Kerberos Authentication Failure for POP3 After Upgrading to 10.6.5

So I just upgraded from 10.6.4 to 10.6.5 and now Kerberos authentication for POP3 from Mail fails. Kerberos authentication for SMTP outgoing mail is just fine, it's only POP3 incoming mail that fails to authenticate. POP3 Kerberos authentication still works fine for the same account from another machine running 10.5.8. The mailaccess.log file contains the following:
Nov 23 15:36:59 server master[423]: about to exec /usr/bin/cyrus/bin/pop3d
Nov 23 15:36:59 server pop3[423]: executed
Nov 23 15:37:00 server pop3[423]: accepted connection
Nov 23 15:37:00 server pop3[423]: Major Error (1): A token was invalid (gssaccept_seccontext)
Nov 23 15:37:01 server pop3[423]: Minor Error (1): Token header is malformed or corrupt (gssaccept_seccontext)
Nov 23 15:37:01 server pop3[423]: Major Error (1): A token was invalid (gssaccept_seccontext)
Nov 23 15:37:01 server pop3[423]: Minor Error (1): Token header is malformed or corrupt (gssaccept_seccontext)
Nov 23 15:37:04 server pop3[423]: badlogin: FQDN [192.168.0.4] GSSAPI
Nov 23 15:37:04 server master[52]: process 423 exited, status 0
The server is running Mac OS X Server 10.4.11 and cannot be upgraded any further than as it is ancient hardware.
Any thoughts?
Cheers,
Derek

Makes perfect sense to me that ending one session by logging out enables him to begin a new session by logging back in. I give the young man credit for figuring out how to get around this deficiency in Parental Controls, as, deep down, I'm sure you do, too.
If you can't trust him to stick to his agreed upon half an hour a day, you can always (threaten to) lock him out of the computer for 23.5 hrs/day using the Bedtime settings. ; )

Similar Messages

  • Authentication failure for zone 1 error

    We did some cleanup of old user accounts in our edir tree and after that I noticed a whole bunch of error messages on our catalina.out file. Problem is the error message does not specify what account it is looking for so I do not know what account I need to restore/recreate. Vibe seems to be working okay so I'm not sure what is broken with this account missing. Error message reads:
    2014-01-18 18:38:02,429 WARN [http-8443-55] [org.kablink.teaming.module.authentication.impl.Aut henticationModuleImpl] - Authentication failure for zone 1: org.springframework.security.userdetails.UsernameN otFoundException: User account disabled or deleted; nested exception is org.kablink.teaming.security.authentication.UserAc countNotActiveException: This account has been disabled or deleted.
    We are running on Vibe 3.4.0. Any help in identifying the account needed would be much appreciated.
    Thank you,
    Ronnie

    This looks okay.  An authFail indicates that someone is polling this device with the wrong community string.  Check x.x.x.x to make sure there aren't any applications polling this device with wrong credentials.
    Something else to note is that you should not be using '@' in your community strings.  While this shouldn't really matter for routers, it's a good rule of thumb not to use '@' on Cisco devices as that character is reserved for community string indexing.

  • Duplicate emails on outlook for mac after upgrading to mavericks

    I was getting duplicate emails on my outlook for mac after upgrading to mavericks
    After reading several websites,  I realise this is a common problem.
    some people suggesting checking " prevent app nap"
    this seemed to work for a while, but is now back again
    it is very difficult to handle, with hundreds of emails downloading each time i log in
    regards
    seema

    Try looking/posting here.
    Microsoft Support – Office for Mac
    Microsoft Support – Office for Mac (2)

  • Kerberos authentication prompting for credentials in Sharepoint 2013

    Hello all,
    I think I’m a bit confused on what I should expect out of Kerberos and sharepoint.
    Following the steps located in
    http://blog.blksthl.com/2012/09/26/the-first-kerberos-guide-for-sharepoint-2013-technicians/ , I’ve setup Kerberos in my Sharepoint 2013 environment. My hope was that configuring kerberos authentication would solve the issue of users being prompted for
    credentials when they access sharepoint. I know that one way to address this problem is to tweak the IE settings by adding the site to the local intranet or trusted zones, but am I wrong in thinking that Kerberos should also authenticate the user on to the
    site? Here’s my situation:
    Previously, I had our sharepoint URL in the trusted zone and had IE set to pass my credentials through, and that worked. After configuring Kerberos, I can see the tickets on my system using klist and the security log on our web front-end shows that I authenticated
    using Kerberos.
    However, if I then remove the sharepoint URL from the trusted zone in IE, I still get prompted for credentials. If I cancel the credential prompt, I get a 401 error and the security log on the server shows a NTLM login attempt.
    As soon as I put the URL back in the trusted zone, I can access the site and the server log shows a Kerberos authentication.
    I’m I wrong in thinking that if Kerberos was working properly then I shouldn't need to have the URL in the trusted zone?
    Thanks
    Bill

