Where is the kerberos database stored?  Why doesn't kadmin -l dump work?

I'm trying to figure out where exactly OS X Server stores the passwords when using Open Directory.  Is it in LDAP?  Is it the authAuthority attribute that's in LDAP?  I don't know a whole lot about Kerberos and I was trying to figure it out and I can't seem to get this question answered.  There is such a void of documentation concerning Open Directory.  Do you think Apple intends on killing it some day?
And `kadmin -l dump` says "kadmin: hdb_foreach: iteration over database only supported for DSLocal".  Does anyone know how to dump the database?

sudo ktutil list
will at least list the principles, Not quite what you wanted, but i may be useful anyway.
If you go into Server and select Open Directory, one option is to "Archive Open Directory Master..."
That creates a password protected (encrypted) sparseimage (disk image). If you mount that, you will see a volume called /Volumes/ldap_bk that looks like
$ ls -alhFG /Volumes/ldap_bk/
total 4640
drwx------  21 servadmin  staff   782B 26 Oct 15:10 ./
drwxrwxrwt@  5 root       admin   170B  1 Nov 12:48 ../
d-wx-wx-wt   2 servadmin  staff    68B 26 Oct 15:10 .Trashes/
-rw-r--r--   1 servadmin  staff     0B 26 Oct 15:10 .little_endian
-rw-r--r--   1 servadmin  staff    79B 26 Oct 15:10 DB_CONFIG
-rw-------   1 servadmin  staff   955B 26 Oct 15:10 KerberosKDC.plist
drwx------   2 servadmin  staff    68B 26 Oct 15:10 LaunchDaemons/
-rw-r--r--   1 servadmin  staff    28K 26 Oct 15:10 authdata.ldif
-rw-------   1 servadmin  staff    79B 26 Oct 15:10 authdata_DB_CONFIG
-rw-r--r--   1 servadmin  staff   2.2M 26 Oct 15:10 backup.ldif
drwxr-xr-x   7 servadmin  staff   238B 26 Oct 15:10 certificates/
-rw-------   1 servadmin  staff   521B 26 Oct 15:10 com.apple.openldap.plist
drwxr-xr-x   3 servadmin  staff   102B 26 Oct 15:10 dslocal/
-rw-r--r--   1 servadmin  staff    29B 26 Oct 15:10 hostname
-rw-r--r--   1 servadmin  staff     0B 26 Oct 15:10 id_omitfile
-rw-------   1 servadmin  staff    20B 26 Oct 15:10 keychain
-rw-r--r--   1 servadmin  staff   1.5K 26 Oct 15:10 krb5backup.tar.gz
-rw-r--r--   1 servadmin  staff   260B 26 Oct 15:10 local_odkrb5realm
drwxr-xr-x  15 servadmin  staff   510B 26 Oct 15:10 openldap/
-rw-r--r--@  1 servadmin  staff    11B 26 Oct 15:10 primary_ipv4
-rw-r--r--   1 servadmin  staff    65B 26 Oct 15:10 version.txt

Similar Messages

  • Where is the stickies database stored on a backup HD

    I recently had to wipe my hard drive clean on my MacBook pro. It is running 10.9.4
    I  use time machine to back everything up. Now I want to transfer my pictures, sticky notes and music files from the back up hard drive to the laptop. I'm having all sorts of trouble fining them. And I did force a back up the night before I the laptop was wiped cleaned and had the OS reinstalled. I just don't know where the files are located, on the backup hard drive, and where to put them, on the laptop. Can someone please help?
    Thanks,
    Lou

    Why don't you simply migrate.. then you don't need to worry.. the migration software will move all the info to the required locations.
    Although this is a little out of date, ie up to Mountain Lion it is still packed with helpful info.
    http://pondini.org/OSX/MigrateLion.html
    Apple's notes are available albeit lack detail.
    OS X: How to migrate data from another Mac using Mavericks

  • Where is the connection information stored for Mac Remote Desktop?

    I want to restore Mac Remote Desktop connection information from a Time Machine backup to a new Mac.  On the new Mac, I've installed Remote Desktop from the App Store and installed all the files found in
    ~/Library/Containers/com.microsoft.rdc.mac from
    a Time Machine backup.  But I don't see my old connections.  I also don't see any connection information in my Time Machine backup here
    ~/Documents/RDC Connections.
    Where is the connection information stored?

    The path is correct. You could try to get an console log during application launch. This log might give you information why the information is missing.

  • Where is the network setup stored?

    Hi all
    My time capsule died and I bot a airport extreme. The setup went automaticly but I lost my old parameters.
    Where are the network prefs stored? I would like to go back with time-machine and to see my old network-setup.
    Thanks in advance
    kk

    Yes my computer backups automaticly - thanks god for time-machine ,-)
    I have a static IP (as well as dynamic as it seems) and a server behind a firewall-setup. Thats why I would like to check back my old setup and prefs. But since Airport Express did everything automaticly - they are gone...

