triggered something for me.
Per Nick:
Our laptops don't join the network untill after a user logs in, therefore
they do not get the proper Kerberos identity/ticket and it nicks up the DFS
connection.
On desktops we are finding that 10.6 will not auto renew the Kerberos
identity/ticket at the 10 hour expiration.
We are having an issue with 10.6 machines bound to AD, mainly with laptops,
where logging into the machine or clearing the screen saver password dialog,
when off network primarily, either does not work or takes an overly long
time. How long? Well, I've timed it on my laptop to take 4 minutes at
times. What I'm noticing is that in the secure.log I am seeing these two
errors:
3/6/11 10:43:11 PM authorizationhost[279] k5_authenticate(): got
-1765328164 (Cannot resolve network address for KDC in requested realm) on
/SourceCache/SecurityAgent/SecurityAgent-39574/plugins/krb5/krb5_operations.c:84
3/6/11 10:43:11 PM authorizationhost[279] -[SFBuiltinAuthenticate
performDSPasswordAuth](): got -1765328164 (Cannot resolve network address
for KDC in requested realm) on
/SourceCache/SecurityAgent/SecurityAgent-39574/authhostbuiltins.m:1039
I've been able to figure out that it is related to Kerberos, not just
because of the mention of the KDC in the errors, but because a klist shows
no open tickets.
Allen and I have been exchanging emails (and trying to test) some edits to
/etc/authorization (among other things) that would kerberize the screen
saver. Unfortunately both of our schedules have been so hectic that we
haven't been able to test lately.
I have opened two bug reports with Apple:
9093265
Unable to clear Screen Saver password in 10.6
AND
9184458
Long Delay in Authentication on 10.6 bound to Active Directory
So, has anyone else seen this, and does anyone have a solution?
Oh, and I'm seeing this on all version of 10.6 including 10.6.7.
Steve Wood
Director of IT
swood at integer.com
The Integer Group | 1999 Bryan St. | Ste. 1700 | Dallas, TX 75201
T 214.758.6813 | F 214.758.6901 | C 940.312.2475
