HodgeHi Posted May 21, 2012 Posted May 21, 2012 Have you been able to rule out any network drop-outs? I know that if OS X is running using networked based accounts that if the network disconnects for long enough then the clients will crash causing the issues that you see. Occasionally if the network comes back up in time the client may be able to restore functionality. If off long enough, the client will just freeze. Maybe the connection to the SMB share is dropping out causing the clients to freeze. Finder is unresponsive as soon as network connectivity is lost. Local home dirs would not be affected like this so would not show the symptoms even if the home dir is mounted. This may disappear but it wouldn't cause the system to crash. OS X is notoriously bad when used on a networked account as it doesn't download a copy like Windows does. It runs right from the server, hence the reason to redirect any folders that could be written to frequently. You could maybe open up an SSH tunnel to a client and then run a tail on the logs to see what is happening. If the network connection does drop-out your connection may be lost as a result and then you would know what the cause is.
iSteve Posted May 21, 2012 Posted May 21, 2012 This is odd. We run a couple of hundred Macs, authenticating against AD with files stored on OSX server shared over AFP with 10.6.8 on the client and server. We redirect all cashes to the local machine. Your problem is reminiscent of how we first had things under 10.4 with NO redirection. There has to be some sort of network problem here, either name resolution or caching. You could set your Macs to have portable home directories - similar to Windows where it downloads a copy rather than running off the network. How many clients connect before things start to go wrong, by the way?
Sheridan Posted May 21, 2012 Author Posted May 21, 2012 Theres 15 macs in the room - on the same network segment as maybe another dozen windows PCs. The problems can occur when only one Mac is in use and no Windows machines in use at all. I've tried moving to a difference network segment and switch but the problem can still occur. Its exactly as Hodgehi describes - I'll have to see if I can get one to hang regularly so I can test it in the hung state. Easier said than done with it being so variable when it happens.
Sheridan Posted May 29, 2012 Author Posted May 29, 2012 (edited) I'm going to try and do a fresh blank installation using a 10.6.8 image (I've just realised that the original disk was 10.6.5 and updates added to that) But where can I get a download for a full 10.6.8 install?, I can't find it on Apple site anywhere, just the update. I've also noticed an error today that doesn't seem to coincide with the 'hanging' but is relating to AD: gssd[2194] Major error = 851968: Unspecified GSS failure. Minor code may provide more information gssd[2194] Minor error = 100006: DirectoryService[15] GSSAPI Error: Unspecified GSS failure Minor code may provide more information (Server not found in Kerberos database) Does that error mean anything to anyone? Edited May 29, 2012 by Sheridan
JR-PCS Posted May 29, 2012 Posted May 29, 2012 There is not a full 10.6.8 installer that I'm aware of. You will need to use your 10.6.5 disk and update if you want a 10.6.8 image. 1
HodgeHi Posted May 29, 2012 Posted May 29, 2012 You could use this combo update package that would go from 10.6.5 to 10.6.8 in one go.
HodgeHi Posted May 29, 2012 Posted May 29, 2012 Also is this of any use? https://discussions.apple.com/thread/2441020?start=0&tstart=0 It seems to mention that the NFS service is being used to access home dirs, using Kerberos authentication. As your 2nd error is stating that your server is not is the kerberos Database, this could be your problem. If your users are set for any auth type it may be looking for kerberos and then falling back to the next auth type. You could possibly try to re-kerberise your services. Also if it is a AD-OD system, ensure that kerberos is not running on your OD. I think you have been through the klsit -kt commands before but if not then you could take a look at the results of that to see (if you are using NFS) that the service is kerberised. If it doesn't have the FQDN domain listed then you may need to kerberise the service again. 1
HodgeHi Posted May 29, 2012 Posted May 29, 2012 The command to kerberise all the services is sudo dsconfigad -enablesso
Sheridan Posted May 29, 2012 Author Posted May 29, 2012 (edited) Do you re-kerberise the services on the client or server, or both? I've checked klist and the services all show the FQDN of the mac. Today I've rebuilt a test mac from scratch (actually my original cd was 10.6.2) and used the 10.6.8 combo to get it up to date. Problem still occurs and has happened at least 5 times today! The last time it happened I had the Console open looking at the errors and the error that coincides with the hang is the same one I had ages ago, from smb_iod_sendall: Timed out waiting on the response for 0xa0 mid=0xdaf. The error above does show different hex values but its the one that always appears around the time of the hang. Oh Oh - doing a search for the above error brings up this: https://discussions.apple.com/thread/2769127?start=0&tstart=0 Which looks like I'm stuffed unless I upgrade them to 10.7 Edited May 29, 2012 by Sheridan
JR-PCS Posted May 29, 2012 Posted May 29, 2012 Lion is only £9.90 when buying 20+ licenses. I'm disappointed in my self for not suggesting that it could be incompatibility with your file server. I have seen this before, just last summer in fact. Good to know 10.7 could be the fix though.