  • Why doesn't my VGA adapter work to connect my iPad2 to my projector. I haven't had any problems in the past?

    Why doesn't my VGA adapter work to connect my iPad2 to my projector. I haven't had any problems in the past?

    Hey MarieF-D,
    Thanks for the question. The following article provides basic troubleshooting steps that may help to resolve your issue:
    iOS: About Apple Digital AV Adapters
    http://support.apple.com/kb/HT4108
    Troubleshooting
    If you encounter an issue using the Apple Digital AV Adapter or VGA Adapter:
    Disconnect and reconnect the adapter from the iOS device and display.
    Connect directly to the TV, projector, or external display using a known-good VGA or HDMI cable.
    Remove any VGA or HDMI extension cables or converters.
    Note that accessories that convert a VGA or HDMI signal to other video formats (DVI, Composite, Component) are not supported.
    Ensure that you are using the latest version of iOS. Some Apple Digital AV Adapters require iOS 5.1 or later.
    Note: When using an Apple Digital AV Adapter manufactured before early 2012 with iPad (3rd generation), you may see the "This accessory is not supported" alert. Dismissing the alert will allow you to use the adapter.
    For optimal performance, you may need to adjust the video resolution or settings for your display. If your display offers an "auto detect" or "factory default" setting, you may be able to use these options to optimize video resolution and display.
    Thanks,
    Matt M.

  • When target DB is down in which table is the data from source is stored, also where are the error messages stored in ODI

    When target DB is down in which table is the data from source is stored, also where are the error messages stored in ODI( I am not getting any error message in E$_TARGET_ANI_TEST).
    When i am running the interface i am getting the below error against the errored step
    "ORA-01045: user ABC lacks CREATE SESSION privilege; logon denied."
    Only E$_TARGET_ANI_TEST  is created with no data. No such tables like C$_0TARGET_ANI_TEST, I$_TARGET_ANI_TEST are created and also data is not inserted in the target table TARGET_ANI_TEST.

    Hi,
    I have checked that only E$ table is created. C$ and I$ table are not created ( I have selected my target schema as the part for the staging table).
    All the parameters for dropping the tables are selected as "<default>:false".
    I am importing the following KMs with the following parameters:
    1) CKM Oracle
    DROP_ERROR_TABLE
    :false
    DROP_CHECK_TABLE
    :false
    CREATE_ERROR_INDEX
    :true
    COMPATIBLE
    :9
    VALIDATE
    :false
    ENABLE_EDITION_SUPPORT
    :false
    UPGRADE_ERROR_TABLE
    :false
    2) LKM SQL to SQL
    DELETE_TEMPORARY_OBJECTS
    :true
    3) IKM SQL Incremental Update
    INSERT
    :true
    UPDATE
    :true
    COMMIT
    :true
    SYNC_JRN_DELETE
    :true
    FLOW_CONTROL
    :true
    RECYCLE_ERRORS
    :false
    STATIC_CONTROL
    :false
    TRUNCATE
    :false
    DELETE_ALL
    :false
    CREATE_TARG_TABLE
    :false
    DELETE_TEMPORARY_OBJECTS
    :true 

  • Where are the MMB files stored in unix box

    Hi all,
    Can anyone tell where are the MMB files stored in unix box. Thanks in advance.
    Regards,
    Sandeep V

    Hi Thomas,
    Thanks for the reply, I got the FNDMENU.mmb file , but Iam not able to find the menu item which Iam searching for. There are some special menu items like SPECIAL , SPECIALB and SPECIALC. So, when I select release from plan menu item special27 is called , but Iam not able to find release in this menu. Can you please help me in this regard.
    Regards,
    Sandeep V

  • In transaction scase, where is the field 'status' stored ?

    Hi
    in transaction scase, where is the field 'status' stored (in Hdr. data), for a specific BP ?
    thx.
    Edited by: avijit saxena on Nov 12, 2008 10:10 PM

    table>srmprotocol>filter on [ACT_ID] 'attribute change'>choose colom 'arg_string'->filter on 'stat_orderno'

  • What on earth is the "click me" lego man on the home page and why doesn't it do something when I click?

    What on earth is the "click me" lego man on the home page and why doesn't it do something when I click?

