[UniMacTech] Active Directory / Open Directory & Kerberos

Matthew Taylor mrtaylor at utas.edu.au
Thu Sep 11 11:22:50 EST 2008


Hi,

Has anyone had any luck binding a 10.5 client to both Active Directory  
and Open Directory with Kerberos working seamlessly?

I have 10.5 clients and 10.5 server.  The server is bound to the  
universities' Active Directory and feeding off the AD's kerberos.  I  
have groups in the 10.5 server that contain AD members.  The client  
10.5 machine is bound to BOTH the Active Directory and the 10.5 Open  
Directory.  Thus when I log on to the client using my Active Directory  
account I get in fine and the open directory group settings are  
correctly applied.

The problem is that when I go one step further and open iCal (or any  
other kerberised program) on the client after logging in I don't see  
the group calendar I set up on the OD server.  Also when I try to  
access the Group Wiki on the OD server it denies me access.

I am assuming this is some kind of kerberos problem.  I'd be keen to  
find out if anyone else out there has been able to set up this "magic  
triangle" authentication.

Regards,

Matt Taylor
Computer Support
Academy of the Arts
University of Tasmania
(03) 6324 4412




More information about the unimactech mailing list