Sheridan Posted May 29, 2012 Author Posted May 29, 2012 I looked into the smb issues a good while ago when we were all on 2003 server, however now its 50/50 whether the users are on 2003 or 2008 server and they all get the issue. So it does seem like the fault lies totally with osx 10.6. Nobody seems to have these issues with 10.5 that I can find!
HodgeHi Posted May 29, 2012 Posted May 29, 2012 The change probably came with Server 2008 using an updated SMB2 protocol. Lion Server is the only one that I know of that was released with support for this. I am using server 2003 across all of our servers and share out using both SMB and AFP. Is it possible to use AFP instead or are your shares on the windows server? The kerberising of the services is done on the server. Edit: I have just found an article that shows how to disable SMB2 signing. Could this help? http://www.petri.co.il/how-to-disable-smb-2-on-windows-vista-or-server-2008.htm
HodgeHi Posted May 30, 2012 Posted May 30, 2012 The last post in the Apple discussion thread you mentioned is an interesting one. Have you got CS5 installed on any of your macs? Could you remove a copy off one and se if the results are the same, or have you already tried a fresh install of just the OS with the combo update? Also just reading your last post regarding the klist. You say they all have the FQDN of the mac. Is this the mac server? I almost certain that if your services are kerberised by the AD then they should have the AD REALM after the service name. Mac Servers tend to add the server name at the beginning of the REALM name like server.example.com instead of just example.com. Here's a list of my services, kerberised by the AD. 72 05/14/12 14:42:41 imap/[email protected] 72 05/14/12 14:42:41 xmpp/[email protected] 72 05/14/12 14:42:41 fcsvr/[email protected] 72 05/14/12 14:42:41 http/[email protected] 72 05/14/12 14:42:41 ftp/[email protected] 72 05/14/12 14:42:41 afpserver/[email protected] 72 05/14/12 14:42:41 afpserver/[email protected] 72 05/14/12 14:42:41 afpserver/[email protected] 72 05/14/12 14:42:41 smtp/[email protected] 72 05/14/12 14:42:41 host/[email protected] 72 05/14/12 14:42:41 host/[email protected] 72 05/14/12 14:42:41 ipp/[email protected] 72 05/14/12 14:42:41 xgrid/[email protected] 72 05/14/12 14:42:41 xgrid/[email protected] 72 05/14/12 14:42:41 xgrid/[email protected] 72 05/14/12 14:42:41 vpn/[email protected] 72 05/14/12 14:42:41 vnc/[email protected] 72 05/14/12 14:42:41 nfs/[email protected] 72 05/14/12 14:42:41 nfs/[email protected] 72 05/14/12 14:42:41 vpn/[email protected] 72 05/14/12 14:42:41 pop/[email protected] 72 05/14/12 14:42:41 ldap/[email protected] 72 05/14/12 14:42:41 ldap/[email protected] 72 05/14/12 14:42:41 ldap/[email protected] 72 05/14/12 14:42:41 HTTP/[email protected] 72 05/14/12 14:42:41 HTTP/[email protected] 72 05/14/12 14:42:41 HTTP/[email protected] 72 05/14/12 14:42:41 cifs/[email protected] 72 05/14/12 14:42:41 cifs/[email protected] 72 05/14/12 14:42:41 cifs/[email protected] 72 05/14/12 14:42:41 pop/[email protected] 72 05/14/12 14:42:41 nfs/[email protected] 73 05/28/12 14:25:35 ipp/[email protected] 73 05/28/12 14:25:35 vnc/[email protected] 72 05/14/12 14:42:41 pop/[email protected] 73 05/28/12 14:25:35 vnc/[email protected] 72 05/14/12 14:42:41 pcast/[email protected] 72 05/14/12 14:42:41 pcast/[email protected] 72 05/14/12 14:42:41 pcast/[email protected] 72 05/14/12 14:42:41 XMPP/[email protected] 72 05/14/12 14:42:41 XMPP/[email protected] 72 05/14/12 14:42:41 XMPP/[email protected] 73 05/28/12 14:25:35 imap/[email protected] 73 05/28/12 14:25:35 xmpp/[email protected] 73 05/28/12 14:25:35 fcsvr/[email protected] 73 05/28/12 14:25:35 http/[email protected] 73 05/28/12 14:25:35 ftp/[email protected] 73 05/28/12 14:25:35 afpserver/[email protected] 73 05/28/12 14:25:35 afpserver/[email protected] 73 05/28/12 14:25:35 afpserver/[email protected] 73 05/28/12 14:25:35 smtp/[email protected] 73 05/28/12 14:25:35 host/[email protected] 73 05/28/12 14:25:35 host/[email protected] 73 05/28/12 14:25:35 host/[email protected] 73 05/28/12 14:25:35 ipp/[email protected] 73 05/28/12 14:25:35 vpn/[email protected] 73 05/28/12 14:25:35 