The server was originally set up as standalone with no DNS and no fqdn. We wanted to set up a test intranet, so I started DNS, set a fqdn, and modified the /Library/Preferences/edu.mit.Kerberos to reflect the new REALM. I then set OpenDirectory to an OD Master role.
I started Kerberos manually (since KDC was not running) using the standard MIT setup. KDC started and I could use kinit, and kadmin.local. Using kadmim gave the “client not registered” error.
I then reinstalled Kerberos manually using the “Apple” setup. In this case KDC didn’t start (as detailed in my original message).
Comments are closed