Kerberize - Endless Password Prompt (no admin account will authorize)

I've finally got DNS setup (without ANY errors! hurray!). I've set the server up as Open Directory Master.
In OD, when I click on "Kerberize..." it prompts me for an admin name, password, and realm. Realm is correctly set to servername.domain.com
I've tried the ldapv3/127.0.0.1 directory administrator user name and password, each local admin account, root, and even created a new ldap admin with full privileges. (I even reset all the passwords to make sure I was using the correct password. I've also rebooted the server to make sure any settings have taken affect).
None of them work. Each time I hit "Ok" the prompt immediately reappears asking me to supply the user name, admin, and realm.
What am I missing here?

Sorry to be ridiculous about this stuff - I'm dealing with about 8 different things at once.
Under Open Directory, Kerberos is shown as stopped. DNS is still in perfect working order.
====
kerberosautoconfig -r SERVER.DOMAIN.COM -m server.domain.com results in...
"Unable to replace config /Library/Preferences/edu.mit.Kerberos with temp file /Library/Preferences/edu.mit.Kerberos.B0(bunch of junk here) error 1.
====
And kdcesetup -f /LDAPv3/127.0.0.1 -w -a diradmin -p (password) SERVER.DOMAIN.COM
results in...
"Segementation fault"
===
slapconfig -kerberize -f diradmin SERVER.DOMAIN.COM results in...
diradmin's Password:
Removed directory at path /var/db/krb5kdc.
command: /sbin/kerberosautoconfig -r SERVER.DOMAIN.COM -m server.domain.com -u -v 1
kerberosautoconfig command output:
Unable to replace config /Library/Preferences/edu.mit.Kerberos with temp file /Library/Preferences/edu.mit.Kerberos.nh6N3w6H3i0yc3bDdN1Rw error 1
command: /usr/sbin/kdcsetup -f /LDAPv3/127.0.0.1 -w -a diradmin -p ** -v 1 SERVER.DOMAIN.COM
kdcsetup command output:
Contacting the Directory Server
Authenticating to the Directory Server
Creating Kerberos directory
Creating KDC Config File
kdcsetup command failed with status 10
kdcsetup command failed with exit code 10: stdout=(null), error-message=Contacting the Directory Server
Authenticating to the Directory Server
Creating Kerberos directory
Creating KDC Config File
After running slapconfig -kerberize, Kerberos is still stopped. Even after a reboot it doesn't start.
====
"sso_util configure -r SERVER.DOMAIN.COM -a diradmin -p (password) all" results in...
Contacting the directory server
/Local/Defaul
/BSD/local
/LDAPv3/127.0.0.1
Creating the service list
Creating the server principals
kadmin: Cannot contact any KDC for request realm while initializing kadmin interface
SendInteractiveCommand: failed to get pattern

Similar Messages

  • ISE password expiration for Admin account issue

    OK .. we have been working on getting ISE up and running for a little while now and I have come across an odd and reoccurring issue with my admin accounts. I cannot figure out if there is something that we have missed in the setup or if there is and actual issue with the password policies. It seems that there is a "user" type password policy and then there is an "admin" type policy and am trying ti figure out if they are stepping on each other or something. I am running version 1.2.0.899 with patch 5,1.
    Here is the issue. I have started receiving password expiration reminders for the two admin accounts I have setup on the cluster. I have my address setup for an admin user named "admin" and an admin user named "wberry" and I receive two different e-mails for both accounts. The issue that I have is the dates listed in the e-mails. This is one e-mail that I get:
    The password for your local admin "wberry" is expiring on Mon Jun 01 09:43:03 CDT 2015. Please update immediately, by going to https://mem7700.spd.mli.corp/admin, signing-in, and clicking on the user name at the upper right corner.
    This is the second email that I get for the same account:
    Your network access password will expire on Thu Dec 03 08:43:03 CST 2015. Please contact your system administrator for assistance .
    As you can see the dates in the two messages are completely different. My admin policy is set with expired 180 days after creation and last change and the reminder is set to 10 days prior to expiration. The user password policy lifetime is also 365 days if password not changed with the reminder after 355 days. 
    Thoughts / recommendations.
    Brent

    Here you go:
    http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/application_networking_manager/4.1/user/guide/UG_over.html#wp1053919
    In fact, to reset the password, you must choose the change password option before you login the GUI.
    Cheers,
    Dom.