    Thanks for the quick reply, Alex. At least it’s good to know it appears to be working as designed.
    Thanks again,
    Bill

  • Kerberos Authentication Setup for MSCRM in cross forest oneway trust environment.

    Dear All,
    Kindly help related to implement Kerberos authentication on CRM application with multiple Forest environment. My environment details are as below:
    Number of forests: 2
    1. First is with name of domain1.local
    2. Second is with name of domain2.local
    Trust Level: One Way trust from domain1 and domain2.
    CRM Farm Details:
    1.  1 CRM(APP + WEB)Server (CRMAPP-01.domain1.local)
    2.  1 SQL Server (CRMSQL-01.domain1.local)
    3. 1 CRM SSRS Server (CRMSSRS-01.domain.local)
    4. CRM site url: http://mscrminternal.domain.local/MSORG1
    *I have successfuly configured Kerberos authentication and everything is working fine once try to access for Users of domain1.
    But once I tried to access for users of domain2. I am getting following error.
    HTTP Error 401 - Unathorized: Access denied.
    *If i switch to NTLM, I can access CRM site for domain2 and domain1 users without any issue.
    I read MS article, Kerberos delegation can be established if one way FOrest trust is present.
    Please help me to understand if Kerberos is possible to setup cross forest oneway trust.
    Regards
    Gyan
    GYAN SHUKLA

    Hi Gyan,
    I assume that you have solved this issue by synchronizing time between Domain Controllers, right?
    Then your last reply should be marked as answer.
    If this issue still persists, pelase feel free to let us know.
    Best Regards,
    Amy 

  • Fix for iPhoto after upgrading to Yosemite

    After upgrading to Yosemite I was unable to open iPhoto. I moved it to Trash (do NOT empty trash after moving it here!!!) - then go to App Store and download iPhoto. You'll want to make sure you then go to your Finder and click on the iPhoto download app in order to complete the download. When you open iPhoto it may say you need to upgrade - go ahead and do so then your photos will appear again with a new icon in your dock (remove the old one since it won't work now - the new icon will look different if you had an older version of iPhoto).
    Hope this helps!

    Ok so here's what you gonna do. (had this problem myself today, and after some fiddling figured out what to do.)
    Find your old iPhoto with a cross through it, right-click it and select 'show package contents'. A folder will open. In that folder go to Contents>MacOS and there will be three little things there. Click on the one called 'iPhoto' and terminal will open. Leave terminal open and wait four seconds and VOILA! iPhoto opens. Leave terminal open until you are finished with iPhoto, because if you close terminal, iPhoto will close with it. THX! ENJOY! Hope it works.
    P.S.
    You can close terminal once you close iPhoto. I also suggest backing up your iPhoto library while you can.

  • Plug-in failure in safari after upgrading to lion

    after upgrading to lion, seems like there is a plug-in issue - not sure if it's in safari or quicktime (i think the former).  any idea on how to fix so you can view quicktime videos on web?  already tried to reload latest (version 11) adobe flash without success.

    This problem just hit me.
    I have just spent 3 hours trying every combo of Flash and Java install/uninstall in order to get video on Safari on MBPr with ML. There are various posts on this issues going back thought several OSs.
    Flash 10.3 can make it work on Firefox, but that is likely to be a security hazard, acccording to Apple, so was not ideal. I tried everything that I could find on line.
    Nothing would make Safari function... then I hit on a simple solution. I keep a clone of my HDD via Carbon Copy Cloner (although Time Machine should work too). I trashed all the /Library/Internet Plugins, and replaced them with those from the clone, which was a couple of days old. I repaired permissions (there were quite a few to do from this), but then... back to normal.
    Good luck!