    The Click Me logo is part of the Humble Mozilla Bundle promotion - once clicked you should be able to control the character with the "WASD", and "IJKL" keys.
    Quoting '''the-edmeister''' from https://support.mozilla.org/en-US/questions/1025706
    That Click Me game is part of the Humble Mozilla Bundle promotion on the default Home Page [about:home], that loads from the Mozilla servers in the "Brand Logo" (DIV) section of about:home. A feature that was first used in Firefox 29 [IIRC] just prior to the start of the Olympic Games.
    Also, part of that promotion is addressed in the "Snippet" below the Search Container on the about:home page.
    If you want to block the "Brand Logo" section (and the "snippet" below the Search container) from ever being seen again, you can install Stylish and this UserStyle. https://userstyles.org/styles/104673/about-home-hide-snippets-and-hide-brand-logo

  • Where is the stand alone installer ,why won't my computer upset from10.9.1 to 10.9.2

    where is the stand alone installer ,why won't my computer upset from10.9.1 to 10.9.2

    Go to About This Mac in the Apple menu.
    Click on the Version number in the window that opens. It will change to Build number. What's the build number?
    Also, what error message do you see, or any other helping description of what happens when you try to update.

  • Where is the account picture stored after initial setup?

    where is the account picture stored after initial setup?

    Are you looking to change the image? If so go to system prefs, go to accounts. You'll see the image that you see at login, by clicking on it you'll be given a drop down with all the images which you can select a different right there. If you go to the root directory in the libray folder you'll see a folder user pictures they are in there. The root directory is the main device on your hardrive, you can open finder and see it listed in the sidebar. Hope this helps!
    Joseph

  • HT5262 where does the information get stored when you back up your i-phone? It just reports its done but I have no idea where to find it if I need it again!

    Where does the information get stored when you sync/back up your i-phone. I have no idea where to look if I need it again!
    Thanks

    You can chhose the backup when you would reset your device. In this case you would get the option, during the set up process, to choose your backup and restore your device from it.
    (You can find a few information e.g. size and date of your backup in "Settings > iCloud > Storage & Backup > Manage Storage")

  • Quick qs: Where is the Reconciliation Policy stored under debug?

    It seems whenever we import files into IDM, we accidently step over the reconciliation policies set up for various resources. And I do not know where these are stored - which xml files?
    I initially thought that these are in the resources themselves - but I was wrong, because even if I do not import the resources, the reconciliation policies are erased.
    Please let me know where are the reconciliation policies stored in IDM?
    Thanks ia

    Thank you - I think that was what I was looking for.
    A

  • ASA5510: where is the startup-config stored?

    Hi,
    i'm new to cisco's asa and trying to get used to it. it's not a real problem i have, which detains me from productive work but i'm just snoopy about this. on my cisco 871, when i do a
    dir nvram:
    i see a file called startup-config. but i can not find it on my asa 5510. i have a disk0-1:, flash: and system: but nowhere a startup-config. but it must be somewehre because a
    copy tftp startup-config
    is working somehow and does what i expect. furthermore, where are the cryptographic keys stored. the same issue. i can not find them. maybe someone of you is able to point me to this. thanks.
    ct,

    The startup configuration for single mode or for the system in multiple context mode is a hidden file in flash memory. From within a context, the location of the startup configuration is specified by the config-url command. For example, if you specify an HTTP server for the config-url command and then enter the copy startup-config running-config command, the security appliance copies the startup configuration from the HTTP server using the admin context interface.
    Also check the details about the commands "copy" and "configure-url" in the links below: 1)COPY--http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c4.html#wp2104587
    2)CONFIGURE-URL----http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c4.html#wp2100481

  • Where are the Safari passwords stored in OS X 10.6.8?

    Where are the Safari passwords stored in OS X 10.6.8?

    Check out applications/utilitiies/keychainchain utilities
    Look thru and fin what you are looking for

Maybe you are looking for

  • Feature Request: List of linked contacts

    hi there, as there is bug with disapearing gmail contacts (those which are linked with SIM contacts if SIM card contacts display is switched off) i've tried to view all linked contacts and unlink them. i found the only way to do this is to go trough

  • JPA 2.0 in Weblogic 10.0 MP1

    Hi there, Is there a way to deploy a JPA 2.0 based application in a Weblogic 10.0 server? We have an application that uses Spring 3.0.4, Hibernate 3.5.0.Final and Hibernate JPA 2.0. Our customer is a major telecom operator that uses Weblogic 10.0 MP1

  • Firefox ver 31 latest doesn't play videos -

    Firefox will not play videos in or out of U-Tube. . All videos play in I.E. ver 11.0.10 without an issue In Firefox I get a large black square that reduces to a black bar and then when I place the cursor in the area where the video should be I see a

  • IChat not allowing initiate of multi party video

    iChat works for me in almost every case...even iChat to AIM...and even when the remote location is behind 2 NAT routers. It has worked between Tiger and Leopard, between Tiger and PC/AIMver5.9, and other scenarios. However, there is now a problem. I

  • Garbled text when reply chinese content email

    My BB is Z10, Email protocol is Exchang ActiveSync. Garbled text when reply chinese content email, But preview is normal, Just reply when will appear garbled. English content email no this problem. Could you please help to resolve?