  • Changed password on Creative Cloud account - will apps stop working?

    Hi,
    My laptop with Creative Cloud CS6 installed was stolen in a burglary at our house. Fortunately I didn't lose much as I had recently done a clean install (to install CS6!)
    I have changed my password on all my accounts, including Creative Cloud. Does this mean that
    1) The apps installed will not longer work as they cannot get a license
    2) When I get a replacement laptop I will be able to activate Creative Cloud on that laptop
    I am concerned because, while my insurance is replacing hardware, it doesn't cover software.
    Thanks,
    Chris.

    Many thanks for the reply.
    Will the apps stop working after 30days when they prompt to be re-authenticated? Does authentication require someone to know the Adobe ID and password?
    Thanks,
    Chris.

  • Admin password works within admin account, not in standard/managed account

    My admin username and password work within my admin account but when I try to use them to override changes in my wife's or my daughter's standard / managed accounts it does not work. If I want to allow the application firewall or to change parental controls there is a request for an admin password. I know that the username and password are correct and the account has not been made a standard account by upgrading. I have read the other threads about the problems found by some users in 10.5 but this is different as it is definitely still an admin account, it just seems as if it not recognised as such outside the admin account itself.
    Hope my description of this makes sense to someone. Any help would be appreciated.

    Are your wife's or daughter's accounts using keyboard layouts that might be remapping some of the characters to a different key? Are any of these characters in the admin password?
    Also, you should be using the "short" user name of the admin account when authenticating. Normally the short user name has no capital letters in it. Check the short user name in System Preferences -> Accounts.
    Suggestion: Create a fourth account, make it an admin account, and then remove admin rights from your own user account. Unnecessarily running all the time as admin is bad security practice. Apple recommends only logging in to the admin account to do admin tasks, and doing all of your day-to-day work in a non-admin account.

  • If I change the password for my icloud account will it also change my apple ID password?

    the two passwords are the same now - If I change my icloud password does that automatically change my apple ID password or do I have to change it seperately?

    If you change the password for your iCloud ID, you have to change it on any services you use the ID for on your device.  If you use the same ID for purchasing, go to Settings>iTunes & App Stores, tap the ID, sign out, then sign back in using your new password.  If you use it for iMessage, do the same thing in Settings>Messages>Send & Receive.  If you use it for FaceTime, do the same thing in Settings>FaceTime.
    To change it for iCloud, you have to go to Settings>iCloud, tap Delete Account, then sign back in using your new password.  When you delete the account it only deletes the account and your synced data from yor iPad, not from iCloud.  Provided you are signing back into the same account and not changing accounts, your data will be synced back to your iPad when you sign back in.

  • The tempory password sent to my account will not r...

    i am trying to get skype on my new tv and do you think it will let me sign in i've tried using my facebook details which signs in automatically on lap top and desk top with out a problem and I have tried changing the password on laptop and now it is being real cute and saying that that password which i have copied and pasted is incorrect Help please

    Click here for information. If you can't reset them through the method described in that article or by sending yourself a rescue email(the email may take a few hours to arrive), contact the iTunes Store staff via the link in the 'Additional Information' section.
    It isn't possible to create a rescue email address without correctly answering two of the questions. Nobody on these boards can reset them for you.
    (95491)

  • How to Reset Password of User while not connected to Domain using Local Admin Account

    How to Reset Password of User while not connected to the Domain using Local Admin Account
    (I have the use of a local admin account), and I want to help a user reset their password who has logged in the PC and had their credentials cached, but forgot this password. 
    In Local Admin Account :
    When I go to Control Panel, users, users, manager user ; I cannot see any users in this window except the local admin account, and, so I cannot reset a user password this way.
    When I go to lusrmgr.msc, then users ; the local admin account will display only. 
    If I go to command prompt and type "net user", this will not display any users who have logged in to the computer, and so I cannot use "net user" to reset a password.
    I don't want to use any disks, 3rd party programs, or create a VPN connection to the domain.  I just want to help a user who calls in and forgets their password.

