Posted on 02-19-2016 06:38 AM
I have a scenario where Kerberos is not working as desired. An User is working with a valid kerberos ticket and end of the day s/he closes the laptop instead of log off or shutdown. When the user enters the password and tries to mount a smb share or use a browser if the ticket is expired, it doesn't generate a new ticket.
Is there a way to generate kerberos ticket when it is expired without the user doing it manually?
Solved! Go to Solution.
Posted on 02-20-2016 03:06 AM
@swaroopmj typically a VPN connection will not create a Kerberos ticket.
KerbMinder might help.
Posted on 02-19-2016 07:17 AM
So far the easiest way I've found is to have the user start screen saver and unlock the screensaver. This will grant you your Kerberos tgt.
This however requires you to be connected to your network, be bound to AD, and have a password protected screensaver.
Connecting to VPN should also grant you a tgt iirc.
Curious to see what else is out there.
Posted on 02-19-2016 07:44 AM
In my test, I did connect to VPN before trying to mount my share. It prompted for my AD password. I was also under the impression, connecting to VPN will generate a ticket, but it didn't.
Posted on 02-20-2016 03:06 AM
@swaroopmj typically a VPN connection will not create a Kerberos ticket.
KerbMinder might help.
Posted on 02-20-2016 04:20 AM
Posted on 02-22-2016 08:02 AM
we had this exact problem with our old Sophos Proxy, KerbMinder alleviated most of those problems.
Before that we were just refreshing the ticket from Ticket Viewer which is in Applications>Utilities>Ticket Viewer.
Posted on 02-23-2016 06:21 AM
Talk to your Apple rep about Enterprise Connect. It will take care of this.