Has anyone ever made Kerberos work with AFP reliably?

I've been working on this for a couple of weeks. And while I've figured a bunch of stuff out, I'm fairly certain at this point that it's literally impossible to make AFP work using Kerberos.
So it would be great if I could get some feedback that this is possible in any way?
My question is, has any person here ever successfully made AFP work with Kerberos, as defined by:
1. In Server Admin, under AFP > Settings > Access the Authentication setting is set to "Kerberos"
2. You have been able to run your server(s) with this setting for an extended period of time, greater than two months, and are still running this way.
Please only respond positively if you have literally done this, not if you have heard of it being done, or wish to do it, or have read in a manual somewhere that it can be done.
And if you have done it, and you have good resources we might not have found using google or the os x server manuals, feel free to point them out.
Sometimes questions are pulled off the site because they are not specific enough, so I want to make my question clear. Should I continue down the path of trying to make this work (as evidenced by other people having successfully made it work) or should I give up on it?
My hunch is that a lot of people think they have Kerberos working because Server Admin > Open Directory > Overview says it's working (as mine does) and they think they have SSO. But really they just checked the "remember my login" box when logging in to a share and Kerberos isn't doing a thing, their Mac just automates the login process every time they go to a share. If they set AFP to use only Kerberos their network would break just like anyone else who tries to do that.

Yes. This most certainly works.
The areas that you need to focus is DNS and time, likely in that order. Assuming DNS is set up properly and remains that way, then you may be running into the lazy mDNSResponder issues that are plaguing early releases of 10.6. If this is the case, then tools like nslookup and dig will return the proper lookup results, but when trying to resolve to a service, the connection fails as it is misdirected. This happens most frequently on split DNS installations and has improved dramatically with the release of 10.6.3.
Beyond that, make sure your time on all workstations agree with the time on the domain server. If you have Mac Pros, those Xeon chips like to drift. If you have a time skew then Kerberos auth with fail and you will be dropped back to standard auth or no auth if you only permit kerb. This can become more complicated if your domain server and your file server are different machines.
Hope that helps. This is doable and has been since the 10.4 days. Yes, 10.6 had some release pains, but so do all OS releases. 10.6.3 is now deployable in all but the most custom environments.

Similar Messages

  • Has anyone ever had a problem with their iphone 4 not syncing and/or writing a backup file?

    Has anyone ever had a problem with their iphone 4 not syncing and/or writing a backup file?  Itunes locks up when i attempt a sync as well as when I transfer my purchases from my phone to Itunes. I'm running Itunes 10.4.1 on iOS 4.3.5.  All of this is running on an 8 year old hp pavillian laptop running XP Pro that is fully updated. Could my phone have a bug or a hardware problem. Are there any known problems with  iOS 4.3.5?  Pretty frustrating problem so I'm hoping that someone has heard of this and can offer some suggestions on a solution.  Thanks a bunch.

    Did you used to have service and now suddenly you don't?
    This happened to me a few years back, and several other iPhone users in my neighborhood, and after a while on the phone with AT&T they figured out that a technician had recently adjusted the receiver/sender on the tower and it was slightly off. They sent them back up and I actually had a better signal after than I did before it went out.
    I would call AT&T and explain the issue you are having and see if they can fix it.
    If you never had service there then like wjosten said it's probably just a bad zone.
    Hope you get it sussed out.
    -PM

  • Has anyone got Safari to work with Kerberos (SPNEGO) ?

    Has anyone got Safari to with using Negotiate (SPNEGO with Kerberos) when the system is not bound to ActiveDirectory or Macs OpenDirectory?
    I can load Firefox and it works fine, but Safari does not work. I keep hearing that Safari works out of the box, but its looks like its somehow tied to AD or Macs Opendirectory and its deployment of Kerberos.

    I am having the same problem and checked out the Apple Discussions for a solution.
    I too am meticulous with my addresses.
    Seeing no solution I went back to testing.
    I have tried:
    From Shrewsbury
    To Telford
    The result was a trip in the US taking 14 hours.
    Then I tried:
    From Shrewsbury UK
    To Telford UK
    This worked.
    When on the "Get Directions" screen there is a "Globe" icon by the "Space" icon. Pressing this brings up "English (US)". Press again and you get "English (UK).
    Any ideas?
    When I use the "Contacts" to get the Start and End fields the iPhone is bringing up the correct address but with "United States" at the end of the address.
    Again any ideas?
    In my Address book I never use the "Country" field as all my contacts are in the UK. I wonder if this is the problem and the iPhone is defaulting to US in the absence of no "Country"?
    Help!

