. Click Repair. Disk Utility checks and repairs the disk."
    http://docs.info.apple.com/article.html?artnum=106214
    Then try a Safe Boot, (holding Shift key down at bootup), run Disk Utility in Applications>Utilities, then highlight your drive, click on Repair Permissions, reboot when it completes.
    (Safe boot may stay on the gray radian for a long time, let it go, it's trying to repair the Hard Drive.)
    If that doesn't fix it then this might sound scary, but I think we have to do it...
    Reset OS X Password Without an OS X CD...
    http://theappleblog.com/2008/06/22/reset-os-x-password-without-an-os-x-cd/
    Admin Hack...
    http://www.hackmac.org/?q=node/4
    Starts up like the first time you buy a new Mac, but after filling in all that info again, you should have access to the computer and the other Users & files will still be there... give the new User a different name than an existing one.

  • Before, when reading PDF files, I was able to copy and paste part of the book. Now it is not possible. I can copy but when pasting gets nothing.  Antes, quando lia arquivos PDF, eu conseguia copiar e colar parte do livro. Agora isso não é possível.

    Before, when reading PDF files, I was able to copy and paste part of the book. Now it is not possible. I can copy but when pasting gets nothing.
    Antes, quando lia arquivos PDF, eu conseguia copiar e colar parte do livro. Agora isso não é possível. Eu consigo copiar, mas quando vou colar o texto, não cola nada.

    Caro Fabiano,
    Obrigado por ter contactado as Comunidades de Suporte Apple.
    Na origem do seu problema podem estar várias causas. Nomeadamente:
    O ficheiro (arquivo) que está a ler pode não ser texto, ou seja, pode ser texto transformado em imagem e exportado como PDF.
    A aplicação de destino (onde está a tentar colar o texto copiado) pode não aceitar a colagem de texto formatado.
    A aplicação que está a utilizar para abrir os ficheiros PDF pode não ser indicada para certo tipo de documentos. Experimente o iBooks, o Dropbox ou até mesmo o seu e-mail.
    No caso de nenhuma destas causas estar na origem do seu problema, forneça, por favor, mais informações sobre a origem do ficheiro (descarga pelo Safari, Mail ou outro) bem como o destino (documento Pages, Keynote ou Numbers ou outra aplicação que não o iWork).
    Atentamente,
    Gonçalo Matos
    Estou aqui para ajudar. Clique no botão "Reply" no caso de ter outra questão ou necessitar de outro esclarecimento para que eu possa ajudar da melhor forma que conseguir.

  • How can I tell how many licenses are included in a volume license?  I can login, but am unable to see the number included, just says purchased "1", but not the amount in the volume.

    How can I tell how many licenses are included in a volume license?  I can login, but am unable to see the number included, just says purchased "1", but not the amount in the volume.

    Hi networka,
    Please see this page for links to the resources you can use to manage a volume license: Customer resources | Adobe Buying Programs. You should be able to find this information by logging in to the Licensing Website.
    Best,
    Sara

  • He 19 2113 I can login but screen is blank

    I've tried restarting/rebooting f10 and f8 and f5 saving changes restoring defaults and nothing works. I can login but the screen is blank.

    Hello @susie528,
    I understand that when you start your HP 19-2113w All-in-One Desktop PC running Windows 8.1 it is to a blank screen. I am providing you with an HP Support document: Computer Starts but Monitor Remains Blank (Windows 8), which has been designed to address the issue you are describing. I would suggest you review the document and apply the steps set out within.
    I hope I have answered your question to your satisfaction. Thank you for posting on the HP Forums. Have a great day!
    Please click the "Thumbs Up" on the bottom right of this post to say thank you if you appreciate the support I provide!
    Also be sure to mark my post as “Accept as Solution" if you feel my post solved your issue, it will help others who face the same challenge find the same solution.
    Dunidar
    I work on behalf of HP
    Find out a bit more about me by checking out my profile!
    "Customers don’t expect you to be perfect. They do expect you to fix things when they go wrong." ~ Donald Porter

  • I just hooked up my Canon MP830 printer/scanner/fax to my MAC and can print but can't scan.  Anyone out there know what to do with this?

