Mac OS X Leopard and Kerberos

Posted on July 9th, 2008 in os x by jeremyp

I recently had to set up a new Mac Pro running OS X Leopard (10.5) to run on our network. All of our other Macs are currently running Tiger (10.4), but this new quad-core machine can not. Upon trying to get Kerberos authentication (GSSAPI), I ran into a little bit of a snag that took me a little while to figure out.

On Tiger, the minimal Kerberos configuration file (/Library/Preferences/edu.mit.Kerberos) needed to look like this:

[libdefaults]
  default_realm = EXAMPLE.COM

This setup assumes that the Kerberos realm matches the DNS domain name of the machine, and also depends on the proper DNS SRV records being set up. However, when I copied this file to the Leopard machine, it didn’t seem to work properly. After a little troubleshooting, I found that I needed to add the following section the the configuration file:


[domain_realm]
  .example.com = EXAMPLE.COM
  example.com = EXAMPLE.COM
 

This section maps the DNS domain name to the Kerberos realm. For whatever reason, this used to happen automatically, but now it needs to be stated explicitly. Go figure…

Hopefully this saves someone else out there some time! 

4 Responses to 'Mac OS X Leopard and Kerberos'

Subscribe to comments with RSS or TrackBack to 'Mac OS X Leopard and Kerberos'.

  1. Libby MurrayNo Gravatar said,

    on May 19th, 2010 at 3:19 am

    What company is the best Domain Registrar? i’ve heard that Godaddy and Moniker are the best.,.`

  2. Alexa StewartNo Gravatar said,

    on July 18th, 2010 at 9:19 pm

    i always buy domain names at Godaddy or Moniker because they are the most reliable registrars.~~

  3. Kevin MitchellNo Gravatar said,

    on October 7th, 2010 at 12:55 pm

    domain names should be as short as possible and easy to remember, i alway use Godaddy when signing up new domain names-,;

  4. Acne Remedy :No Gravatar said,

    on October 22nd, 2010 at 1:14 pm

    it is always great to find a domain that has the same name as the product that you are trying to promote-”*

Post a comment