  • Has anyone ever had a problem with your iphone working outside your home but not inside. The internet works fine in and outside of the house

    Has anyone had problems with your iphone working outside of the house, but not inside? Cannot make or receive calls, nor can I send or receive any text messages. This is something that just happened out of nowhere. Can I get some help please?

    Did you used to have service and now suddenly you don't?
    This happened to me a few years back, and several other iPhone users in my neighborhood, and after a while on the phone with AT&T they figured out that a technician had recently adjusted the receiver/sender on the tower and it was slightly off. They sent them back up and I actually had a better signal after than I did before it went out.
    I would call AT&T and explain the issue you are having and see if they can fix it.
    If you never had service there then like wjosten said it's probably just a bad zone.
    Hope you get it sussed out.
    -PM

  • Has anyone ever had a problem with their screen going all "choppy" for lack of a better word. It happens when I go from one window to the next and they sort of mesh together.

    In addition to doing this today my mouse went all crazy and it was like I had no control over it. Once I restarted my computer it was fine. I took it into the genius bar a few weeks ago, but they couldn't find anything wrong with it. If anyone has experienced something similar OR has any idea what in the world might be causing this please let me know!

    Did anyone ever suggest you reset your PRAM?
    http://docs.info.apple.com/article.html?artnum=2238
    Also might want to try resetting the SMC, although I
    doubt there's an issue there.
    http://docs.info.apple.com/article.html?artnum=304123
    I'm getting tired of people who supposedly know what
    they're doing simply guessing that resinstalling the
    OS might solve the issue. It's like trying to dissect
    a frog with a sledge hammer, and wondering why you
    didn't learn anything about anatomy in the process.
    These sorts of things, although bizarre, should be
    (and probably are) fixable without major surgery.
    Thanks for the suggestion... but I think my first question would be why these parameters would need re-setting? This is a new machine... It has never been shut down hard. It is used at most 10 hours per week... mostly using Office 2004 for MAC. I need to figure this out as I will soon need it as a Cs2/CS3 - Aperture workhorse.
    I too agree that it is best not to use a sledge when a scalpel is needed... but as a novice to the MAC world I may have been misled by Apple support. I seems to have fixed the symptoms ( some) but appears NOT to have addressed the cause... which is what I am after.
    Would TechTool Pro detect a bad HD or RAM?
    Thanks....

  • Anyone here made WOL work with K8T Neo2?

    K8T Neo2 with onboard NIC.  + Windows XP SP2/Windows 2003 Server w/ SP1
    What i need is to wake the computer over internet
    I know the Magic Packet is arriving the computer (by monitoring traffic
    when computer is alive)
    but it never wakes the computer successfully, regardless the sleep mode
    (s1, s3, etc). Keyboard wakes system perfectly.
    if you made it work, pls let me know your settings:
    - settings in BIOS/OS
    - BIOS version
    - NIC driver source/version

    To Frankenputer:
    If you turn off "allow windows to turn off..." option, "allow NIC to wake up system" will be grayed out altogether, won't it?
    To Tiresmoke:
    Quote from: Tiresmoke on 05-October-06, 00:53:56
    What ACPI do you have it set too?
    what exactly do you mean?

  • Has anyone ever had a problem with usage calualtor not working, got a data over charge

    Been keeping track of my data usage from the general folder in settings. This past month I went over 3G's and when I tally up their recordings to mine it does not add up. Anyone else notice this problem.tks

    If you aren't receiving password reset emails and your security questions don't work, someone has hijacked your account.
    This happened to me.
    You need to use Expresslane to contact iTunes support to regain access to your account ASAP.

  • Has anyone got Maps to work with directions in the UK?

    If I enter US addresses, it works, but I can not get the routing function to work at all for anywhere in the UK, even used Yo Sushi as seen on the posters and I can find it but the directions function did not work, even from the next street.
    Anyone had any success with directions on maps in the UK? And if so, can you give me the example that worked.

    I am having the same problem and checked out the Apple Discussions for a solution.
    I too am meticulous with my addresses.
    Seeing no solution I went back to testing.
    I have tried:
    From Shrewsbury
    To Telford
    The result was a trip in the US taking 14 hours.
    Then I tried:
    From Shrewsbury UK
    To Telford UK
    This worked.
    When on the "Get Directions" screen there is a "Globe" icon by the "Space" icon. Pressing this brings up "English (US)". Press again and you get "English (UK).
    Any ideas?
    When I use the "Contacts" to get the Start and End fields the iPhone is bringing up the correct address but with "United States" at the end of the address.
    Again any ideas?
    In my Address book I never use the "Country" field as all my contacts are in the UK. I wonder if this is the problem and the iPhone is defaulting to US in the absence of no "Country"?
    Help!