    I just hooked up my Canon MP830 printer/scanner/fax to my MAC and can print but can't scan.  Anyone out there know what to do with this?

    Have you downloaded the approriate Snow Leopard drivers for that printer? Make sure you get the appropriate and latest MP Navigator, as you start scans from the computer, not the all-in-one.  Get them from http://www.usa.canon.com/cusa/support/consumer/printers_multifunction/pixma_mp_s eries/pixma_mp830#DriversAndSoftware

  • I can receive but can't send email

    I can receive but can't send e-mail, my phone keeps asking me to set up a password for outgoing mail but I have done that and still nothing happens.

    try powering it off for a min and then power back on and see if it works.  If not take a look here
    http://support.apple.com/kb/TS3899

  • I can login but doesnt show any of my music

    Having trouble here ....i recently received a new note 4 phone because my 2month phone over heated & died so now im trying to load all apps & started with my spotify app,well im login & shows im login but no music none of my music.Im stuck here can anyone help me out here....thank you

    Hi g30marquez. When you logged into your new phone, are you certain that you used the exact same login details as on your old device? Sometimes people have duplicate accounts, and it's possible that you accidentally signed into a second account as opposed to your primary. Do the songs still appear on the desktop client or the web player? If they do and it's just your phone that isn't displaying anything, then I'm going to assume that it's most likely that you've simply signed into the wrong account.
    If that doesn't quite solve the issue, let me know and I'll happily do some more digging to help get this solved. Cheers!

  • Can login but I am not premium on iphone

    Hi  I can login on computer and play music with my premium account but when I login on my iphone, it's not premium so I can not play music. I try my two iphone, both did not work. I deleted the app, log out and login for several times, still the same. Can anyone help with this?Thanks!!

    Please, try one more time to log out, and login with the same username you use in the web.
    If you're still having troubles, please, contact with Spotify Consumer Support filling this contact form.
    If you receive an automated email that leads you back to the community or help pages, reply to it (even if it's from "no-reply") and one of the Spotify team members will get back to you as soon as possible.
    Don't forget to check your Spam Box ;)

  • Can receive but can't send yahoo.co.uk email

    I have tried multiple steps to reconfigure my outgoing email set up for yahoo.co.uk. the server is smtp.mail.co.uk. correct password is entered and i have even specified port 587. unfortunately i am unable to send via this email server. this is from my wifes account. my yahoo email works on my account fine.
    any ideas

    As far as I know, you can only send emails via a third party client (i.e Apple Mail, Thunderbird, Entourage, etc...) if you upgrade your account to Yahoo Mail Plus as we had the same problem a year or so ago.
    Yahoo Plus is $11.00 per year - is it worth it? er...no. Trying to persuade my wife to go to Gmail, but alas the lady is not for turning...so, get your Visa card out and then pop in these settings into Mail:
    Incoming Mail (POP3) Server: plus.pop.mail.yahoo.com (Use SSL, port: 995)
    Outgoing Mail (SMTP) Server: plus.smtp.mail.yahoo.com (Use SSL, port: 465, use authentication)
    Account Name/Login Name: Your Yahoo! Mail ID (your email address without the "@yahoo.com")
    Email Address: Your Yahoo! Mail address (e.g., [email protected])
    Password: Your Yahoo! Mail password
    This, theoretically, should work. However, we are having some major issues with Yahoo Mail at the moment even though we are using Mail Plus - can recieve but cannot send...sometimes. Why? No idea.

