AD bound 10.7 Mac and Entourage 2008 - issues with kerberos

jhalvorson
Valued Contributor

Now that we are binding 10.7.3 devices to AD using the Directory Binding feature in Casper, our users are running into an issue when setting up Entourage.

When the users opens Entourage 2008 for the first time, the account setup wizard is attempting to use the identify of the Kerberos ticket instead of prompting for domain, user, and password. The only work around I have found is to delete any tickets within ticket viewer, then relaunch Entourage.

The computers are binding to AD correctly during the Casper Imaging process. Domain users can log into the Mac. Single Sign On is working when connecting to SMB department shares.

Between offering SSO versus an easy way for customers to setup Entourage, I would give up SSO until we get to Exchange Server 2010 and Outlook 2011.

Our Exchange admin are focused on getting to Exchange 2010 and aren't able to look into the identity issue with Exchange 2003 servers.

How do I disable kerberos? And is that the proper solution?

2 REPLIES 2

talkingmoose
Moderator
Moderator

You can't disable Kerberos in Entourage. It's just an authentication option like using name/password.

Are you allowing folks to set up their own Exchange account? If so, you need to instruct them to click the Configure Account Manually button in the Account Setup Assistant window. They should then select the option Use my account information instead of Use Kerberos authentication.

jhalvorson
Valued Contributor

Update - The temporary solution has been to use "Ticket Viewer" to remove any valid identities and then run the Entourage 2008 account setup process. That allows our users to manually enter their AD user name and password.

We started migrating to new Exchange 2010 servers. Life is much better for setup. After a user's mailbox is migrated and now that the the our autodiscover feature is working, users can manually enter their username/password or choose to use Kerberos ID when using Entourage 2008 EWS. Either method works.

Once everyone is migrated, the extra education required for setup with Entourage 2008 (WebDAV) won't be an issue.