xgrid/[email protected] 73 05/28/12 14:25:35 xgrid/[email protected] 73 05/28/12 14:25:35 xgrid/[email protected] 73 05/28/12 14:25:35 vpn/[email protected] 73 05/28/12 14:25:35 vnc/[email protected] 73 05/28/12 14:25:35 nfs/[email protected] 73 05/28/12 14:25:35 nfs/[email protected] 73 05/28/12 14:25:35 vpn/[email protected] 73 05/28/12 14:25:35 pop/[email protected] 73 05/28/12 14:25:35 ldap/[email protected] 73 05/28/12 14:25:35 ldap/[email protected] 73 05/28/12 14:25:35 ldap/[email protected] 73 05/28/12 14:25:35 HTTP/[email protected] 73 05/28/12 14:25:35 HTTP/[email protected] 73 05/28/12 14:25:35 HTTP/[email protected] 73 05/28/12 14:25:35 cifs/[email protected] 73 05/28/12 14:25:35 cifs/[email protected] 73 05/28/12 14:25:35 cifs/[email protected] 73 05/28/12 14:25:35 pop/[email protected] 73 05/28/12 14:25:35 nfs/[email protected] 73 05/28/12 14:25:35 pop/[email protected] 73 05/28/12 14:25:35 pcast/[email protected] 73 05/28/12 14:25:35 pcast/[email protected] 73 05/28/12 14:25:35 pcast/[email protected] 73 05/28/12 14:25:35 XMPP/[email protected] 73 05/28/12 14:25:35 XMPP/[email protected] 73 05/28/12 14:25:35 XMPP/[email protected] 1
mac_shinobi Posted May 30, 2012 Posted May 30, 2012 Edit: I have just found an article that shows how to disable SMB2 signing. Could this help? How to Disable SMB 2.0 on Windows Vista/2008 I used that article quite a while back when I did a guide for disabling SMB 2.0 on windows 7 as per attached pdf for scan to folder on Ricoh Copierswindows 7 scan settings v2.pdf 1
Sheridan Posted May 30, 2012 Author Posted May 30, 2012 (edited) The Mac I'm using for testing now has no CS5 on it - and the users I'm trying connect only to a Server 2003 share. I did look at the SMB2 issues a while back but as we were nearly all on 2003 and still 50% are I didn't follow that one up. When I look at klist on one of the failing macs the services all show similar (cifs,afpserver,vnc etc) I.e afpserver/[email protected] There seems to be two entries for each service, one as above and one with @domain.org.uk on the end Is that correct? I'm not sure how to troubleshoot kerberos! Edited May 30, 2012 by Sheridan
Sheridan Posted May 30, 2012 Author Posted May 30, 2012 Heres a dump of klist from one of the test macs: 1 host/[email protected] 1 host/[email protected] 1 host/[email protected] 1 host/[email protected] 1 host/[email protected] 1 [email protected] 1 [email protected] 1 [email protected] 1 [email protected] 1 [email protected] 1 cifs/[email protected] 1 cifs/[email protected] 1 cifs/[email protected] 1 cifs/[email protected] 1 cifs/[email protected] 1 vnc/[email protected] 1 vnc/[email protected] 1 vnc/[email protected] 1 vnc/[email protected] 1 vnc/[email protected] 1 afpserver/[email protected] 1 afpserver/[email protected] 1 afpserver/[email protected] 1 afpserver/[email protected] 1 afpserver/[email protected] 2 host/[email protected] 2 host/[email protected] 2 host/[email protected] 2 host/[email protected] 2 host/[email protected] 2 [email protected] 2 [email protected] 2 [email protected] 2 [email protected] 2 [email protected] 2 cifs/[email protected] 2 cifs/[email protected] 2 cifs/[email protected] 2 cifs/[email protected] 2 cifs/[email protected] 2 vnc/[email protected] 2 vnc/[email protected] 2 vnc/[email protected] 2 vnc/[email protected] 2 vnc/[email protected] 2 afpserver/[email protected] 2 afpserver/[email protected] 2 afpserver/[email protected] 2 afpserver/[email protected] 2 afpserver/[email protected] 1 [email protected] 1 [email protected] 1 [email protected] 1 [email protected] 1 [email protected] 7 host/[email protected] 7 host/[email protected] 7 host/[email protected] 7 host/[email protected] 7 host/[email protected] 7 afpserver/[email protected] 7 afpserver/[email protected] 7 afpserver/[email protected] 7 afpserver/[email protected] 7 afpserver/[email protected] 7 cifs/[email protected] 7 cifs/[email protected] 7 cifs/[email protected] 7 cifs/[email protected] 7 cifs/[email protected] 7 vnc/[email protected] 7 vnc/[email protected] 7 vnc/[email protected] 7 vnc/[email protected] 7 vnc/[email protected] Not being a kerberos expert I don't know whether that looks right or not!
