Hello!
I have the following setup:
-XServe G5 as Open Directory Master, bound to a Windows AD domain, KDC is stopped (running OS 10.3.7)
-second XServe G5 as Open Directory Replica server, also bound to AD, KDC is also stopped
-clients bound to AD domain (for user accounts and passwords), XServe´s OD domain second in Directory Services (for MCX info), clients running 10.3.5
The problem that I have now is that when I bind my clients to AD for the first time, the edu.mit.kerberos-file is correctly listing the AD Domain and the Xserve´s domain, but after a while (could not pin it to a time interval yet) the file gets changed and only shows only the XServe´s domain (and therefore,my users cannot login.
I have worked around this by removing the “autogenerated by”-lines from edu.mit.kerberos, but I´d really like to know WHY the client thinks the AD-Realm is gone…
Bye, Frido.
Comments are closed