How do you use an external MIT Kerberos realm for authentication in 10.4?

Does anyone have experience with OS X Server 10.4.x Open Directory and using a "third-party" KDCs for authentication?
I have four 10.4.5 XServes that form a SAN (Xsan). I am using a common Open Directory domain that consists of about 100 users to manage access to the SAN file space. I have one of the servers set up as OD master and a second as a failover.
My university has a kerberos realm that includes all university staff and students. I would like to use that KDC for authentication, not create my own KDC on the OD Master.
The SAN is only being used to support network file services, not as work stations. The users are going to mount file space on their local machines through AFP, Samba, or via ssh at the command line.
All of the users' short names are identical to their principle names in the University kerberos realm.
All of the Apple documentation assumes that in the OD Master will be the KDC for the OD, and part of the setup involves starting up the Kerberos KDC on the OD master system. There is mention of using any MIT Kerberos KDC, but I cannot for the life of me find where that is documented.
I have tried using the Server Admin interface and the "Join Kerberos . . . " tool, but when I enter the principle and password, the realm name and the DNS of the KDC it always fails with "error creating the keytab file."
I have also tried just putting a valid edu.mit.kerberos file /Library/ Preferences and creating a keytab file in the realm I want to join, and putting that at /etc/krb5.keytab in each of the servers in OD domain, but that doesn't seem to work, either.
Has anyone else been successful doing this with OS X Server 10.4.x?

Leland,
Thanks for your suggestions. I need a little more
guidance though. Can you explain how to do step one?
1) on your OD Master, using workgroup manager edit
the KerberosClient record and add the correct kdc
info to the XMLPlist attribute.
Is this done on the "Inspector" tab of the Work Group
manager for the user record for the principle that is
in the KDC? Exactly which key value pair do I need to
edit?
No, use the "Inspector" tab to look at config records, you will find the KerberosClient & KerberosKDC records in that list.
Select the XMLPlist attribute and edit it.
Look for the realms dictionary and either replace the existing entry with the correct realm info or add a new entry for the realm.
The important keys are KADM_List & KDC_List.
You should also look at the domain_realm dictionary and make sure that
also has the correct info.
Look at the kerberos admin guide at
<http://web.mit.edu/kerberos/www/krb5-1.4/krb5-1.4.3/doc/krb5-admin/krb5.conf.ht ml#krb5.conf>
for an idea of what the sections mean.
2) from the command line on a server run (as
root):
sso_util configure -r FOO.EDU -a kdcadmin -p
kdcadmin_pw -v 4 all
I would do this on each server in the OD, correct?
yes, this step creates the service principals for the servers in the kdc, exports the info to the local keytab, and configures the services to use kerberos (so that they know their service principals)
you might need to modify the
AuthenticationAuthority
entry for each user to point at the proper realm.
Is this also done in the "Inspector" tab for each
user's record in Work Group Manager?
yes
Thanks again for the suggestions.
Glad to be able to help
- Leland
DP G4   Mac OS X (10.4.2)  

Similar Messages

  • How can you use the same e-mail address for multiple ipads?

    I have two iPads.. an iPad and an ipad 2.  I registared my new ipad 2 and now my old ipad is will not let me log on and is telling me that my e-mail address is already in use.  how can you use the same e-mail address for multiple ipads?

    And by using the same Apple ID you can also share purchases.  If you have a different Apple ID for each iPhone then you can't share purchases.

  • How do you use a photo as a placeholder for a video in ibooks author?

    I am having trouble in ibooks author, I am trying to use a still photo as the place holder for a video, so what I want to do is when you click on the picture, a video will start playing. If anyone knows how to do it, please let me know, thanks!

    iBooks Author lets you use an image, such as a .PNG (even one with transparency) as a poster image for your video. When tapped, this image will open your video in full-screen mode.
    To do this, first drag your video file onto the page in iBooks Author to create a video widget. Select the widget and, in the Inspector panel under the Widget options, choose the Interaction tab, and check "Full-screen only" (Note: Using a separate image as a placeholder will only work if this option is checked).
    Next, simply find the photo file you'd like to use as your poster image—it can be any file, not necessarily a frame from your video—and drag it over the video widget on the page until you see the edges highlighted in blue, and release. That image is now the placeholder for the video, and when tapped it will launch your video in full-screen mode.

  • How do you use an external hard drive for your Mac (movies only), iTunes and Apple TV2 all together?  I can't put movies on internal HD as it would use it all up.

    any help is appreciated

    Welcome to the Apple Community.
    The following article(s) may help you.
    Moving your iTunes library to an external drive (Mac)
    Moving your iTunes library to an external drive (PC)

  • How do you use only one plugin in Logic for multiple guitar tracks? I want to only use one instance of Pod Farm and run all my guitar tracks through that one instance.