  • Can see, but can't print to network printer in Panther Server

    I'm running Panther Server 10.3.9 in a vLAN with 16 OS 9 clients. They all
    print to 2 Xerox Phaser 6200 and 6250 network printers. I am unable to print
    to either one from a G4 running Server 10.3.9. I have limited desk space so a USB-attached printer, while
    more convenient, is impractical. When I run Classic from the Server, I can print to the Phasers.
    *> that means that OS X is seeing the printers. When you print in Classic, what*
    *> happens is that the Classic drivers (LaserWriter 8) hands off the print jobs*
    *> to the appropriate OS X drivers, which do the actual printing.*
    Although I'm using OS X Server, I don't have Print Services turned on. I never could get the OS 9 clients to print the way I wanted and I didn't want to have a single point of failure for 16 clients if the Fileserver (Panther Server) went down. So they print to the Phaser themselves using, as you said, Laserwriter 8.
    I can connect to administer them both with a browser.
    *> this definitely means that you can see the printers.*
    Yes. Everytime. I can reset them and anything else I want to do administering them with a browser (Safari).
    I have all the drivers I should need (new re-installs), but print jobs stop every time.
    *> Does this mean that the drivers are installed and are visible in Print & Fax?*
    Yes. I have both a 6200 and a 6250. Both drivers are visible.
    Is there a log file or some way I can see why these jobs fail?]
    *> There are logs, some of which are visible in CUPS using the browser.*
    >
    *> What error messages are you getting?*
    What is CUPS? I've heard of it, but don't know what it is or does. I think when I had ServerAdmin running a lot, there were CUPS files that were taking up hard drive space and I had to periodically delete them in Terminal.
    I'm not getting ANY error messages. It's like the print job just evaporates before it gets to the printer. There are never print jobs showing in the list under the Print Queue.
    FWIW, I can see the Phaser 6250 (but not the 6200) under Rendezvous printers.
    I've tried AppleTalk, IP printing, and Rendezvous. I can always see the printer, but can never print.
    AAAARRRRGGGGGHHHHH!
    Do you have any pearls of wisdom?
    Thanks
    mrcrna

    I was having the same problem, and basically it comes down to Epson not having driver support for networking. The solution, install better drivers!
    Go to: http://gimp-print.sourceforge.net/MacOSX.php and download the latest version of the drivers. Once you've installed them go to Print & Fax in System Preferences, delete the last print setup (the little minus sign), add the new one but importantly from the driver menu select the Gutenprint driver. That should solve the problem, certainly worked for me!

  • Palm Desktop - Can download but can't access Palm Desktop for Treo 755p

    After 6 months of use, no problem with my Treo.  Last week my Palm Desktop won't let me access into it.  Have uninstalled/installed at least 6-7 times each.  Desktop downloads onto computer fine but I only see the front "page" if you will.  Keep getting this error ...
    Microsoft Visual C++ Runtime Library ... Runtime Error! ... Program C:\Program Files\Palm\Palm.exe ... This
    application has requested the Runtime to terminate it in an unusual way.  Please contact the application's support
    team for more info.  
    Have tried everything to override this error.  Installing, uninstalling, disengaging antisoftware, spoke with Palm Support via Live Chat (my analyst Vivian there was really helpful and tried but still stuck with same problem), have researched
    forums, the net, my how to guides, everything.  But no luck.  Someone suggested to try a different desktop.  Have researched that but can't even get into my App to see which version I have cause I'm locked out of it.  I have
    Windows XP Home SP 2 OS, Treo 755p Palm OS Garnet v.5.4.9.  I don't use the Treo as a phone, mostly as a
    portable PDA so only USB connection to computer.  I am not tech savvy.
    Post relates to: Treo 755p (Sprint)

    Thank you Pat for all your help.  Your advice worked.  A dash shows the specific folders and keys I located on my computer (for those reading this and have exact same problem, you might have same and/or the other keys).  I trust you gave all variable folder and key names. It worked perfectly the first time.  
    I had not made a backup or rename of my backup folder but as it was still in my Garbage Bin, I restored it after the fact.  The restored Palm Folder files scattered all over my computer.  When I tried to reinstall after the Restore, same Microsoft error blocked me again out of Desktop.  Not knowing what files to really delete, but determination and "painfully" did a search by both my Treo username and "Palm", sifted thru every file, sent back to garbage bin, cleaned registry again, reinstalled, and held my breath as computer restarted. 
    Everything is cleaned out, running smooth and I have my backup folder.
    Might I add to the viewers not to save a backup of the backup folder AFTER the fact.  Either rename or save a duplicate outside of the Program Folder to avoid hours of needless work.  Again thank you so very much for helping me.  
    Next:
    Delete folders:
    - C:\Palm
      C:\Program Files\Palm
      C:\Program Files\PalmOne
      C:\Program Files\Handspring
    Then go to Start > Run
    Type Regedit and click Run or OK
    Then delete keys:
    - HKEY_Current_User\Software\PalmDesktopAutorun
      HKEY_Current_User\Software\Palm
      HKEY_Current_User\Software\Palmone
    - HKEY_Current_User\Software\U.S Robotics
    - HKEY_Local_Machine\Software\PalmSource
    Post relates to: None