HodgeHi Posted May 30, 2012 Posted May 30, 2012 Whats the output from the OD Master? Some services that are kerberised using the LKDC will have a long UID after the @ symbol, such as the AFP service.
HodgeHi Posted May 30, 2012 Posted May 30, 2012 Also if you check server admin and then the Overview of the OD service, Kerberos should be stopped. This is because if the server has used the kerberos realm of the AD server then it won't start ther kerberos service as it hasn't got it's own DB or something like that. If the kerberos service is running then this may indicate that the OD master has kerberised the services with it's own REALM. I don't know if this is causing your problem but it may cause issues with authentication if it was using 2 realms.
Sheridan Posted May 30, 2012 Author Posted May 30, 2012 (edited) OD Master (Xserve) output: 3 afpserver/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 3 afpserver/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 3 afpserver/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 3 cifs/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 3 cifs/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 3 cifs/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 3 vnc/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 3 vnc/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 3 vnc/LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619@LKDC:SHA1.B449178E8E43C29DED06A8AFADF5D443B9AD5619 43 nfs/[email protected] 43 pcast/[email protected] 43 xmpp/[email protected] 43 xmpp/[email protected] 43 pcast/[email protected] 43 nfs/[email protected] 43 xmpp/[email protected] 43 ldap/[email protected] 43 ldap/[email protected] 43 nfs/[email protected] 43 xmpp/[email protected] 43 ldap/[email protected] 43 http/[email protected] 43 http/[email protected] 43 xmpp/[email protected] 43 ldap/[email protected] 43 [email protected] 41 vnc/[email protected] 41 vnc/[email protected] 43 ldap/[email protected] 43 http/[email protected] 41 vnc/[email protected] 41 vpn/[email protected] 41 vpn/[email protected] 43 http/[email protected] 41 vnc/[email protected] 41 cifs/[email protected] 41 cifs/[email protected] 41 cifs/[email protected] 43 http/[email protected] 41 cifs/[email protected] 41 xgrid/[email protected] 41 XMPP/[email protected] 41 XMPP/[email protected] 41 vnc/[email protected] 41 xgrid/[email protected] 41 ftp/[email protected] 41 vpn/[email protected] 41 ftp/[email protected] 41 HTTP/[email protected] 41 cifs/[email protected] 41 vpn/[email protected] 3 XMPP/[email protected] 3 XMPP/[email protected] 3 XMPP/[email protected] 3 XMPP/[email protected] 3 xmpp/[email protected] 3 xmpp/[email protected] 3 xmpp/[email protected] 3 xmpp/[email protected] 3 xgrid/[email protected] 3 xgrid/[email protected] 3 xgrid/[email protected] 3 xgrid/[email protected] 3 vpn/[email protected] 3 vpn/[email protected] 3 vpn/[email protected] 3 vpn/[email protected] 3 vnc/[email protected] 3 vnc/[email protected] 3 vnc/[email protected] 3 vnc/[email protected] 3 host/[email protected] 3 host/[email protected] 3 host/[email protected] 3 host/[email protected] 3 smtp/[email protected] 3 smtp/[email protected] 3 smtp/[email protected] 3 smtp/[email protected] 3 cifs/[email protected] 3 cifs/[email protected] 3 cifs/[email protected] 3 cifs/[email protected] 3 pop/[email protected] 3 pop/[email protected] 3 pop/[email protected] 3 pop/[email protected] 3 pcast/[email protected] 3 pcast/[email protected] 3 pcast/[email protected] 3 pcast/[email protected] 3 ldap/[email protected] 3 ldap/[email protected] 3 ldap/[email protected] 3 ldap/[email protected] 3 ipp/[email protected] 3 ipp/[email protected] 3 ipp/[email protected] 3 ipp/[email protected] 3 imap/[email protected] 3 imap/[email protected] 3 imap/[email protected] 3 imap/[email protected] 3 http/[email protected] 3 http/[email protected] 3 http/[email protected] 3 http/[email protected] 3 HTTP/[email protected] 3 HTTP/[email protected] 3 HTTP/[email protected] 3 HTTP/[email protected] 3 ftp/[email protected] 3 ftp/[email protected] 3 ftp/[email protected] 3 ftp/[email protected] 4 ftp/[email protected] 