    I want to be able to use only one instance of Pod Farm for my guitars, and have all of my guitar tracks run through it while I'm recording.

    What he said. Or here is a similar approach with a picture.
    1. Press the SEND button on every stereo (or mono) guitar track you want to send through the effect. Then select a free bus.
    2. Make sure you turn up the amount of send (in db). Holding alt while leftclicking on this circle sets the send level to 0 db wich is good.
    3. Open the mixer (Cmd+2). Please see that I here have turned the output off from the stereo guitar track. That way the only output will be the BUS, in your case the AmpTrack bus where all your guitars will pass through. If you want both the original guitar sound AND the Ampfarm effect then just set all outputs on your guitar tracks to Stereo Out, like the AmpF Bus track is set in my picture.
    4. Insert your AmpFarm plugin here. I don´t have that plug so I inserted Waves Renes Axe for demo purpose.
    Adjust the volume/effect of every guitartrack by turning the circle input shown as 2. in my picture.
    I now see that you mentioned Pod Farm, not AmpFarm. But I guess it´s the same trick.
    Have fun.
    Heyclown.
    Message was edited by: WizardSongs - Typhoos

  • How do you use the 100$ student app discount for the app store?

    I recently bought a new Macbook Pro with the 100$ discount from the student aid pack though it also stated that I would have 100$ in app-money. How do I recieve this money on the app store account?

    How to get your gift card here >  http://store.apple.com/us/browse/campaigns/back_to_school

  • Migration Monitor - How Are You Using It?

    Hello!
    In this short discussion, you can help us to better understand how you are using the Migration Monitor – this better understanding would help the team responsible for this tool to adapt their automated tests accordingly and would also influence the future development decisions in this area.
    What is the Migration Monitor?
    The Migration Monitor is part of the software provisioning manager as of SAP NetWeaver 2004 SR1, but can also be executed manually. It uses the EXT, WHR, STR, TPL files to control the unload and load, to accelerate the load by automatic parallelization, and to generate the R3load task and command files (TSK and CMD files).The Migration Monitor does the following:
    Creates R3load command files
    Creates R3load task files if required
    Starts R3load processes to unload the data
    Transfers packages from source to target host if required
    Starts R3load processes to load data as soon as a package is available
    Informs the person performing the system copy in case of errors
    How Do You Use the Migration Monitor?
    Only for sequential unload and load - that is, you first unload to a local system, transfer the export directory to the target host, and then load using this directory.
    For parallel unload and load:
    a) Unload and load using a shared network directory
    b) Unload and load using transfer by FTP
    c) Unload and load using sockets
    In your reply, please just name your preferred option (1, 2a, 2b, or 2c) – and why you prefer it.
    Thanks a lot for your support!
    Boris

    Boris,
    Options - All three but mainly Option # 2.
    Option # 1 - To dynamically increase the number of parallel process from Source system. But in case of homogeneous system copies with massive database sizes, the database proprietary methods comes in handy than the R3load procedures.
    Option # 2 - To reduce downtime in migrations (hetero combinations) thru parallel export/import of data loads.
    Hope it helps.
    Regards,
    Srinivas K.

  • How do i use an external hard drive for all my itunes music?

    how do i use an external hard drive for all my itunes music?

    Hi valleydave,
    Here are two good links for you to check out:
    http://support.apple.com/kb/ht1751
    http://support.apple.com/kb/ht1449
    The first one goes over, in-depth, what you're looking for in regards to "off site" iTunes.

  • How do I use an external hard drive with iMovie 10.0.1? I have run out of disk space on my Macbook Air.

    How do I use an external drive with iMovie 10.0.1?  It is not obvious and I have run out of space.

    If you want to move a complete iMovie 10 library (file with .imovielibrary extension) click on the library in the libraries pane and select  File - Consolidate Library Media.  This ensures that all media is copied to the library.  You can then move the library onto your external drive using Finder.  The first time to want to access it from iMovie you will have to tell it where it is by choosing  File - Open Library -Other and navigating to it.
    If you only want to transfer part of a library to another drive, create a new library a at the desired location  File - Open Library - New  and copy projects and events to it from within iMovie.
    Its all described in iMovie help - "Work with multiple libraries".
    Geoff.

  • How Do I use my External Drive for my iTunes Library without adding anything to my Mac's HD?

    I have a new MBP and have transferred all of my music off my old pc (250+ gigs) to a Lacie 1TB thunderbolt external drive.  How do I use the external as my primary itunes library with out using any of my Mac's HD?  I'm new to mac so I have a few more questions...
    1. The initial question above
    2. will this work or will there be extra steps every time I disconnect and connect the external (other than ejecting)?
    3. Will I be able to access it remotely / home sharing?
    4.  Would this work with itunes match?
    Thanks All  !!!