    Hello Keith,
    I know this is an old thread but I'm trying to better understand how I could change the domain password while not on the network. What I'm getting from your post is that you:
    1. Create a local user account (not a domain user)
    2. Login with that local user account
    3. Connect to the VPN while logged in as a local user
    4. Log out of the local account and login with the domain credentials
    Now, my question is based on the assumption that the password created on the local account is the same password that one will use to login to the domain account? Also, is the local user account the same as the domain account?
    Thanking you in advance!

  • Can't get into Admin account

    I came home the other day and my computer was off, meaning the power had apparently gone out. I turned it back on and everything seemed normal when I got to the login screen. I put in the password for my admin account and it started to log in like normal but then all of a sudden the screen goes black and this white text appears. It says something about Darwin at the top of the screen and asks for a login name and password. I type in the info and it says that no folder exists for my login name and it was logging me in as "/" or something close to that. Well I managed to figure out that typing exit gets me back to the main login screen. I signed into to one of the other accounts on the computer, and it worked fine (which is how I'm typing this now). I looked in the Users folder and strangely, the 2 non admin accounts had one folder each, but my admin account had four, named Admin 1, Admin 2, etc. I searched the Apple website for similar problems but couldn't find anything useful. Any ideas?

    I'm not sure how much this may help.
    Problems with lost Admin account, or
    Restore admin user status.
    If your admin user loses admin status for whatever reason (and it has happened to a few people), and you do not have a second admin account, then try the following:
    Boot into single-user mode. At the prompt enter:
    mount -uw /
    nicl -raw /var/db/netinfo/local.nidb -merge /groups/admin users your-username-here
    Press RETURN after each command.
    To restart in OS X enter:
    reboot
    I recommend you write down these commands in a monospaced font. Be sure to carefully note where there are spaces in the command line.
    Because of the abnormal shutdown I also suggest you do the following:
    Repairing the Hard Drive and Permissions
    Boot from your OS X Installer disc. After the installer loads select your language and click on the Continue button. When the menu bar appears select Disk Utility from the Installer menu (Utilities menu for Tiger and Leopard.) After DU loads select your hard drive entry (mfgr.'s ID and drive size) from the the left side list. In the DU status area you will see an entry for the S.M.A.R.T. status of the hard drive. If it does not say "Verified" then the hard drive is failing or failed. (SMART status is not reported on external Firewire or USB drives.) If the drive is "Verified" then select your OS X volume from the list on the left (sub-entry below the drive entry,) click on the First Aid tab, then click on the Repair Disk button. If DU reports any errors that have been fixed, then re-run Repair Disk until no errors are reported. If no errors are reported click on the Repair Permissions button. Wait until the operation completes, then quit DU and return to the installer. Now restart normally.
    If DU reports errors it cannot fix, then you will need Disk Warrior (4.0 for Tiger, and 4.1 for Leopard) and/or TechTool Pro (4.6.1 for Leopard) to repair the drive. If you don't have either of them or if neither of them can fix the drive, then you will need to reformat the drive and reinstall OS X.

