Kerberos/Keychain and PHD: Am I trying to do something silly?

Howdy-
I'm new to Mac OS server; and I've run into a slight issue - I've set up a Network Account with a roaming profile on OD, and that works fine - Kerberos/SSO all works, and the keychain shows my normal keychains.
However, I'm forever transferring gigs of temporary data into and out of my user account - Which means that I'm constantly waiting for data to move onto and off of my server. I'm only on 100mbit lan, so this can take a while.
So I thought if I switch my user to a Mobile account, I can work like a local user; and simply sync data at the beginning and end of session to keep my roaming profile up to date. This works beautifully albeit one caveat:
Both kerberos/sso and my keychain don't work. So whenever I try to connect to a server, either for screen sharing or AFP, I get prompted for a username and password every time I connect.
I've tried repairing the keychain; adding a new one, etc to no avail - So I'm wondering, am I being silly and I'm trying to do something which the system isn't designed to do?
Many thanks any advice!
- Kogen

You've not provided a lot of detail so I am going to suggest that you look at a common point of trouble. But before I do, I will ask, is your DNS working properly (forward and reverse resolution), and if so, when you open /System/Library/CoreServices/Kerberos, do you have a valid TGT after login (this is a Kerberos ticket granting ticket)?
Ok, if the answers to those questions are yes and yes, then try this:
1: On the server, open Terminal
2: Type the following command:
sudo serveradmin settings afp:kerberosPrincipal
3: You should get a result that look something like:
afp:kerberosPrincipal = "afpserver/[email protected]"
4: If you do not get this, then your AFP service is not configured to properly use Kerberos.
5: Correct the value by using the serveradmin command line tool and determining your proper hostname (hostname) and realm name.
Hope this helps. Oh, if the answers to either of the first two questions is no, then either fix DNS or resolve the issue of why you are not getting a TGT. Remember that time is critical. You client and server must be within 5 minutes delta for basic authentication. Less than that for many services. Time and DNS is the mantra.

Similar Messages

  • I'm having trouble with purchased and every time I tried to install something it won't let. Me

    I want to know that can I install something with out credit card

    Contact iTune Support
    https://ssl.apple.com/emea/support/itunes/contact.html

  • HT5834 I keep trying to activate my keychain and sent to apple support all my passwords are correct as well as the sms code i recieved??

    I keep trying to activate my keychain and sent to apple support all my passwords are correct as well as the sms code i recieved??

    Hi 2 stroke,
    I apologize, I'm a bit unclear on the exact nature of the issue you are describing. If you are having issues setting up or using iCloud Keychain, you may find the information and troubleshooting steps outlined in the following article helpful:
    Get help using iCloud Keychain - Apple Support
    Regards,
    - Brenden

  • I CANNOT change my phone number to an sms capable number to set-up keychain.. I have tried everything. My mobile is stuck set to @icloud and my mac to stuck set to @me and there aren't any options for changing anything. Any help appreciated.

    I CANNOT change my phone number setting to an sms capable number to set-up keychain.. I have tried everything. I am on a Mac OSX, Mavericks upgrade and an iPhone 5. My mobile is set to @icloud and my mac is stuck set on @me and there aren't any options for changing either my phone number, account, details or anything. I simply want to set-up keychain and receive an sms to my mobile and not to my sms non-compatible home phone number. Any help sooo appreciated.

    On your Mac, Sign Out of iCloud, then Sign In with the ID you want to use.

  • My keychains haven't been working so I deleted something and I forgot what it was

    My keychains haven't been working so I deleted something and I forgot what it was, but it was obviously something big and now my mac is saying that it cannot find a place to store a keychain or there is no keychain available or something along those lines. I need help with this problem ASAP. This is how this problem started:
    1) A couple days ago i changed my password and turned my computer off.
    2) Today I powered up my mac and it says "This application would like to use keychains please enter your keychain login."
    3) I didn't know what the password was so I went on Safari and the messages kept popping up.
    4) I went on Safari typed in my problem and it came up with a question similar to mine on an apple webpage.
    5) I clicked the webpage and it was telling me these steps to follow to make the pop up messages stop and how to reset the keychain login password
    6) I followed the steps and one of the steps were to delete something so i did
    7) I then tried to reset my default keychain but it said "This specified keychain could not be found"
    8) so i got worried and restarted my computer and it still had the pop ups and i had to relog into my account.
    9) I got relogged into my account and the messages kept popping up.
    So now i come to you all smart mac users asking for your help and ASAP. Please help me I don't know what i did and i want my mac back to the way it was.
    HELP ME!!!! Answer ASAP PLEASE I NEED YOU SMART PEOPLE!!!!!