4 ftp/[email protected] 4 ftp/[email protected] 4 ftp/[email protected] 3 fcsvr/[email protected] 3 fcsvr/[email protected] 3 fcsvr/[email protected] 3 fcsvr/[email protected] 4 cifs/[email protected] 4 cifs/[email protected] 4 cifs/[email protected] 4 cifs/[email protected] 3 afpserver/[email protected] 3 afpserver/[email protected] 3 afpserver/[email protected] 3 afpserver/[email protected] 4 afpserver/[email protected] 4 afpserver/[email protected] 4 afpserver/[email protected] 4 afpserver/[email protected] 3 nfs/[email protected] 3 nfs/[email protected] 3 nfs/[email protected] 3 nfs/[email protected] 3 nfs/[email protected] Edit - woops posted wrong output! klist output is too long to put all of it here. Edited May 30, 2012 by Sheridan
HodgeHi Posted May 30, 2012 Posted May 30, 2012 Is your DNS all A OK? There seems to be a few different hostnames in the list and also 2 realms. If you take a look at the one I posted up, you can see that it is a single hostname, fizz.eatonvalley.sandwell.sch.uk with a single kerberos realm @EATONVALLEY.SANDWELL.SCH.UK. This is also the name of the domain. The only way I know of getting this back to how it should be is demoting the server to a stand-alone server and then re-promoting. You may need to remove a kerberos file but I can't recall which one, either the krb5.keytab file or the edu.mit.kerberos file. If you back up your groups and users in WGM you back re-import them afterwards. However, you may need to re-create the managed preferences. These are backed up using server admin but this would also backup the possibly messed up kerberos DB/LDAP DB etc.
Sheridan Posted May 30, 2012 Author Posted May 30, 2012 DNS seems to be working ok - all macs and PCs can lookup and reverse lookup with no issues. Dig (-x) also resolves ok on the Macs I might try the demotion of the server, but that might have to wait until the holidays as its in use at the moment!
Sheridan Posted May 30, 2012 Author Posted May 30, 2012 Just to make sure I'm reading this right.... The hostname in your example (fizz.eatonvalley...) - is that the OD Server, or the client mac?
HodgeHi Posted May 30, 2012 Posted May 30, 2012 (edited) fizz is our OD Master (XServe). Fizz is connected to our AD in a Magic Triangle setup. All of the services are kerberised using the AD realm. Having just gone through my entire klist again, I don't have a single entry that has the OD Master realm. This server was built using 10.5 and upgraded in place to 10.6 and is not residing on 10.6.8. If you have to demote the OD master, it's not too bad to rebuild. The hardest part is reconfiguring the managed preferences if theres a good number of them. The users are easy as you will be pulling in the users from the AD and so the UIDs will be the same. The OD groups and any OD users can be imported back in once the server has been re-installed. Just use the WGM tool to export the users and groups. Make sure that any other items that have been configured are either backed up or noted so that these changes can be re-done. Edit: Klist -kt will only show the data for the machine it has been run on as far as I'm aware, which is why i was a little confused over yours but you edited the post with new info. Edited May 30, 2012 by HodgeHi
Sheridan Posted May 30, 2012 Author Posted May 30, 2012 I was looking at the mit.edu.Kerberos file in \Library\Preferences on the OD Master and the default_domain was set to ODMaster.domain.org.uk -I manually edited this and changed it to just domain.org.uk which I'm thinking is correct as it should be referencing the AD Realm, not itself? Anyway - saved the change and rebooted and klist still shows the two realms - the actual AD realm and the OD itself! Very odd.
HodgeHi Posted May 30, 2012 Posted May 30, 2012 Theres also the krb5.keytab file stored in the /etc folder. Just had a look at this file. It looks like the list of services kerberised and the server names associated with them. If you decide to touch any of this file you may want to make a backup first. You may also need to convert it to an XML file first as well.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now