  • Client tools not  authenticating via Windows AD after upgrade to SP4

    We recently upgraded our test environment to SP4 to correct a problem we were having with Windows AD authentication from InfoView.  The upgrade to SP4 and JDK 1.5 solved our InfoView problem, but our client tools (Designer, Desk, Crystal Reports) can no longer login to our test environment using Windows AD authentication.
    The error message we get when trying to connect to the SP4 instance using Designer or Deski  is as follows:
    [repo_proxy 13] SessionFacade::openSessionLogon with user info has failed(Internal error.(hr=#0x80042a01)
    Enterprise authentication continues to work as normal.  My first thought was that my client tools are at the SP2 level and they are trying to connect to an SP4 instance.  Therefore, I need to upgrade the client tools to the SP4 level as well in order to get Windows AD authentication to work.  Is this correct, and if so what is the proper way to upgrade the client tools to SP4? 
    On the SAP download site you can download the SP4 Full install, but when you run it says to uninstall the existing version first which I haven't tried yet.  Does the SP4 full install give the option to do a client install versus a server install like previous SP2 install?

    While we always recommend matching versions I have rarely seen a problem with client tools and AD using different versions. I think you may have a different issue.
    If your clients were installed from a deski/designer ONLY install then you can use a client version of SP4 that is much smaller. There should also be a server version that can be installed on top of deski/designer+ client tools (this should not require an uninstall). Finally there is an integrated build which includes the full XIR2 product with SP4 built in(it sounds like you downloaded this).
    If SP4 does not resolve I'd suggest opening a message with support and packet scanning the client with netmon or wireshark.
    What's the error you get with crystal using AD? There was a known issue on SP3 client patch that made all clients fail with AD/LDAP.
    Regards,
    Tim

  • Custom nodes are deleted for IMG after upgrade

    Gurus,
    We are in processes of upgrading form ECC5 to ECCC6.
    In ECC5 we have custom node in IMG , which were created using SIMGH.
    After the upgrade all the custom nodes are deleted , is there a  way to retrieve the custom node or is there a way custom node are not touched during upgrade .
    Thanks for the help in advance.
    KJ

    Hi Ketan,
    You have used transaction SIMGH for modifying the SAP reference IMG in the old release. Those modifications gets lost
    while upgrading your system. Right?
    Even these custom node disappeared from IMG structure, but the customerspecific IMG structures or IMG-activities should be
    still available within the upgraded system. That means, you only need to reassign your IMG structures or IMG-activities with transaction S_IMG_EXTENSION .
    Those enhancements do not get lost with the next upgrade in future.
    With Best Regards
    Julia Song

  • Users using Windows Authentication unable to login after upgrade to SQL Server 2012 SP2 CU1

    We upgraded from SQL Server 2008 R2 to SQL Server 2012 SP2 CU1.  Upgrade was successful.  Users that have SQL Server Management Studio 2012 can successfully log in via Windows Authentication, but users with an older version of SQL Server Management
    Studio are unable to log in via Windows Authentication. 
    The error they receive is listed below:
    Connect not connect to XXXXXXX
    Login Failed.  The login is from an untrusted domain and cannot be used with Windows Authentication. 
    (Microsoft SQL Server, Error: 18452)
    If we switch to Mixed authentication, users can log in via SQL Server Authentication.
    Our security policy prohibits SQL Authentication. 
    Outside of having the staff upgrade to SQL Server 2012 SQL Server Management Studio, is there any setting I can set/unset to allow older version of SQL Server Management studio to connect to SQL Server 2012?
    Thanks.
    DJ

    Glad to see that you were able to resolve the issue yourself, but for the curious, could you explain what this
    Extended Protection is?
    Erland Sommarskog, SQL Server MVP, [email protected]

  • MW generation error for SRV_WRITE after Upgrade to CRM 7.0

    Iu2019m finishing up with the post-processing steps for the CRM 7.0 upgrade of our development system (from CRM 2007) and ran into an issue when re-generated the Middleware services before activating the MW.
    Per the upgrade guide, I ran GN_START to start the generation, but the results in GENSTATUS show the below 8 errors.  These errors are preventing me from activating MW, regardless of whether weu2019re actually using these services or not.  I ran into this same issue in our Sandbox for the SRV_WRITE object and managed to resolve it there by generating some specific objects using the Generation Workbench (GNRWB), however the same approach has not worked for our Dev system.  We have NOT implemented the Mobile CRM scenario, but are replicating BPs and Material with R/3, and have begun configuring the Server-based Groupware Integration which uses the Middleware framework and CDB.
    /1CRMGC/SRV_WRITE_DEL:The data object "<FS_AFTERCDB0003>" does not have a component called "UPDATE_FLAG".
    Could not determine module name: SRV_WRITE GENKEY: EXTRACT
    Could not determine module name: SRV_WRITE GENKEY: REALIGN_GET_DEP_INT_OBJ<IND>
    From what I can tell, SRV_WRITE is used somehow with Service Order replication?
    Any suggestions for next steps to resolve these errors? Thanks for any input anyone can offer.