    Hello Chewey
    Best thing to do here would be to reset your keychain to factory default. I’ll explain below. But first let me explain the consequences: doing the action below means that your iMac will forget your passwords until you enter them again once more. Think email passwords, wifi passwords, website passwords etc. You don’t have to change all these passwords, you will have to simply enter them once more, so hopefully you either know them by heart or wrote them down in a safe place at one point.
    Either way, I think at this point you have little choice, as your description makes me think your keychain is completely broken anyway unfortunately.
    So here we go:
    1/ click on the Finder and locate the menu called “go” in the upper left corner of your computer display. For reference, this will be somewhere to the right of the classic -menu. Once found, click on it and select: “Go To Folder”
    2/ Type the line below in the box that appears, including the ~ (or copy-paste it from here of course) and click the [GO]-button.
    ~/library/
    3/ Now the Finder will enter a folder with a lot of technical-looking folders. Scroll around until you find the folder called “Keychains” Move this entire folder - with contents and all - to the trash.
    4/ Once trashed (you don’t have to empty the trash if you don’t want to) restart your computer via:  > restart. If this doesn’t work (might happen if a lot of password prompts are hanging around for example) just forcefully restart it this once.
    Your issue should be solved and you’re now left with the slight chore of re-entering your passwords one-by-one as your computer asks for them.  

  • Fixing Fan Noise Created Keychain and Connectivity Problem

    This will kind of be long so bare with me...
    I occasionally will get the dreaded "fan running out of control/noise" scenario with my Power Mac G5 Dual 2Ghz (Mac OS 10.5.6). I usually run through the usual steps, re-set PMU switch, re-set nvram, run repairs with Disk Utility, boot up under a different startup disk, etc. Eventually something works and the fan returns to normal. This time around none of those steps worked but after 20 minutes the fan went back to normal by itself. Go figure...
    At the same time this was happening, my computer would not connect to the Internet. The router's (which is connect to a cable modem) status lights said I was connected but my computer could not automatically get the DHCP information nor could it reach the router's control panel via Safari. I have a PC also hooked up and it was connecting to Internet fine and it was able to access the router's control panel via Firefox. At this point, I was hoping the ethernet hardware was not going bad.
    Not only that, I could not access my keychain formation. When I selected any items and tried to show password, it gave me the error message about unable to access keychain item. I ran First Aid on the Keychain and it reported no problems.
    My main startup disk is running Mac OS 10.5.6. This version of the OS has been running fine for the past couple of days before all this happened. I have a second startup disk which has Mac OS 10.4.x installed. I tried to boot up with that startup disk (OS 10.4.x) and the computer was able to connect to the Internet fine. That ruled out the hardware. I booted up with the main disk (OS 10.5.6) again. Surprisingly enough I had Internet connectivity again. My keychain was almost back to normal. The only problem is that for any item I select to show password for, a pop up window appears saying "Keychain Access wants to user your confidential information stored in "xxxxx" in your keychain. Once I select the Always Allow button the information is displayed.
    So my questions are:
    1. Why did my computer "refuse" to connect to the internet in this odd manner?
    (BTW -- I am using OpenDNS with the router, could this have contributed to the connectivity issue?)
    2. Why did booting up with a different startup disk seemingly corrected the problem?
    3. In the Keychain, is there a way to apply "Always Allow" as a group instead of one by one?
    4. Is this an unforeseen side effect of updating to OS 10.5.6?
    5. Could any of this have been avoided?
    Thanks.
    Message was edited by: Carlton Chin
    Message was edited by: Carlton Chin

    FYI to all the helpful folks here (and any looking to shut their jet engine off as well): Flashing the BIOS did the trick.
    First I had to find a website with DOS OS files and put those on the USB instead of Vista.  Oldie but a goodie, but at least it booted! No other versions would.
    I had been intending to use the WinPhlash utility that Lenovo supplied with the BIOS update but since I was booting from DOS that was useless. However, I found a DOS version of it and used that instead. Boom baby!  Flashed and rebooted. 
    It did take two boots to get it back to normal (first one gave very alarming messages about no operating system being found but I think it was just a remnant of the reboot that was triggered from the DOS session).  A second boot returned life to normal and blissful silence from the server.  And I was finally able to get the model and serial number back in there to get rid of the bootup message it throws for that too.
    Ahhhhhhh. 
    Thanks to all for the hints - I believe I had gotten the idea of flashing the BIOS to solve this from some other thread I found here.  This is a very nice forum to have bookmarked.  

