Single Sign-on not working for me :(

Hi Everyone,
I have set-up an OS X Server 10.5.4 Open Directory Master, Kerberos is running my Kerberos Realm: SERVER.MYDOMAIN.COM, DNS is running fine and everything is in-order as far as I can tell.
But the issue that is driving me crazy is that, When a user logs-in on their laptop and they go and click on the Server with AFP shares in Finder they get "Connection Failed" but they can login when they go under Go->Connect to Server->Login window pops-up they put their username and password they access the shares.
For Kerberos single sign-on do I have to do any other configurations that I have not run across in the documentation or discussions.
Here is the settings that are in the edu.mit.Kerberos file:
# WARNING This file is automatically created, if you wish to make changes
# delete the next two lines
# autogenerated from : /LDAPv3/server.mydomain.com
# generation_id : 1164378777
[libdefaults]
default_realm = SERVER.MYDOMAIN.COM
[realms]
SERVER.MYDOMAIN.COM = {
admin_server = server.mydomain.com
kdc = server.mydomain.com
[domain_realm]
.mydomain.com = SERVER.MYDOMAIN.COM
mydomain.com = SERVER.MYDOMAIN.COM
[logging]
admin_server = FILE:/var/log/krb5kdc/kadmin.log
kdc = FILE:/var/log/krb5kdc/kdc.log
If anyone has some ideas, that would be great!
Thanks,
D

To do SSO the client computer must first find the right KDC (Key Distribution Center) to get the ticket from, login, get the ticket and then you (the computer) should be able to use that ticket to login to any kerberized service in the same realm, without having to authenticate again as long as the ticket is valid.
The question is: when do you get that ticket and where are you connecting from?
When connecting from outside of the LAN where the KDC is, you still need to find it, if using kerberos.
I suspect you (should) get the ticket when logging in locally using an OD server account.
Wheter the machine has to be bound to he OD I don't know but it seems logical to expect that if it works similiar as to how an AD works.
I'm not 100% sure about what is cached when using a portable account but as the default time a ticket is valid is 10 hours you'll need to reauthenticate when the time is up.
When logged in, if you open this application and don't quit it: /System/Library/CoreServices/Kerberos.app
it should get you a new ticket when the old one expires.
Also, using this application you should be able to get a ticket (before) trying to mount/use kerberized services (even if not using a OD server account locally or beeing bound to the OD) and not having to authenticate again — "manual SSO"?

Similar Messages

  • SPNego - Windows integrated Single-Sign On not working - How to debug?

    Dear board,
    I've tried to configure SPNego - Windows Integrated SSO with no sucess yet. We do use SAP EP7 on Windows Server 2003 64bit with MS AD 2003. The following is done:
    - Service Account is created, authentication works when done on pupose
    - SPNego wizard completed sucessfully, WebAs Java restarted
    - IE6: Windows integrated Logon is activated, IE shows Intranet when accessing the portal url ( I can't modify the IE Security Settings yet, but as we do use KERBEROS outside of SAP as well, my assumption was settings are fine)
    - UID in windows, EP and ECC are equal
    When I access the portal URL, I am prompted for used id and password. How can I trace methodically what is wrong? Some kind of checklist with links, url or SAP Notes would be great. I've also read references to a test application as well as some diag / trace tool.
    Please post thoroughly as I am rather new to this topic and still missing important terms and knowledge.
    Kind regards and thanks in advance,
    Richard

    Dear board,
    after the service principal name registration was done (once again maybe) the error message disappeared in the SPNego wizard when I retrieve the Principal in Step 2,  the test resolution works as before in step 3 of the wizard.
    At the moment, the error message in the central log file is still unchanged. Acquiring crendetials for realm xxx.xxx.org failed, no valid credentials provided.
    #1.5 #001A4BAF485A0079000000040000207000043C8446E8BA7E#1192438730203#com.sap.engine.services.security.authentication.logincontext#sap.com/irj#com.sap.engine.services.security.authentication.logincontext#J2EE_GUEST#0####d8ce7ab07afc11dc8d93001a4baf485a#Thread[Thread-307,5,SAPEngine_Application_Thread[impl:3]_Group]##0#0#Error#1#/System/Security/Authentication#Plain###LOGIN.FAILED
    User: N/A
    Authentication Stack: com.sun.security.jgss.accept
    Login Module                                                               Flag        Initialize  Login      Commit     Abort      Details
    1. com.sun.security.auth.module.Krb5LoginModule                            OPTIONAL    ok          exception             false      null#
    #1.5 #001A4BAF485A00580000007F0000207000043C8446E8C109#1192438730203#com.sap.engine.services.security.authentication.loginmodule.spnego.SPNegoLoginModule#sap.com/irj#com.sap.engine.services.security.authentication.loginmodule.spnego.SPNegoLoginModule#J2EE_GUEST#0####d8ce7ab17afc11dc8f50001a4baf485a#SAPEngine_Application_Thread[impl:3]_29##0#0#Error##Java###Acquiring credentials for realm XXX.XXX.ORG failed
    [EXCEPTION]
    #1#GSSException: No valid credentials provided (Mechanism level: Attempt to obtain new ACCEPT credentials failed!)
    Any ideas? I haven't used the diag tool yet, is there any other reasonable way how to debug the setup?
    Kind regards and many thanks,
    Richard

