Did you check for open kerberos tickets? I am running into a verify similar issue. Deleting Kerberos tickets resolves this issue for me.
I ran a kdestroy -a but didn't look at ticket viewer to see if I had any active tickets. I'll take a closer look at this one and report back.
Still no luck. No open kerberos tickets when viewing Ticket Viewer.app or klist in terminal. I even re-installed Mavericks yesterday as a hail-mary.
Just tested mine: Works OK for me. (with clients: OSX 10.6.8 .. 10.9.0 )
My Distribution Point is on a Virtualised Mac OS X 10.6.8 Server, offering AFP, and HTTP.
Thanks Peter
My primary DP is 10.7.5, physical, offering AFP only. I feel like there may be something server-side that I can do to resolve it but I am drawing blanks as to what might be a solution.
Interesting solution... switching my primary DP to SMB as a protocol. Connected right up.
Hopefully AFP isn't broken in Mavericks as well.
Thanks all for your comments.
I noticed that I needed to hold down Option when launching Admin v9.2 on OS X 10.9 and re-specify the JSS address, after that it mounted fine.
Switching to SMB did resolve my issue as well. Thanks freddie!
I actually blew up the casperadmin/casperinstall accounts, removed from sharing, re-added & was able to mount. Server is running 10.8.5.
@freddie.cox & @jeffpugh on the macs where there is an issue, you should be able to find a CasperAdmin log file.
Can you check it? I wonder if the JSS is trying to mount //jss.fqdn/CasperShare & as we're now on 10.9 that changes to: SMB://jss.fqdn/CasperShare & not AFP://jss.fqdn/CasperShare as per pre-10.9.
Just wondering, as if that's the issue... Should be an easy fix for JAMF.
@bentoms Casper Admin / Remote loads without issue and mounts caspershare and everything works good if I don't have a kerberos ticket but with tickets I get negative results when using AFP.
I think our issue was I am using a service account (casperadmin) - you know the defaults for r/w access etc. I also setup svc accounts in AD with same shortname.This is what I used since v 5 of JSS - all worked fine.
What I did to fix was create a local account on the fileserver for AFP that doesn't have an associated AD account and I'm back in business.
@bentoms where is the log located, I was trying to find it and was unsuccessful.
@freddie.cox I think it's ~/Library/Logs/CasperAdmin.log
@bentoms The only thing that I have in that location is a Casper Admin Sync Log.log
I was hoping there was a way to access a log for Casper Admin to see what it was doing, but it doesn't appear to be writing one. Heck, I even ran composer while launching Casper Admin just to see what/where it was writing to.
@freddie.cox][/url
You can put the Casper Admin to Debug mode by just putting a file named "debug" in app's "Support" folder.
sudo touch /Applications/Casper Admin.app/Contents/Support/debug
Then do the test and grab the debug log file from;
~/Library/Logs/JAMF/CasperAdminDebug.log
or
~/Library/Logs/CasperAdminDebug.log
I think this method applies for all Casper Suite apps.
@Kumarasinghe][/url This was the nugget I was hoping to get out of this. Thanks so much.
After doing this I get this output:
Running Simple Shell Command:
'/Applications/Casper Suite/Casper Admin.app/Contents/Support/jamf' mount -type afp -server 'server_address' -share 'CasperDP' -username 'CasperUser' -passhash 'hashofpasswordhere' -visible
Simple Shell Result:
Mounting afp://server_address/CasperDP to /Volumes/CasperDP...
There was an error mounting the file server afp://server_address/CasperDP. Will attempt again.
Mounting afp://server_address/CasperDP to /Volumes/CasperDP...
There was an error mounting the file server afp://server_address/CasperDP. Giving up.
It appears the binary can't mount the dp for some reason and trying to run that manually in terminal results in the same error. Removing the password hash and using the -password flag also ends in a failed connection.
@Kumarasinghe nice one. That's what i was reaching for.
@freddie.cox can you map the drive via the GUI authenticating as the CasperAdmin user?
Do you have any special characters in the password? ?%*<$|*
Can you simplify the Casper admin password & then try?
@bentoms
-Yes, I can manually map the drive as the CasperAdmin user.
-Yes, I do have special characters.
-At this point I am too lazy to change the password as we have 14 DP's I would have to touch. :-)
@freddie.cox haha!
Can you change it for this 1 DP to see if it's the characters?
they have this recent invention called Directory Services, you can set the password on a server and all the rest of the computers that are connected to the directory service know the new password. You should try it :)
@nessts then give all domain users read access to the drive as it'll mount using Kerberos?
We use server local accounts + HTTPS secured to that account to stop people nosing around our share.
not sure my users are that smart to find the casper share and mount it and look around, and since they dont have admin rights. I figure if they have Self Service and can download and install the apps through that whats the harm in them viewing the share if they find it? Sorry i should not be a smarty pants and try to make humor.
@nessts.. Humour was fine & well placed (plus we NEED it here).
Just making a point... + mine are admins so why am I bothering? They can is install anything!!
Ok well old habits...
Right, now let's have a nose @ this new fangled directory whatjamajigger