  • Problems with Keychain and

    I was on my computer and I tried to change something in the system preferences and the computer wouldn't let me. I noticed that the keychain lock on the bottom. Of the screen was locked so I made a attempt to unlock it but it wouldn't let me. When I put in the info that I always put in for my administrator's name and password that has never been change that I know of it says that it not the right name or password. I don't know what else to do at this point can someone help. I don't care what I have to do.

    Since there's no lock associated with the System Preferences window, you need to provide more information. Exactly which prefPane are you trying to unlock? Alternatively, go to http://search.info.apple.com/ and search for *reset password* and review the various articles that search returns, since that might be your only option.

  • I keep getting a session timeout message after agreeing to the new iTunes store terms.  Have reset the keychain and restarted iTunes.  No joy.

    The message is:  "Your session has timed out.  Please try this operation again from the beginning."  It appears immediately after I click on the I agree button.  This is the first time accessing the store since I upgraded to Snow Leopard.  The reply from the Apple Help person via email pointed to a web page that suggested there might be a problem with keychains so I used the Keychain Access app to verify and repair it/them/whatever.  I have never used keychains and really don't see any use for it/them.  I guess I can get along without new iPad apps, or maybe I'll have to...

    Having the same problem on my iMac.  I've tried everything to do with connection problems in the Help article re: the iTunes store with no results.  Also contacted Support, which referred me to the Help article and to the Support Communities i.e. here; no dice.  I get the idea that something's mixed up here; they told me it was probably my internet connection rather than an iTunes issue, but according to my diagnostics the network is working perfectly fine.  It has to be something on the far end - especially since there would appear to be no less than four people with the issue.

  • Keychain and 1password questions

    Can someone give me a basic rundown of what the Keychain is and how I am supposed to use it?
    Also, I use 1password and it requires me to put in my password every time. It gives me the option to remember the PW in the keychain, but when I select that it gives me a serious sounding warning that basically says it is not safe to do it the keychain is not properly secured which by default it is not. How do I secure it so I can safely save my 1password PW?

    Keychain and 1Password are similar beasts. In fact 1Password uses a separate keychain file to store its passwords. The difference is that 1Password integrates very will with most web browsers available on the Mac.
    The reason 1Password gives you that warning is because by default your default keychain is unlocked when you login to your Mac. And since a lot of people do not even password protect their Macs when the screen saver runs or when waking from sleep, and allow their Macs to automatically log them in when they boot up, that means anyone that can get their hands on your Mac will have access to ALL your passwords in both your keychain AND 1Password.
    It is possible to use Applications -> Utilities -> Keychain Access -> Edit -> Change Settings for Keychain "Login".
    Of course changing those settings will most likely result in Keychain asking for your password when 1Password wants access to it, instead of 1Password
    So if you trust that no one will ever get their hands on your Mac, then allowing 1Password put its password into Keychain will stop the constant password requests. It is your Mac and your information you are trying to protect.
    The main advantage of 1Password is that you only need to remember 1 password instead of several dozen passwords for each web site, or worse using the same single password for every site, so that if some figures out the password to one site would give them access to all your sites. At least with 1Password you can use strong passwords for your web sites and only memorize the password for 1Password.

  • HT1631 I am not able to recover my keychain access.  I followed the directions to "Reset My Default Keychain" and then entered a new password.  It will not accept a new password.  How do I Reset or recover the KeyChain Access Password?

    I am not able to recover my keychain access.  I followed the directions to "Reset My Default Keychain" and then entered a new password.  It will not accept a new password.  How do I Reset or recover the KeyChain Access Password?

    This is what you tried?
    Resetting your keychain in Mac OS X...
    If Keychain First Aid finds an issue that it cannot repair, or if you do not know your keychain password, you may need to reset your keychain.
    http://support.apple.com/kb/TS1544
    Keychain Access asks for keychain "login" after changing login password...
    http://support.apple.com/kb/HT1631

  • Why login keychain and user keychain

    Hi,
    I am trying to dianose a keychain problem my little home network is having and realize I don't quite have the knowledge to get started. My first, very basic question is, why do I have both a login keychain and a "user" keychain. Which is unlocked automatically when I login? What is the point of both of them?
    Thanks!
    Tom

    Hi baltwo, thanks for responding.
    I have a home net with several G4/G5 machines all running 10.4. I "sync" the keychains on the various user accounts via .Mac.
    Keychain Access shows that I have four keychains; tom, login, system and X4509Anchors. In my library/keychain folder I have two files: login.keychain and tom (with out an extension). I did not specifically create the tom keychain.
    I am trying to understand why I have a tom keychain. I am also trying to understand which unlocks automatically.
    The reason I ask this is periodically one of the machines (it varies) on the network will have keychain problems and request that a keychain be unlocked or require manual entry of a password. This normally only happens with Apple's Mail application and on occasion when connnecting to a networked machine.
    Curiously, when I "correct" the problem on one machine (usually by deleting a keychain) the problem will often move (probably whily syncing with .Mac) to another machine.
    Thanks!
    Tom

  • I can't understand apple teminology - what is the difference between a keychain and a password - why does my mac keep asking me to type in the keychain - I don't know what it is or when it was created!!!