  • Bricked Lenovo Yoga 3 Pro-1370 due to broken microsoft ecosystem / unrecoverable admin account

    Hi. So now I am here. HELLO EVERYONE! All you friendly and curious troubleshooters. I am frustrated and lost. I will not give you the 14 step Microsoft issue.  But I guarantee this will be one of the more bizarre or interesting problems you have read in a bit.   so tl;dr - my yoga 3 is bricked because the user account switched the administrator to an unrecoverable & disused / non-used outlook.com email account b/c of the MS App store. Their tech has not helped, no recovery has worked at all. I just want to factory reset the hardware at this point, but the software "glitch" needs me to log in to my admin account to factory reset, which is something I can't do.   Way too long of info story:   a) on my lenovo tablet, I had my personal login to sign into my admin profile. I did not use a MS Outlook account at all. In Feb, I signed up w/ a "dummy" outlook.com account for the app store, but never DL anything, and didn't think to realize this account locked me into an ecosystem... I just thought it was a temp email to register, and didn't keep any details. The 1st time it removed my local user account profile from admin, and replaced it with the outlook.com account. I immediately switched it back, that time.   b) 2 weeks ago, I wanted to DL The Economist app. We hadn't used any apps, & again it made me sign in to Microsoft. I signed into my account and DL the app. I believe it signed in with a remembered password, as I don't remember it. It could be one of 15.    c) At this point, microsoft's account removed my personal local lenovo user account, and replaced it with the microsoft outlook.com sign in d) Now, when I try to log in to my tablet, it says "You can't sign into your PC right now. Go to account.live.com to fix the problem, or try the last password you used on this PC". No previous passwords work. This is probably because I tried to sign in a bunch of times under my personal local user account, before realizing it had switched the admin to the outlook.com account. e) I go to account.live.com, and it redirects to login.live.com. When I try to sign in with my outlook.com account, it says "You've tried to sign in too many times with an incorrect email address or password." f) At this point, a captcha comes up, and no matter how many times I solve it correctly, it won't let me sign in. I did get to a point where I see a different type of screen that says my account is locked. g) When I try any form of account recovery, and attempt to have an email or password sent to my secondary recovery email, those emails never arrive in my inbox. h) when I attempt to have a code sent to my phone, I never receive the code. i) the microsoft support number has a phone tree that leads me to a place that tells me to go online to get support. j) When I try to contact customer support, it leads me back to the login in page. So I made *another* MS account for support, and have spent 2 weeks getting copy pasta support about "try password reset", "try text code reset", "try account recovery". I never get the password reset to my recovery email, I never get the text, and the account recovery doesn't work because I never used the email, and don't have enough information like email subject lines, or folders, for them to know the account is mine.... even though it was a throwaway email to use for the ecosystem, and not to use for anything else. I am still 10 tech support messages in with their support team, and they still haven't realized the problem: I DO NOT CARE ABOUT RECOVERING MY OUTLOOK EMAIL, but I do if that's the only way to gain access to my hardware's admin account. I have tried everything, and it doesn't work. I do not care anymore. I just want to factory reset the **bleep** thing, but it needs my password for the admin account to do it. Ain't that the darndest thing? I mean.. think about it! Microsoft's broken ecosystem of account recovery means their software has intrinisically bricked my Yoga 3 and made it unusable. I can still use a sub-account, but it acts all wonky because it wants me to download apps using an outlook account and when I try to sign a new one in, it leads to broken links, etc. If Microsoft's ecosystem doesn't allow for account recovery in any way, how do I take control of my hardware again? I feel frustrated and alone. This was a HUGE purchase for us, and I never thought a software glitch or problem with the ecosystem would brick hardware in this manner. NB: I know I have to take some accountability for not remembering the password, or realizing the ecosystem being a bit rigid and fierce, especially when trying to find back end understanding or support in recovery.... I had no idea, and that's on me. I also know it's not "bricked" IE unusable, per se... but not being able to log in to the admin account, nor make changes, updates, or get into the app store... it's pretty brickish. Thanks for listening. Any help is appreciated. 

    Can you get into the Advanced Startup Options page in any way?
    http://pcsupport.about.com/od/windows-8/a/open-advanced-startup-options-windows-8.htm

  • Can't log on to my admin account.