    Thank you for the post.  After comparison of Dev system with Sandbox, I think I am missing FM /1CRMGC/HTSRV_WRITE_RRX in Dev.  However, when I try to generate in GNRWB using the below parameters, I am getting the errors below.  How to proceed?  Once again, thank you for your help!
    GNRWB Generation:
    Gen Group = RRLEX: Replication Extract
    Industry = High tech
    Rep Object = SRV_WRITE
    Generator = EXTRACTWR
    Generation Log:
    No runtime object for generator REPLI_FLOW_FUGR and object SRV_WRITE registered in TGN_OBJREG
    No runtime object for generator REPLI_FLOW_FUGR and object SRV_WRITE registered in TGN_OBJREG
    thanks,
    John

  • Social feed app for 9300 after upgrading to os6

    hi, 
    i upgrade to os6 , however the social feed app is missing. rest everything is working fine.
    my carrier- airtel, india.
    os6 bundle- 2342
    thanks

    ttexidor, please read this thread http://supportforums.blackberry.com/t5/BlackBerry-Bold/Battery-Drain/m-p/1202765/highlight/true#M811...
    There 's some information that might help you.
    Also, it is not unusual for battery drain to occur when using a new OS on the device. It should become more normal after a few days. Info about that in the thread also.
    1. If any post helps you please click the below the post(s) that helped you.
    2. Please resolve your thread by marking the post "Solution?" which solved it for you!
    3. Install free BlackBerry Protect today for backups of contacts and data.
    4. Guide to Unlocking your BlackBerry & Unlock Codes
    Join our BBM Channels (Beta)
    BlackBerry Support Forums Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • -23045 AuthNameErr in Mac Manger for OS9 after upgrading to 10.4

    Hello all. We have recently upgraded our G4 based Xserve from 10.3 to 10.4 Server. In the process because of several network changes done over this holiday season I also had to change the IP address of this server from 10.0.16.45 to 10.1.12.230. At that time I also changed the DNS records to point to the new IP Addy.
    Since then when a user logs into a OS9 Client machine they are able to login with their password properly however they are give the error code "-23045 Unknown Error" and told that their home directories cannot be mounted. They can then either say yes and go into the machine anyways without their personal settings or say no and go back to the login screen. Now our server has dual Copper NICs and a 1000SX Fiber card as well. For years we used the Fiber card with the IP 10.0.16.45, but with the addition of Link Agg to 10.4 I now have them all in use. The Fiber card kept its original IP address, but I added the new IP (10.1.12.230) to the Link Agg.
    All of our DNS records point to the Link Agg (10.1.12.230) currently. I was hoping to do a way with the old IP all together, but when we found this issue I reenabled it.
    I have done some net research and in the process have found that most posts say this error has something to do with DNS in a lot of cases. I did change our DNS records when I made the change to the server. I even added PTR records as noted in Apple Mac Manger Mailing list, but still no luck. In our setup I do not use LDAP AFP mount points for home directories. In Workgroup Manager everyones home dir is just /home/teacher which worked fine before. We currently haven't evolved up yet:>
    In my testing I have found that if I do change a user over to use an AFP point instead of the vanilla way they do in fact work and login, but its horribly slow! I went into the Share section of Workgroup Manager and checked off /home/teacher to be and LDAP AFP mount point. I then changed a user to have their home dir there then instead of the old way. I could login and everything appear to work. However the wait time on login and logout was longer then usual. We do have the MMLocalPrefs Extension enabled so we do expect some login delay, but it is sooo much worse in this configuration. I tested out general AFP share point directly
    through the chooser on nonMM machines, Windows Filesharing, FTP access, and also Server to Server transfers (we also have a newer G5 Xserve I put 10.4 on as well which has the dual Link Agg.) In all of those cases File Transfer was very very fast.
    One more weird thing I noted. I thought maybe now that I made changes something could be up with MM itself. I logged in as SysAccess and then launched the Mac Manger Admin piece. I was looking at our Student group who mounts up a directory at login which is where we keep Reading Counts. Now when I was looking at the volumes section it says "MSE on 10.0.16.45" which was the old IP. I removed it from the list and saved. Swapping back to the chooser real quick I mounted MSE manually using the new IP 10.1.12.230. I went back into the MM client and moved MSE back over to the right pane for mount on login. Again it said "MSE on 10.0.16.45" Still the old IP even though I used the new IP to mount it. I tried this test a bunch of different ways trying to force the mount as being on 10.1.12.230 but was never successful. This test sorta tells me that for some reason something in MM is holding on to the old IP. If thats so that makes sense why the error code would be saying the name isn't right.
    I read another post on the above mentioned list where someone mentioned that they formatted their clients and this problem went away. Though I don't want to this I kinda wonder if theres some sort of On Client cache of MM info or maybe even a file in my users own personal perfs which is causing this issue. If so what would be the proper way to go about working that issue out.
    So above is what all I know. I want to run some new tests Tuesday to try to track this issue down further, but in the mean time I figured it wouldn't hurt to post here so that maybe someone with Experience in old school Mac Management may know the answer or have better suggestions:> Thanks.
    -Jesse C. Smillie
    Gateway School District
    Monroeville, PA
    Xserve G4 and an Xserve G5   Mac OS X (10.4.3)  

