Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > macOS > OSXS Panther: How to turn on Kerberos (KDC) if stopped?

OSXS Panther: How to turn on Kerberos (KDC) if stopped?
Thread Tools
gorickey
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 19, 2004, 02:21 PM
 
Anybody know how to turn on KDC (Kerberos) if it suddenly becomes stopped and you can't authenticate to the machine using OSXS Panther? Terminal command or anything? I don't see anything through the GUI that just flips it back on...

Thanks.
     
[APi]TheMan
Mac Elite
Join Date: Sep 2001
Location: Chico, CA and Carlsbad, CA.
Status: Offline
Reply With Quote
Jul 22, 2004, 12:24 PM
 
Originally posted by gorickey:
Anybody know how to turn on KDC (Kerberos) if it suddenly becomes stopped and you can't authenticate to the machine using OSXS Panther? Terminal command or anything? I don't see anything through the GUI that just flips it back on...

Thanks.
You can't log on locally to the server itself?
"In Nomine Patris, Et Fili, Et Spiritus Sancti"

     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 22, 2004, 05:20 PM
 
Originally posted by [APi]TheMan:
You can't log on locally to the server itself?
You can log on locally; however, you can't authenticate to the ODM (Open Directory Master) at that point.

Kerberos (KDC) must be up and running anyway.

Any idea?
     
CatOne
Mac Elite
Join Date: Nov 2001
Status: Offline
Reply With Quote
Jul 22, 2004, 07:45 PM
 
Originally posted by gorickey:
Anybody know how to turn on KDC (Kerberos) if it suddenly becomes stopped and you can't authenticate to the machine using OSXS Panther? Terminal command or anything? I don't see anything through the GUI that just flips it back on...

Thanks.
Did you monkey with DNS settings at all?

Anyway, to address this, try setting Open Directory to "standalone server" (via Server Admin), and then changing it back to "Open Directory Master." If your DNS is properly set up, this will cause the KDC to start back up.
     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 25, 2004, 11:03 PM
 
Originally posted by CatOne:
Did you monkey with DNS settings at all?

Anyway, to address this, try setting Open Directory to "standalone server" (via Server Admin), and then changing it back to "Open Directory Master." If your DNS is properly set up, this will cause the KDC to start back up.
You know, come to think of it, another person did fix some reverse lookup things on the DNS side a few weeks ago. Could that have done it by chance? How does that break KDC?

I'll try your suggestion and try to let you know as well if it worked.

Thanks!
     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 26, 2004, 12:35 PM
 
Originally posted by CatOne:
Anyway, to address this, try setting Open Directory to "standalone server" (via Server Admin), and then changing it back to "Open Directory Master." If your DNS is properly set up, this will cause the KDC to start back up.
Before trying this, I assume this isn't going to jack up anything by simply switching this back and forth? Like the LDAP database won't be erased if I make it a Standalone, and then back to an ODM immediately?

Just confirming.
     
CatOne
Mac Elite
Join Date: Nov 2001
Status: Offline
Reply With Quote
Jul 26, 2004, 03:58 PM
 
Originally posted by gorickey:
Before trying this, I assume this isn't going to jack up anything by simply switching this back and forth? Like the LDAP database won't be erased if I make it a Standalone, and then back to an ODM immediately?

Just confirming.
It won't jack anything, no. You won't be able to access/log in as the LDAP users while it's turned off, of course.

It was probably the reverse DNS changes that screwed things up. That can affect lookups in strange ways..
     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 26, 2004, 09:23 PM
 
Originally posted by CatOne:
It won't jack anything, no. You won't be able to access/log in as the LDAP users while it's turned off, of course.

It was probably the reverse DNS changes that screwed things up. That can affect lookups in strange ways..
Thanks for the confirmation, I'll give it a go and see how it goes...

Thanks yet again.
     
[APi]TheMan
Mac Elite
Join Date: Sep 2001
Location: Chico, CA and Carlsbad, CA.
Status: Offline
Reply With Quote
Jul 28, 2004, 12:23 AM
 
Ah, DNS is evil, it does weird things to LDAP if its mucked with after you bind... It's a rather infamous feature of OS X Server. Fortunately Panther comes with the changeip command which previous incarnations didn't have. I hope that fixes your problem...
"In Nomine Patris, Et Fili, Et Spiritus Sancti"

     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 28, 2004, 11:21 AM
 
Everything is back and working again...it worked!

Thanks for all the help.

I hope Apple can incorporate a better "GUI" for KDC (starting/stopping) in a future version of the OS...
     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 28, 2004, 11:22 AM
 
Everything is back and working again...it worked!

Thanks for all the help.

I hope Apple can incorporate a better "GUI" for KDC (starting/stopping) in a future version of the OS...
     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 28, 2004, 11:23 AM
 
Everything is back and working again...it worked!

Thanks for all the help.

I hope Apple can incorporate a better "GUI" for KDC (starting/stopping) in a future version of the OS...
     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 28, 2004, 11:24 AM
 
Everything is back and working again...it worked!

Thanks for all the help.

I hope Apple can incorporate a better "GUI" for KDC (starting/stopping) in a future version of the OS...
     
gorickey  (op)
Posting Junkie
Join Date: Nov 2001
Location: Retired.
Status: Offline
Reply With Quote
Jul 28, 2004, 12:17 PM
 
Major database burps...

YIKES!
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 04:51 AM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,