  • Has anyone ever got good results with an autorouter?

    Hi,
    I just read a recent mesaage about using the autorouter.
    For the last 20 years i have been in designing PCB's, and I never met anyone that uses an autorouter...
    So I wondered if any of you ever used any (ultiboard or other) with good results,
    and if you did, what type of circuit was it?
    and is it possible to share a picture with us?
    I'm just curious...
    Stressed user

    I have gotten excellent results with the ultiboard 9 autorouter and understand that the newer versions are even better.

  • Has anyone ever made a film poster??

    Hello.
    I need to convert my video images( 720x480, 349 KB, PNG image) to a resolution of 300 dpi in order to make a film poster.
    I am new at this. I don't know if Photoshop can help me. With the resolution but I know it will probably be most appropriate for the layering I have to do.
    I would appreciate anyone who has done this before. Any advice is welcomed.
    Thanks in advance!

    You will notice most movie posters depict a scene that doesn't actually appear in the film, the idea is simply to convey the genre of the film, is it sinister, funny, action packed . . etc.
    You should either photograph the actors and composite them to depict this or use a metaphorical image eg. if it was about time travel that went horribly wrong a photo of a pocket watch with the glass smashed would convey this in conjunction with the film title . . . . you get the idea . . .

  • Has anyone ever made an international FaceTime call?

    I read a lot of reviews on the subject, but for some reason could not find anyone who actually did it. I did read that a lot of people couldn't figure out how to do it. So I'm wondering if it's even possible at this stage, and ideally without some serious hacking.
    Message was edited by: Tux Kapono

    I made a international call from San Carlos Mexico to New York City on July 3rd 2010. I have a Mexico plan with At&T so the initial call was made through TELMEX and then the face time was established. The face time lated 1/2 hour with good quality considering the wifi connection I had. The best part is once you establish a face time connection you can then reconnect to that person without a phone call the next time. The call resulted in more new iphones being ordered by some of the participants.

  • Has anyone else been having trouble with safari ever since the update? I have restarted several times,mans it still doesn't work.

    Has anyone else been having trouble with safari ever since the update? I have restarted several times, it still doesn't work.

    Greetings Blueleoapple,
    After reading your post, it sounds like you are experiencing an error with Safari. You may want to consider resetting your device, which is different from restarting. This article provides detailed instructions for Restarting, and Reseting:
    Restart or reset your iPhone, iPad, or iPod touch - Apple Support
    How to restart
    Press and hold the Sleep/Wake button until the red slider appears.
    Drag the slider to turn your device completely off.
    After the device turns off, press and hold the Sleep/Wake button again until you see the Apple logo.
    How to reset
    You should reset your device as a last resort and only if you can't restart it.
    To reset, press and hold both the Sleep/Wake and Home buttons for at least 10 seconds, until you see the Apple logo.
    Thank you for contributing to Apple Support Communities.
    Best,
    Bobby_D

  • TS3899 Our CEO has an iPhone and an iPad. Everytime he is at a specific airport (BWI) he is unable to send or recieve email over 4G or wifi. Everything else seems to work just fine over wifi or 4G LTE. Has anyone ever seen anything similar? is this malwar

    Our CEO has an iPhone and an iPad. Everytime he is at the Baltimore Washington Airport (BWI) he is unable to send or recieve email over 4G or wifi. Everything else seems to work just fine over wifi or 4G LTE. Has anyone ever seen anything similar? is this malware?
    Both devices are on Verizons 4G LTE network. Both devices do have some of the same APPS installed. Can this be a case of him connecting to a rogue wifi network of a hacker that may have installed malicious code on his devices when he connected? That would explain why only his devices have the same exact issue only at BWI airport.

    Something similar I've experienced. I was once having to use a AT&T hotspot and the iPad simply refused to access my mail via the mail app. But if I used safari I could get it.  So the internet was working, but my supposition is that something with the hotspot's firewall messes with mail exchange.
    next time your boss is at BWI, do you guys have a web interface? (for example if I wanted to access my work mail I could get them to set it up via the mail app and exchange, or I could go to a certain web address and access my mail that way via safari)
    He could try using safari and the web interface if you have it.
    If it's something in the hotspot's firewall I doubt it's anything that can be changed.

  • Has anyone ever been able to get a Windows VPN to work on Airport Express?