    Hey there!
    I just got the MacBook Pro retina. I was setting it up and connected it to my iCloud account and all is going well. I decided to start using a new email address, so I switched to the new email on my iCloud account. Then I log out and when I try to sign back into my admin account, I can't, because no matter what password I try it doesn't seem to be the right password. The password for the admin account is the same for the iCloud account, so this is weird since I had literally just updated my email and password for the iCloud account.
    So I'm just wondering what went wrong here?
    I tried both old and new passwords, I tried resetting the iCloud password a couple of times and nothing. Even tried resetting the old e-mail which was registered before and that's now unavailable/locked out.
    I'm guessing this has something to do with the iCloud mess, like my computer is now somehow just connected to that but there's no way for me to get to the old password or whatever it is that I need to get into my admin account.
    What are my options here? Restarting the thing? All help will be greatly appreciated.

    See
    http://osxdaily.com/2011/08/24/reset-mac-os-x-10-7-lion-password/ and
    http://osxdaily.com/2011/09/19/change-password-mac-os-x-10-7-lion-without-knowin g-current-password/

  • Time limit on admin account?

    I was wondering if there is any way or any third party app which will allow me to set time limits on the admin account. I want this because if I make an other account or guest account it doesnt keep the icon dock customized and it doesnt show XBMC the way it is customized on the admin account and I really dont want to re set up XBMC on another account.
    thanks

    No that is not possible to set time limits on the master acount change the password on the admin account to something (sh)e does not know and go to system prefrences parental controls Create an account name with (sh)e s name set the time limits you are done! thanks luke burwick

  • Admin account removal

    Hi,
    i recently purchased this Mac Book from my mums school as they were
    getting rid of a load of them cheap. i have been in contact with the
    school about this problem but they don't seem keen to help.
    basically my problem is as it was originally used by a school they have a admin account with restrictions on the other account, they seem to be unable to give me the password to the admin account, i was wondering if there was anyway of me being able to delete the admin account without having to format the hard drive.
    as you can expect this is a huge inconvinence when it comes to updating the outdated software.
    many thanks
    lewis

    Most likely, you missed a step. The disk is mounted as read only. You need to change to read/write.
    The command you need is listed in a message you will see on the screen. The author of the tip lists ...
    mount -uw /
    I like my procedures better. I include how to change the password & how to create a new administrator account.
    You need to get into single use mode for steps one and two that are listed below.
    This page will tell you how to get into single user mode.
    http://support.apple.com/kb/HT1492
    Basically, you hold down the command-s key then powering on your machine. The command key has a little apple symbol on the lower left. It is between the alt/option key and the space bar. On a PC keyboard, it will be the windows key, I think.
    1) You can change the password on an account. ( Do you know Unix. You are in a Unix single user console. ) The setup commands you need should be listed on the screen. For Mac OS 10.4.11, the commands are:
    # Type the follow two instructions to access the startup disk in read/write:
    /sbin/fsck -fy
    /sbin/mount -uw /
    # Start up some utility processes that are needed.
    sh /etc/rc
    # You will probably need to press the return key once the system stops typing.
    # To find out the users on the system type, use the list command. The l is a lower case L:
    ls /Users
    # One of these accounts will be the administrator.
    # Pick one of the users which I'll call a-user-name and type it in this command:
    passwd a-user-name
    # and enter the new user password. You need six characters.
    # You will need to enter your password twice. Your typing will not show up on the screen just
    # press enter when you complete the typing.
    # For cryptic information on these commands try:
    man ls
    man passwd
    The root account isn't enabled by default. I am not sure if changing the password on root will enable it.
    2) Get the Mac to set up an additional administrative account. You can then change the password on your old account.
    Start with your computer power off. Hold down command-s. Power on your computer.
    Type in the following:
    The first two commands will depend on your release of Mac OS X. Look at what is typed out in the console to determine the exact format.
    # Type the follow two instructions to access the startup disk in read/write. Press return after each command.
    /sbin/fsck -fy
    /sbin/mount -uw /
    cd /var/db
    pwd
    #List all files. The l is a lower case L.
    ls -a
    #The move command acts as a rename command in this format.
    mv -i .applesetupdone .applesetupdone.old
    reboot
    Once you've done that the computer reboots and it's like the first time you used the machine. Your old accounts are all safe. From there you just change all other account passwords in the account preferences!!
    Limnos adds detailed explainations:
    http://discussions.apple.com/message.jspa?messageID=8441597#8441597
    The above the idea came from a post by JoseAranda at September 9, 2006 3:48 AM
    http://www.askdavetaylor.com/howdo_i_reset_my_mac_os_x_admin_rootpassword.html
    You will need to scroll down to see this post. Search for applesetupdone
    Once you have a new administrative account, you can change the password of your old administrative account
    blue apple > System Preferences > Accounts
    Robert