  • Networking locks up regularly - can connect but can't transfer data

    About once a day the networking on my Imac G5 dies. I can make outgoing TCP connections which connect to their remote destination, but no data is retrieved.
    For example, trying to retrieve a web page from a server on my LAN:
    telnet 10.0.1.7 80
    Trying 10.1.0.7...
    Connected to 10.1.0.7.
    Escape character is '^]'.
    GET / HTTP/1.0
    ...at this stage I get no data back (normally I get a page of HTML).
    The web server sees my GET request and sends a packet of data back. But it never gets an ACK for that packet so it keeps retrying. Eventually both ends time out.
    This problem affects all TCP connections - POP-3, Imap, HTTP, ssh.
    Once my Imac is in this state the only option available to me is to restart it. And often it will hang during the restart with a blank screen and I will have to physically power it off with the switch.
    Please can somebody offer some advice on how to diagnose this problem? It is driving me mad having to reboot my Mac so many times.
    Thanks!

    Your HTTP request is incomplete - the server is waiting for more data, therefore your test is in valid.
    That's not to say there isn't a problem, but that the information provided does not lead to that conclusion.
    You're issuing:
    <pre class=command>GET / HTTP/1.0</pre>
    and the HTTP/1.0 nature of the request REQUIRES a corresponding host header so that the server can determine the site you're trying to access. This is commonly used by servers running virtual hosting, where multiple sites run on the same server.
    The appropriate request should look more like:
    GET / HTTP/1.0
    HOST:your.site.com
    (note the extra return after the last header - this tells the server there's nothing more to come)
    The addition of the host header is the key (the actual data may or may not matter, depending on the site in question).

  • Can see but can't hear

    i'm having a problem with the sound when i try to use ichat. i have successfully talked with people over ichat but i usually can't hear and see them at the same time. i can connect with them and hear them over the audio successfully. i also can't connect with people, they have to invite me to chat. it's frustrating because i have successfully communicated over ichat, but i can't initiate it or get it to work on my own.

    Hi,
    Umm Comcast.
    They claim that they offer a VoIP telephone service that DOES NOT use SIP and therefore should not interfere with iChat.
    The Netgear may need some tweakes.
    Here is a page that allows you to find out the default Access info (As well as Port Forwarding Instructions).
    Check the UPnP menu item to see that it is active (it should be by default)
    In the WAN page check the item that Disables DOS or SPI (you will have one or the other). They block what they think are attacks based on how much data is coming to you.
    IF the modem is in Bridge Mode and passing the public IP to the Linksys then you may also have to disable WAN/Anonymous Ping Blocking.
    12:06 PM Thursday; September 13, 2007

  • Can Read but Can't Write to Database

    hi...i'm fairly new to java and have a problem w/ a database program i have written...i'm running windows xp along w/ access xp...the program i wrote works fine on my computer, however, the program is for my brother and on his computer it only reads from the database but can't write to it...unfortunately i packed the program in a jar file so when u run the program no console comes up to display the exceptions...he is running windows 98 (first edition) and doesn't have any version of access on his computer...i figure his odbc driver is out of date or something like that but i wouldn't know where to start to tackle this problem...any help w/ be very much appreciated...thank you...

    First, don't cross-post:
    http://forum.java.sun.com/thread.jsp?forum=54&thread=440288&tstart=0&trange=15
    Submit your question to the forum that best suits its contents. Don't try to increase your chances of getting a response by posting the same question here, there, and everywhere. It's considered rude.
    Second, if you've written a Java app that runs fine on XP, then your Java is okay. That's a good start.
    I think Windows 98 is the problem. It's rather old technology now. I would say that Windows 9x really isn't an application platform worth thinking about. You might be correct - the ODBC driver might be out of date.
    Is the version of Access you're running the same on both machines?

Maybe you are looking for