Sheridan Posted May 30, 2012 Author Posted May 30, 2012 Theres also the krb5.keytab file stored in the /etc folder. Just had a look at this file. It looks like the list of services kerberised and the server names associated with them. If you decide to touch any of this file you may want to make a backup first. You may also need to convert it to an XML file first as well. Is the krb5.keytab file generated by the OD Master? - mine shows as a binary file so I'm not keen to mess about with it whilst the server is in use
HodgeHi Posted May 30, 2012 Posted May 30, 2012 I think it is. It is usually generated from a default file.
Sheridan Posted June 1, 2012 Author Posted June 1, 2012 I've tried again - flat install of 10.6.2 and upgraded to 10.6.8 with the combo. Added no applications and joined to the AD domain and then OD. Logged in and within 10 minutes I see the smb_iod_sendall error in the log. So I guess unless we upgrade to 10.7 (not worth it IMO) we're going to set these up as Windows 7 machines and ditch OSX for the time being. I might revisit this in another year and see if apple have managed to sort this out. Oddly enough - getting Windows 7 to work on these was considerably easier than I thought. Perhaps MS aren't so bad after all :-)
ste1988 Posted June 1, 2012 Posted June 1, 2012 I've tried again - flat install of 10.6.2 and upgraded to 10.6.8 with the combo. Added no applications and joined to the AD domain and then OD. Logged in and within 10 minutes I see the smb_iod_sendall error in the log. So I guess unless we upgrade to 10.7 (not worth it IMO) we're going to set these up as Windows 7 machines and ditch OSX for the time being. I might revisit this in another year and see if apple have managed to sort this out. Oddly enough - getting Windows 7 to work on these was considerably easier than I thought. Perhaps MS aren't so bad after all :-) Mountain lion will be nicely patched by then, and you can skip lion all together 1
Sheridan Posted June 1, 2012 Author Posted June 1, 2012 Whats after that? Sleepy Lion!? I managed to get rid of the double realms in the kerberos - by deleting the krb5.keytab file on both client and server.Both now show a simple list of services kerberized only by the AD domain. Has made no diffence to the lock ups but I do seem to get more lockups for users on one particular server. Whether this is anything relevant or not I don't know as the frequency is variable anyway. Working fine with Windows 7 though
ste1988 Posted June 1, 2012 Posted June 1, 2012 Whats after that? Sleepy Lion!? I managed to get rid of the double realms in the kerberos - by deleting the krb5.keytab file on both client and server.Both now show a simple list of services kerberized only by the AD domain. Has made no diffence to the lock ups but I do seem to get more lockups for users on one particular server. Whether this is anything relevant or not I don't know as the frequency is variable anyway. Working fine with Windows 7 though No i think they should leave the cat family alone after the next release, maybe elephant next
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now