  • I have an apple ID which I use to sign into icloud for my iPad and iPhone.But when I use the same ID for setting up iCloud on my Macbook it says INCORRECT ID or password, try again. I tried changing my passwords but it does not work for the macbook.

    I have an apple ID which I use to sign into icloud for my iPad and iPhone.But when I use the same ID for setting up iCloud on my Macbook it says INCORRECT ID or password, try again. I tried changing my passwords several times but it does not work for the macbook.

    You will have to provide the correct password to delete the existing account, if you have tried but are not getting the password reset email, contact Apple for assistance by going to https://expresslane.apple.com, then click More Products and Services>Apple ID>Other Apple ID Topics>Lost or forgotten Apple ID password.

  • Wifi is not working for me but woking for everyonne else in my house

    Hi my wifi on my ipod5 is not working I am the only one it is not working for.. also I turned off my imessage because I noticed it was taking a very long time to send the message and it made me sign in like normal and i was not able to sign in because i didn't have wifi. PLEASE HELP!!!

    open settings, wifi and find the network name.  Does it connect?  Does it prompt for a password?  What happens?

  • Allow Custom Text Entry for Drop down not working For Dynamic form

    Dear All,
    In drop down field Allow custom text entry is working fine if the form is save as a static pdf form file.But if the form is save as a Dynamic pdf form file it is not working.I can enter custom text in drop down field but after filling it up when I click on next field the text from the drop down is disappearing.
    If any body can please help me to solve this problem.
    Thanks a lot in advance
    Regards
    Rakesh

    Dear Jimmypham,
    Thanks a lot for your quick response.But it's not working for me.I have even tried with a form having only single field and save it as a dynamic pdf file.In that form also it's not working.The text which I have entered is disappearing when I click outside of this field.
    Can you please help me to find out the solution for this problem.
    Regards
    Rakesh

  • Sound not working for apps

    The sound is not working for game apps, and possibly other apps. Sound effects work. Side switch is not on mute. Nothing, I repeat NOTHING, is muted. YouTube videos work. System sounds work. Games that are supposed to have sounds no longer have sounds.
    I also cannot update the iOS system. It says that there is no internet connection but the internet works fine for everything else. I am posting this from the device. Resetting and restarting have not worked. Also, the keyboard seems to be having minor problems as well, such as capitalizing, autocorrect, etc, which used to work but now doesn't.
    I have not used the iPad in over a year because of forgotten passcode, and now it has a bajillion problems!
    btw, how do I change the Apple ID username and email information?

    You said that you "reset" and that means different things to different people so we could use some clarification on that.
    For now, I would start with this. If you have already done this, please remember that is where the clarification is so important. Go to Settings>General>Reset>Reset all settings. The iPad will start up on its own when you do this. No data is lost. It all settings have to be entered again.
    IF you changed your Apple ID, go to settings>ITunes & App Store>Apple ID. Sign out in there and sign in with the new ID. This is worthwhile reading and should help.
    What to do after you change your Apple ID email address or password - Apple Support

  • Document library open in client application not working for img,pdf,txt files

    In an office 365 sharepoint site i have enabled open in client applicartion for document library but it is not working for image/txt/pdf files for word and excel files it is working fine. I have even turned on the feature open document in client application
    by default from site collection features also but there is no change.
    Please advice.
    Regards,
    Chaitanya

    Hi Chaitanya,
    The feature is currently designed to be used with HTTPS, and will not work as expected with the HTTP connection available on Office 365 for professionals and
    small businesses sites.
    To take advantage of this update, do the following steps:
    Wait for the update to the SharePoint Online service, which is in progress now.
    Upgrade Adobe Reader to the version 10.1.2 client.
    Add your SharePoint Online root URL/domain to the Trusted Sites security zone in Internet Explorer1 (e.g., 
    https://contoso.sharepoint.com).
    Check the Keep me signed in box when you log in to a SharePoint Online site.
    This
    SharePoint Online update is currently
    being rolled out worldwide along with several other new features.
    Best regards.
    Thanks
    Victoria Xia
    TechNet Community Support

  • Custom Pakage is not working for me.

