Mac Thread, Lion Server AD-OD setup in Technical; Hello,
Just a heads up really. I ran into a slight issue when trying to configure Lion Server as a ...
21st June 2012, 01:43 PM #1
Lion Server AD-OD setup
Just a heads up really. I ran into a slight issue when trying to configure Lion Server as a home dir for my windows users. I eventually sorted this out (which is another thread). Whilst trying to resolve this issue though I came across something that I think is slightly different in Lion Server than 10.6.
The order in which you list the directory bindings does seem to have an effect on things, most importantly the kerberos realm. While the OD server was listed first, the REALM being used was the ODSERVER.REALM.COM rather than the AD's REALM.COM. When running the kinit command the server had no cached credentials for AD users (had no OD users to test). When changing the order to AD first, the server then cached the credentials as expected for AD users but also used the AD REALM.COM. It seems that depending on which server is in the list first, directly impacts which kerberos realm is going to be used. It can change on the fly too without any reboots/terminal commands.
I don't think this was the case in 10.6
IDG Tech News
21st June 2012, 03:20 PM #2
I remember with previous versions to 10.7 it was always suggested that you disable kerberos. When setting up integration in the correct steps it does this for you. But because lion uses a different version of kerberos it does not need to be done now.
21st June 2012, 04:48 PM #3
Yes, you are right. Lion uses Heimdal as opposed to the MIT kerberos. However, the point I probably managed to hide in my post is that lion server will kerberise depending on the Directory Services list order. Take for example, the OD REALM is OD.EXAMPLE.COM and the AD is EXAMPLE.COM.
If the AD is first in the list then the realm used would be EXAMPLE.COM. But if the OD server was first in the list the realm used would be OD.EXAMPLE.COM.
Try it and see if you get the same results. Switch the list order around and then run the kinit AD username and see the results. If the OD server is first the cache would be empty and the realm would be the OD one.
Last Post: 24th May 2012, 11:23 AM
By Laphan in forum Windows Server 2000/2003
Last Post: 24th August 2011, 09:39 PM
By chrissmall in forum Mac
Last Post: 19th November 2010, 07:40 AM
Last Post: 7th September 2007, 01:22 PM
Last Post: 7th September 2007, 01:05 PM
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)