    I can;t understand the apple terminology - what is a keychain and how is it different to password?  When I set a new password it keeps asking me for the login keychain.  None of my passwords work for it and I don't know when it would have been created.

    A "keychain" is a secure database in which passwords are stored in an encrypted format to prevent unauthorized discovery of your passwords. Think of it like a bank safe deposit box in which you can safely store your passwords.
    If you have a problem with your keychain then perhaps you have not changed the passwords correctly or need to repair your keychain. You might try:
    Assuming that you are using a recent build of OS X, go to /Applications/Utilities and launch the app called Keychain Access. Go to the Window pulldown menu and select "Keychain First Aid". Enter your password, set the radio button to "Repair", and click "Start".

  • I have adobe editions 4.0 and I've been trying to get library books on my kobo for over 2 hours! The book goes onto my Kobo fine, but when I try to open in on my kobo it says, "Oops! The document couldn't be opened. It's protected by ADRM and is not curre

    I have adobe editions 4.0 and I've been trying to get library books on my kobo for over 2 hours! The book goes onto my Kobo fine, but when I try to open in on my kobo it says, "Oops! The document couldn't be opened. It's protected by ADRM and is not currently authorized for use with your Adobe ID." It does it with every single book. I've never had this problem before. I've tried everything! Please help.

    same problem for me. I am using abe edition 3 as I don't think 4 can be used with kobo. Book has been downloaded to kobo but it can't be read as it is not authorised.Help please

  • HT5312 Hi I'm just wondering does any one know why the email to reset ur password hasn't came to my email address its been 2 days and I have been trying since No Emails ?

    Hi I'm just wondering does any one know why the email to reset ur password hasn't came to my email address its been 2 days and I have been trying since No Emails ? anyone know what happening ?

    Either it ended up in a spam filter or it isn't being sent to that address. If you can't find it, use the link in the 'Additional Information' section of that article to contact the iTunes Store staff.
    (88597)

  • I have just tried to connect my Mac book pro to an LG Plasma TV via an iWires Mini DisplayPort to HDMI cable. All I get on my TV is the Mac wallpaper and nothing else. I am missing something really silly, could anyone help please.

    I have just tried to connect my Mac book pro to an LG Plasma TV via an iWires Mini DisplayPort to HDMI cable. All I get on my TV is the Mac wallpaper and nothing else. I am missing something really silly, could anyone help please.

    Hi there. I also bought an iWires mini Display port to HDMI cable and have an LG LED/LCD TV. I plugged it in to my MB Pro and followed the very small writing that came in the package and got both audio and video going. You need to change the audio settings from within System Preferences on your Mac to select your TV as the audio output.
    My concern is the data latency - do you experience a delay between moving your mouse on the MBPro and the TV displaying the movement? It is only a fraction of a second, but certainly enough to be annoying, especially in a cable as expensive as the iWire.

Maybe you are looking for

  • How can I get a new copy of the Voicemail app for my LG Spectrum?

    How can I get a new copy of the Voicemail app for my LG Spectrum?  It no longer works....the screen say Loading please wait....the !Visual Voice Mail - A Visual Voice Mail error has occurred.  Please try again. OK   I've tryed several times with the

  • WHY can't I get iTunes to import cd's that I put on Windows Media Player?

    I loaded about 100 cd's onto Windows Media Player prior to receiving my Nano. When I try to put them in my iTunes library, it gives me an error message about "protected WMA format" and iTunes only being able to convert unprotected WMA song AND advisi

  • Tips on donating old Apple TV & crashing movies?

    Anyone have tips on how to prepare an old Apple TV for donation? I am having this probelm with a 1st generation Apple TV that I was copying content onto that I was going to donate to our kid's school (old kid movies they no longer watch).  We've move

  • Connection to server Problem with JWS

    Hi All I have an applet client and a server side. when i lunch the applet with Appletviewer or from its Web page, the connection between the server and the client applet works well. I have successfully lunched it with Java Web Start, BUT the server s

  • N95 Browser - search for wlan option vanished

    Hi, In the browser on my N95-1 (v30 firmare), the option to search for wlan had disappeared. The only options are my home wlan (when at home), and the various GPRS access points. How can get the search for wlan option back? Thanks