    I called Apple Educational support and more or less they told me that the way I was doing home dirs isn't possible anymore in 10.4. So I changed over to AFP LDAP points and its working now. Still a tad bit slow, but thats a question for another post.h
    -Jesse

  • Failure to launch after upgrade to 34.0.5

    Did the auto upgrade to 34.0.5. Couldn't launch Firefox. Reinstalled to new folder and the product launched. When I closed Firefox and tried to launch from desktop it would not launch. Completely removed Firefox. Reinstalled and still have the same problem. Ran Norton Scan and no issues. Am at the end of my rope. When I look at Task Manager after trying to launch I see firefox.exe *32 but shows no CPU time. Each time I tri the *32 issue appears in Task Manager. I end the tasks and try again with the same results. Any suggestions. I had posted a similar issue a few hours ago and I thought it was resolved when I reinstalled Firefox but then I closed it and the problem is back,.

    I once had an issue. After an update, Firefox had no access to the web at all.
    But other programs were working fine. I started doing the normal diagnostic
    things. No joy. So I thru everything. I finally discovered the problem. Somehow,
    during the update, my proxy setting was changed from No Proxy. After I
    changed it back, FF was back on the web.

  • Still have no access for Assets after upgrading to Single App ...

    CC Windows, OS: Windows 7 x64 Build: 6.b7601
    Signed up for Photography program like a month ago. While I was trying to access Assets for use in Photoshop I was warned by a dialog about limited access, and I have to subscribe for CC Complete or Single App membership. Today, I have decided to go for Single App. Membership w/ Acrobat and subscribed for this programme but still there is no access ... Can you please fix this ...

    Are you sure, you are working for Adobe ? ...
    As I said before ... I have just upgraded my subscription from Photography to Single App. for ONLY assets access (Not acrobat subscription ... Single app subscription) ... Whatever; here is the description for assets feature from Adobe website -- Creative Cloud Help | Creative Cloud Market
    "To download and use Creative Cloud Market content, upgrade to either Creative Cloud Single App or Complete plans."
    and that was why I upgraded my subscription to Single App. In the end Single App is Single App; Acrobat or Illustrator. Whatever ... I am just trying to tell your subscription system fails, or at least single-app acrobat users are not being taken into consideration as single-app subscribers. I know it is reasonable purchasing Illustrator or InDesign for assets access, but there is nothing mentioned about having Acrobat as single app would not allow to use assets feature.
    So this is what happens;
    * I bought PS and Lightroom ( Photography )
    * I tried to download assets, but CC desktop app told me to upgrade my subscription to Single App or Full Membership to use them.
    * I followed the link to upgrade my plan.
    * I upgraded my plan to Single App. (Acrobat) ... Or whatever, just get it ... title of the software should not be the case, at least according to Adobe.
    * Returned back to CC desktop App. to reach assets.
    * Still no access ...
    * Still same warning to upgrade my plan which should be upgraded in step 4 !
    * 3 Weeks ...
    * Still same ...

Maybe you are looking for