Forum Replies Created
-
AuthorPosts
-
lschafroth
Participant[QUOTE][u]Quote by: Dave_H[/u][p]You need to bind the Server to the AD domain first – Then set up your server as an OD master
This way you will be able to log on to your mac clients with AD as it will use the AD domain as the Kerberos realm. [/p][/QUOTE]
It sounds like the AD would always have to be the keeper of all the accounts. We dont want this at all, we just want it to sync the accounts from the OD master which is the server that keeps all accounts.
Lannie
lschafroth
ParticipantSince his site is dead does anyone have a good complete guide?
I have Open Directory runing on Snow Leopard. I have some software that ONLY works on AD so I need the OD accounts synced into AD. We dont use the AD server for anything else. It is a web server and SQL server and the AD is no longer in use but still running in AD mode.
Lannie
lschafroth
ParticipantI had to add KDC to the /etc/hosts
so I had:
10.x.x.x servername.winterset.k12.ia.us kdc
Then it worked.
LAnnie
lschafroth
ParticipantI found a great kerberos pdf that came from this site. It shows a lot of example files and configurations. I will go through it today and see what happens.
Thanks!!
Lannie
lschafroth
ParticipantI found this link:
https://www.afp548.com/article.php?story=20060714092117916&query=kerberize
I got very close!! The commands all worked until I got to the kinit command. It says no kdc server could be contacted. The kdc service is running, but I have not rebooted the server until tonight.
Can anyone give me a pointer on the next step to troubleshoot?
Thanks!!
Lannie
lschafroth
Participanttime to switch to windows?
lschafroth
Participantcrickit…..crickit……
lschafroth
Participantyawn…..
lschafroth
ParticipantI take it from the lack of response that Kerberos is an impossible task on the MAC.
Lannie
lschafroth
ParticipantAnyone?
lschafroth
Participanthello??
lschafroth
ParticipantNo, I just want both the OSX machines and the XP machines to auth against the OpenDiretory on the Xserve and map them to their home directories. The home directory could be AFP and SMB depending on which type of OS they login with.
The XP machines would have to login to the domain but use only 1 certain local profile on the XP machine. No roaming profiles due to some extra programming and licensing in place.
Lannie
lschafroth
ParticipantAnyone?
lschafroth
ParticipantI take it from the lack of responses that this cannot be done and we need a seperate 2K3 server.
Lannie
lschafroth
ParticipantKnock knock…
-
AuthorPosts
Recent Comments