    DevonC wrote:
    I haven't set up Time Machine yet because it wants me to completely format my external hard drive, and it seems to want to use it for TM backups exclusively?
    However, I would also like to use it to store stuff that I don't want to keep on my computer, eg tons of photos, videos, stuff from my sister's computer, etc.
    Is there a way to do Time Machine but also use the external hard drive for storage? I don't mind temporarily copying the photos etc that are on there to my computer while I format, so that's not the issue. I just don't want my EHD rendered completely useless to everything else.
    Thanks!!!
    There are several ways to do exactly this.
    If you partition the external drive, you can use one partition for TM and the other for anything else.
    Even if you do not partition the drive, you can safely store other data in folders on the drive. Just to not use the folder that TM creates for anything. And it's best not to put files directly on the drive, in my opinion, but use folders for storage.
    Just remember that whatever you put on the drive takes up room from TM and when the drive gets nearly full, TM will start automatically deleting older files from it's own folder.
    I have my Tiger clone on my external TM drive in a separate partition and everything works fine.

  • How can I use my external hard drive for my iphoto instead of my mac book pro memory?

    i don't know if this question has been asked before: how can I use my external hard drive for my iphoto instead of my mac book pro memory? just like itunes all my song are save on my external hard drive. make sense?

    Moving the iPhoto library is safe and simple - quit iPhoto and drag the iPhoto library intact as a single entity to the external drive - depress the option key and launch iPhoto using the "select library" option to point to the new location on the external drive - fully test it and then trash the old library on the internal drive (test one more time prior to emptying the trash)
    And be sure that the External drive is formatted Mac OS extended (journaled) (iPhoto does not work with drives with other formats) and that it is always available prior to launching iPhoto
    And backup soon and often - having your iPhoto library on an external drive is not a backup and if you are using Time Machine you need to check and be sure that TM is backing up your external drive
    LN

  • How Do You Verify an External Firewire Drive?

    Hi. How do you use Disk Utility or the Terminal to verify the condition of an external firewire drive (which I use as Time Machine) that is not Time Capsule? Is there a program for it on Boot Camp Windows? Thank you in advance.
    Gbu

    Open disk utility and click on the drive the click verify.

  • How do i use an external display with my macbook pro?

    How do I use an external display with a macbook pro?

    Just buy the proper adapter cord, such as MiniDisplay port to HDMI for example.  Plug it in and it will be automatically recognized.  Use System Preferences > Displays to set options.
    The display can Mirror your primary desktop or Extend the Desktop.
    Regards,
    Captfred

  • How do you use Default Resource Access Information?

    I have some 10g Forms & Reports that I want to use with SSO and they will all be connecting to the database with the same connection info. I know how to configure a Default Resource Access Information, but how do you use this with Forms & Reports?

    Douglas,
    the default Resource Access Infomation should be the connection information right? This is used in conjunction with SSO. You need to configure your F&R applications to delegate authentication to SSO by placing ssoMode=true in the config section of formsweb.cfg.
    The Forms Servlet will connect to OID retrieve the Resource Access Information (descriptor) for a given user and automatically log them into the application.
    Users will need a global identity in OID and SSO must be enabled to use resource access info with F&R
    regards,
    tt

  • How do you use emojis in the iPhone 5s

    How do you use emojis in the iPhone 5s

    Tap on Settings, General, Keyboard, Then Keyboards, Add New keyboard, and choose emoji.
    The next time you are in text messaging or email, and the keyboard pops up, select the globe to get to the emoji symbols.

Maybe you are looking for

  • How to connect my laptop to the internet using my iphone?

    Hello, I've just change from my former Nokia N95 to the iphone 4 (on Tmobile Germany) and I'm totally thrilled because this new device is just fantastic! However, I could easily connect my macbook via bluetooth to connect to the internet occasionally

  • Creation of currency for company code

    Dear Experts ,                                 Kindly let me know the steps of how to create currency & make it available to assign it to company code. Also Please let me know what needs to created first . Company code or controlling are ? Regards Ke

  • HT204150 iCloud and my iPhone sync okay but my second Mac does not sync with iCloud. What's wrong?

    iCloud and my iPhone sync okay but my second Mac does not sync with iCloud. What's wrong?

  • Reinstall Acrobat Pro 9 after a hard drive crash?

    So I am sitting here looking at the disk I have and the serial number.  I cannot remember where we bought this and I am not sure I even have that documentation anymore.  All I can recall is that it was 2 licenses per disk.  I do know we did not buy i

  • Problem with USB

    Ok, I've had my 40g classic for about 2 years now. The cord I use has always been the same. Starting about Saturday, it stopped working. The computer keeps nagging that the USB is not recognized. So, On Monday, I went through the 5R's and it worked.