  • Outlook Password Prompts events

    Few mailboxes (not many) where reported with outlook password prompt and I'm trying find events related to outlook password prompts.. 
    Need help on, where to find the event logs related to outlook password prompt.. Do I need to configure any perform or new captures to captures those events ?

    Hi,
    I'n my experience this can be cause by additional mailboxes mapped to the account. 
    On the client that is experience the password prompt, right click on the Outlook icon in the bottom right while holding shift. Then select Connection status. You should be able to see the connections to the exchange.
    Check is there is any connection that is in the state connecting when you get the password prompt. The Type will tell you what kind of connection this is and if it's an additional mailbox or mapping.
    When a user has full permissions to an mailbox it is automatically mapped to the user.
    You can disable this if wanted.
    http://technet.microsoft.com/en-us/library/hh529943(v=exchg.141).aspx
    or simply edit the attribute on the users account
    \Mattias
    http//blog.gsec.se

  • Resetting admin password using another admin password

    How do I reset an admin password on the imac from another user who is also an admin?

    Hello, Keugantic. 
    Thank you for visiting Apple Support Communities. 
    Here are the steps that will walk you through changing an admin account password using another admin account. 
    Resetting a user's password using an administrator account
    Important: Passwords for administrator accounts should not be blank.
    Log in with an administrator account. Tip: If you don't know the password of any administrator accounts, see "Resetting the original administrator account password" below.
    From the Apple menu choose System Preferences.
    From the View menu choose Users & Groups.
    Click the lock button if it appears locked; enter the administrator password.
    Select the name of the user whose password you want to change.
    Click the Reset Password button or the Change Password button.
    Enter a new password in both the New Password and Verify fields, and add a Password Hint if desired.
    Click the Reset Password button or the Change Password button.
    OS X: Changing or resetting an account password
    http://support.apple.com/kb/ht1274
    Cheers,
    Jason H. 

  • When macbook air restarts, it does not require the password for the admin

    I set up parental controls on son's Mac boolk air, but anytime it is restarted, it defaults to the admin account without haveing to enter pasword.  So basically, pointless to have controls if he can just use admin account.

    A. He can't use the admin account unless you gave him the password.
    B. He cannot access the admin account on startup unless you are using automatic login on the admin account.
    Turn off Automatic Login in Users & Groups under Login Items. Start using a new password on your admin account and keep it secret.

Maybe you are looking for

  • How do I save an image with an incremented filename?

    I am new to LabVIEW and am working on acquiring and saving many 12 bit images.  So far I have a File Dialog box to allow me to select the path to save the file. After I select the path, how can I make each image acquisition filename after that increm

  • Why does Adobe Premiere CC lockup on the launch?

    Why does Adobe Premiere CC lockup on the launch?

  • Turn around a log graph

    Hello all, I need a strange graph.  It has to be logarithmic, but I need the time axis markers to be spaced so that the first values are denser than the last values.  In other words, I need the same physical space between 0 and 100, and between 100 a

  • Help for this problem

    I use cisco 2911 with 4 FXO port and 1 FXS port for my office. My IP phone is CP 3905 I configure for call internal/ external  ok. But when i change the dialpeer for outgoing PSTN, I not make a call from internal -> PSTN I debug error and the error m

  • Firefox porpose to download my JSP files !

    Hi guys, I have a jsp web application that propose to the client to download the file .jsp instead of "opening" the file in the client. It does not happen all the time, and I tried several things, but the problem is still around. Any help will be gre