    I've got an Aiport Express hooked up as my primary router for my home network. My laptop is running Windows XP and I'm using SafeNet as the VPN client. When I use any PC based router and open port 500 I cang et the VPN to work no problem. As soon as I started using the Airpot, I can get the initial authentication to work, but all secured data packets keep getting dropped. I have a feeling it's because UDP port 500 isn't being passed through (though apple's documentation says VPN passthrough is supported), but I'm not sure.
    I've seen a number of people with the same problem, but I haven't seen anyone get it to work. Has anyone been able to do this using IPSEC based VPN?
    Thanks,
    Dave

    I'm an IT guy myself, with quite a bit of VPN experience under my belt, and I've thrown everything I know at the Airport with no success. I have a feeling the problem could be one of two things.
    1. The port forwarding feature is TCP only (ipsec needs 500 UDP)
    2. The VPN passthrough function is interfering with PC based VPN, and has only been tested with Apple VPN software.
    Has anyone tried contacting Apple support with this issue? Any official responses?

  • Has anyone gotten DLNA to work properly with Windows 7 x64 ?

    Has anyone gotten DLNA to work properly on Windows 7 64 bit and Windows Media Player 12? I got it working, sort of. It's not reliable though, and very slow. It drops the connection a lot, and when I go to engage it it connects about half of the time and half of the time it won't see the Media Server. It also times out when trying to scan my (admittedly large) music directory on my PC.
    I'm sure that my hardware is ok, I think that DLNA is just a buggy system. But if anyone has it working properly with Windows 7 x64 and WMP 12 can you tell me exactly how you set it up?  And if you used another desktop app besides WMP can you tell me what worked for you?
    Thanks!

    Try setting it up like this.  Hope this helps!
    Start Device Manager.
    Windows 7 Click Start > Control Panel > System and Security > Device Manager.
    The following devices are normally installed:
    Anrdoid USB Devices
    My HTC
    Disk drives
    HTC Android Phone USB Device
    Modems
    HTC Modem (if using as a tethered modem)
    Portable Devices
    E:/ (Where E represents the assigned drive letter.)
    Universal Serial Bus controllers
    USB Composite Device
    USB Mass Storage Device
    If a red X, yellow ! or yellow ? is displayed to the left of a listed device, a conflict is present and the drivers must be updated or reinstalled.
    Driver conflicts may also be indicated by a device entry labeled Other Devices or Unknown.
    If a conflict is present:
    If using the HTC DROID Incredible ADR6300 as a Sync device continue to step 3.
    If using the HTC DROID Incredible ADR6300 as a Modem ensure the device drivers are installed. Refer to Downloading and installing VZAccess Manager for additional assistance.
    If VZAccess Manager is installed and a driver conflict is still present, continue to step 3.
    Right-click the device then click Update Driver Software.
    If using Windows 2000 / XP, right-click the device then click Update Driver.
    The device name may differ from the example shown.
    Click Browse my computer for driver software.
    If using Windows 2000 / XP, select Install from a list or specific location (Advanced) then click Next.
    Enter C:\Windows\System64\driver into the search window then click Next.
    The driver location can be entered manually or navigated to by clicking Browse.
    If the driver software is not found, a Windows Operating System update may be needed.
    Click Close.

Maybe you are looking for

  • Save for Web only let me save as jpg!

    For some reason, I got a file that's only let me do Save for Web in jpg format. I choose png24, click save and it changes to jpg in the save dialog. Then I created a blank doc, copy everything from the problem file over to the new file and I can Save

  • Can't get my file to read correctly..  keep getting mismatch error

    below will be my code and the file it is supposed to read.. I can't get it to work. It keeps giving me a mismatch error. import java.util.*; import java.io.*; public class TestStudent{ public static void main(String[] args){ try { Scanner s = new Sca

  • What does the usage of CURSOR word mean in an SQL statement?

    Hey folks, Please check out the following query and do please explain me what does the usage of CURSOR keyword in an SQL statement mean. select deptno,cursor(select ename from emp a where a.deptno=b.deptno) from dept b; well, the output was like this

  • Word 2013 - Work with Master Documents very slow

    Hello, we changed from Office 2003 to Office 2013. A user who creates many documentations by using master documents informed me, that he cannot work longer by using Word 2013, because extending master documents or refreshing table of contents takes l

  • RoboHelp 10 For WORD IE10 & IE11 Windows 7 Word 2010 Display Problems

    I have applied fixes from Adobe for Blank Topic Panes in IE10 and a blank TOC in IE11. The instructions indicate the fixes should be made in folder RoboHTML which I have done with no solution to the problems. I am wondering if I should apply the Adob