    I was dropping photos just fine into the custom package a few minutes ago, and printed a few photos.  I imported new photos from my external drive, and when I try to print it does not work in custom. No dropping photos into the boxes, and I cannot drag and move around the boxes. I need help! I don't know what happened that it stopped working. hmm now that I think about it.. the first photos i printed were from a new sony A6000.  The ones i'm trying to print now, print fine in single photos, but they are from an older camera, could that be the reason the custom tab completely is not touchable?..  Okay no.. I just tried to custom package photos from new camera again and its not working for the new photos too..@
    Thanks, in advance..

    I am not sure exactly what is going on, there, but when you drag-and-drop a photo you have to click-drag on the thumbnail, not the surrounding gray border area.
    The reasons you’re guessing why things aren’t working don’t seem like they’d be reasons to me.

  • Need help when I sign in not working

    ''locking this thread as duplicate, please continue at [https://support.mozilla.org/en-US/questions/978554 /questions/978554]''
    I did try to follow the update things but could not get that. So how can I get my sign in working?
    XXX
    please help me get my sign in working
    <sub>edit: removed personal information for your protection. (philipp)</sub>

    when I sign in not working. I did try to folow the update but could not get that.
    XXX
    please help me get my sign in working
    <sub>edit: removed personal information for your protection. (philipp)</sub>

  • Activesync not working for Windows Phone with certificate

    We have a new Exchange Server 2013 setup and using activesync.  We have setup a policy to require simple password and to send an email to provision a device when it connects.  Activesync is setup to use self signed certificates,  this was
    tested first on the Ipad.  Certificate installed entered the settings and the device appeared in the quarantined devices list awaiting to be approved.  This was also done on the Iphone and worked. 
    When putting the same certificate on the windows phone device it errored with there is a problem with {as.domain-name.net} and does not appear in quarantined devices screen.
    I tested again with another Ipad and an android device and they work without an issue.  Tested with a Windows RT device and got the same issue.  If I look in the IIS log files I can see the windows device making a connection then when I presume
    to be the error 500 at the end of the line. 
    This is not a user issue as I can use the same user on the various devices.  The windows devices just do not want to connect.  We have looked at the certificate but if it works for apple and android devices why does it not work for windows? 
    Is there any additional security settings that need to be turned on or off for windows phones?  Is there something specific on the certificate what windows devices need that others ignore?

    I did inital think it might be a widows phone issue but there are no other settings for me to use.  I have also tested using a windows 8 surface and I get the same issue.
    I have raised the event log level on the exchange server to expert and I have seen 2 messages when I try to connect. 
    I get Event ID 1100:  Exhcnage ActiveSync device requests for your uses are being blocked.  This problme frequently occurs when HTTP OPTIONS method is not allowed.
    I know it is allowed as the test exchange connectivity worked and passed that test.
    The other error Event ID 1309 ASP.NET warning.  Part of the exception messge is DeviceTypeMissingOrInvalid
    I have come across a comment that says for certificates to work you need to use windows intune or SCCM which we don't have.  Do we know if this is true? 

  • Live Preview is not working for me

    Live Preview is not working for me.  I've read many other forums and tried everything and I still get the same issue that everyone else has mentioned.  I'm on Chrome  Version 34.0.1847.116 m .  I have multiple user profiles with Chrome so not sure if that makes a difference.
    Adobe Edge team, for a lightweight browser that should be easy to use, this does not make it easy.  Hopefully you can implement a fix soon that works for all cases as I was really looking forward to trying this out and I'm unable to.

    I am having issues as well.
    Running through the intro tutorials - Just the basic HTML tutorial files. When initiating live preview, I restarted Chrome as prompted for debugging, After restart the preview page loads fine a single time, works for about 10 seconds or so and then disconnects. I cannot get it to reconnect without restarting the program, but the same thing happens.
    Live Preview Error: Unable to Load Development Page
    The live preview icon remains orange - as if connected, but no changes write to the preview window in HTML or CSS.
    Ive seen the other threads, but none of those items seem to fix my issue.
    Anything I can do here besides wait for update? Love the basic product - the editing features are awesome, but until live preview + reliable FTP is set, I'll probably stick with current coding solutions.
    Running an Imac OSX 10.9.2
    Chrome 34.0.1847.116

  • My apple id will not work for my icloud account

    my apple id will not work for my icloud account I am running windows 7 I have reinstalled ICloud for PC several times but do not know where to set up an icloud account

    If you are getting a message that says you have a valid Apple ID but not an iCloud ID, it's because you are trying to create an iCloud account on a PC.  You can only create iCloud account on an iOS device (iPhone, iPad or iPod Touch) running iOS 5 or higher, or on a Mac running OS X Lion (10.7.5) or higher.  After creating your account on one of these devices you will then be able to sign into the account using this ID on your PC.

