Kerberos Extension Issue

Priya98
New Contributor

Hi,

After updating macOS to 15.2.0, not able to sign in to Kerberos Extension. Showing Network credential not available. When trying to sign in getting error as "Your organization is not available". I tried command like kinit, kdestroy.

Any other suggestions? Would Appreciate any help.

 

Thanks.

Kerberos.png

13 REPLIES 13

AJPinto
Esteemed Contributor

Are you on a network that is able to see your domain? 

It's the same when i am connected to office network or home wifi. 

AJPinto
Esteemed Contributor

I would not expect it to work from home unless you have a VPN in place that is tunneling traffic back to your on prem network for this.

 

Can you ping the FQDN from the device?

Jason33
Contributor III

You may want to update/redeploy the /etc/krb5.conf file. Chance it may have gotten corrupt on that device.

 I have re-added the device to the conf profile jamf pro. Is there any other way I can try?

Shyamsundar
Contributor III

Did this issue in only one device or multiple devices affect with this, if its multiple devices i would check the connectivity, whether the AD is reachable from the Mac

2 devices as of now where 1 got fixed with just a restart but other one is not getting fixed. I ran kdestroy, kinit as well but no success.

obi-k
Valued Contributor III

When you open Terminal, enter this: 

dsconfigad -show

 

Do you get information returned? Maybe try to force unbind, then rebind.

Priya98
New Contributor

When I run dsconfigad -show, gives information which is correct. When running klist, it is giving error as "Cache not found" and kinit showing as "unable to reach any KDC in realm"

mainelysteve
Valued Contributor II

So just to confirm as others have asked and it's been danced around, are you able to ping the FQDN of the directory server(s)? You mention you re-added the configuration profile to the client. What did that entail? Typically removing a kerberos SSO extension config profile from a client requires a restart after the fact, at least in my past experiences. Are you binding to AD or another directory service or are you using the SSO extension with a local account?

Using SSO extension with local account. There is a config profile running in jamf pro and re-added the device and restarted.

obi-k
Valued Contributor III

When you click the Kerberos Key in the menu bar, is the user signed in? Able to sign them out?

Priya98
New Contributor

No, normally it shows Sign out, Change Password  and Reconnect. But for the user it is just showing up Sign in as the only option. And also in the Kerberos Key it is showing "Network Credentials not available", when trying to sign in it showing the error in the screenshot attached.