  • I have an event in my calendar that was sent by someone who does not work for the company anymore and I am reminded 2 times a week. How can I remove it?

    I have an event in my calendar that was sent by someone that does not work for the company anymore and I am reminded 2 times a week. How do I delete it?

    Tap on the event to open the event. Click the 'Edit' button in the event bubble, then press the 'Delete Event' button at the bottom of the Edit pop-up. It's a little different for events that come through Microsoft Exchange, you tap the event to bring up bubble and click the 'Details' button, and then press 'Decline' to remove the event.

  • IPhone 6 External Mic not working for Siri/Dictation

    I am finding that the external mic on my iPhone 6 works for phone calls and voice memos, but does not work for Siri/Dictation.  When I plug in the earbuds, they work for everything (including Siri/Dictation).
    Was chatting to Apple support who had me reset all settings.  I thought that worked, but realized that after a reset, Siri is off and I was talking to "Voice control" (which works).  When I turned Siri back on, it does not work.
    I have two questions for the community to see if you can help:
    1- I have been assuming this must be a software problem since the mic does work for non-Siri access.  But is that true?  Is there a hardware component that Siri depends on which could be faulty here?
    2- If it is software, what action should I try to address it?  I have done a reset all settings already and that did not help.
    Doug

    Hi, everyone.  I talked to Apple Genius at Apple Store last week, she said it should be a software issue and I needed to reset my iphone 6 plus as a new device and I can not use the backup restore from my iCloud, it was because the microphone bug or glitch can be in the backup also. Ok, followed her advice, erased all contents and set my iphone as a new device , the microphone worked for an hour, but went bad again.  I used "voice memo" app from Apple to test the microphone. It is the best tool since it doesn't involve any provider's network and it doesn't need another person's phone to listen and test.  If you can hear your voice recording clearly, then the mic works.  I tested it 3-4 times a day for a few days now, half of the time the mic doesn't work.  So, set as a new device isn't working. The issue is intermittent and it comes and goes as it likes, so very annoying. I carry my Apple EarPods with me in these past few days ust in case I need to make important phone calls.  Will need to go back to Apple Genius this weekend for sure.  Will give update after the weekend.

  • CALLER ID not working for International incoming calls

    Hi,
    I've a strange issue where CALLER ID not working for International incoming calls, it shows INTERNATIONAL UNKNOWN NUMBER in the phone display, but the number shows correclty in Verizon Call assistant !!!
    Any clue?

    yashshankar wrote:
    Hi
    I recently  purschased an Online number but the caller id does not work for incoming calls.How do we resolve this problem?.
    Regards
    Yash
    You didn't mention what country your Online Number is in.  Not all of Skype's Online Numbers are eligible for use as Caller ID when calling telephones or sending SMS messages.  If your number is from one of these countries (Chile, Denmark, Estonia, Hong Kong, Poland, Sweden, the UK and the US), then it can be used this way.  Otherwise, you can use a mobile number from countries other than Japan or Mexico as Caller ID with Skype, after the number goes through a verification process where Skype sends SMS messages with codes to that number.
    To get to these settings, log into your Skype account here on the Skype web site using the "Account" link at the top of this page.  You'll see a screen that would include your current Caller ID settings, and a link to change that.  If your Online Number is from one of those countries I referenced above, just select it and you're done. 
    Hope that helps!
    Patrick
    Location/Ubicacion: Arizona USA
    Time Zone/Hora Local: UTC/GMT -7
    If this message has adequately addressed your issue, please click on the “Accept as Solution” button. If you found a post useful then please "Give Kudos" at the bottom of my post, so that this information can benefit others.
    Si esto mensaje le ha ayudado, por favor haga clic en "Aceptar como solución". Si encuentra un mensaje útil, por favor "Da Kudos" al final del mensaje, por lo que esta información puede beneficiar a otros.
    I am not a Skype employee. No soy un empleado de Skype.

Maybe you are looking for