<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Kerberos Issues With Podcast Producer / XGrid on Leopard Server</title>
	<atom:link href="http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/</link>
	<description>Apple Certified Mac Consulting</description>
	<lastBuildDate>Mon, 09 Jan 2012 22:29:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: earl</title>
		<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/comment-page-1/#comment-3110</link>
		<dc:creator>earl</dc:creator>
		<pubDate>Mon, 06 Jun 2011 20:43:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard/#comment-3110</guid>
		<description>Brent:

My PcP initally worked. I could submit jobs, they would get processed etc, Kerberos works for both e-mail and Podcast Capture login.

Now it quit working. The PcP gui interface indicates it can&#039;t find it. The xcontroller activity logs indicate the agent has been contacted with a job to process. The actual xcontroller logs indicate it has shutdown. Something has clearly changed. Also the three

pcastadmin@MYREALM.CA
pcastuser@MYREALM.CA
pcastxgrid@MYREALM.CA

were never in my OD users list. I didn&#039;t try to create them though. The errors that you indicate above I don&#039;t see. It doesn&#039;t mean though that they are there and as soon as I get beyond where I am now they won&#039;t pop up. I believe worse case it to reinstall the software and start from scratch. It will work</description>
		<content:encoded><![CDATA[<p>Brent:</p>
<p>My PcP initally worked. I could submit jobs, they would get processed etc, Kerberos works for both e-mail and Podcast Capture login.</p>
<p>Now it quit working. The PcP gui interface indicates it can&#8217;t find it. The xcontroller activity logs indicate the agent has been contacted with a job to process. The actual xcontroller logs indicate it has shutdown. Something has clearly changed. Also the three</p>
<p><a href="mailto:pcastadmin@MYREALM.CA">pcastadmin@MYREALM.CA</a><br />
<a href="mailto:pcastuser@MYREALM.CA">pcastuser@MYREALM.CA</a><br />
<a href="mailto:pcastxgrid@MYREALM.CA">pcastxgrid@MYREALM.CA</a></p>
<p>were never in my OD users list. I didn&#8217;t try to create them though. The errors that you indicate above I don&#8217;t see. It doesn&#8217;t mean though that they are there and as soon as I get beyond where I am now they won&#8217;t pop up. I believe worse case it to reinstall the software and start from scratch. It will work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/comment-page-1/#comment-915</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Fri, 08 Aug 2008 18:34:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard/#comment-915</guid>
		<description>kadmin.local must be executed on the master Kerberos server, as root.

This makes me wonder if it&#039;s possible to run an Xgrid controller on an OD replica server. I&#039;ve tried getting it to work, but so far, no luck.

Another topic that I have yet to fully investigate is the issue of Kerberos slave (replica) servers in OSX Server. This article:

http://www.afp548.com/article.php?story=20060724104018616

... says that each OD replica becomes a Kerberos master server, and changes get replicated back to the other Kerberos masters by some unique-to-OSX mechanism. However, the article was written at the time of OS X Server 10.4. In 10.6, my OD replica doesn&#039;t appear to be a Kerberos master, and I cannot run kadmin.local on it.</description>
		<content:encoded><![CDATA[<p>kadmin.local must be executed on the master Kerberos server, as root.</p>
<p>This makes me wonder if it&#8217;s possible to run an Xgrid controller on an OD replica server. I&#8217;ve tried getting it to work, but so far, no luck.</p>
<p>Another topic that I have yet to fully investigate is the issue of Kerberos slave (replica) servers in OSX Server. This article:</p>
<p><a href="http://www.afp548.com/article.php?story=20060724104018616" rel="nofollow">http://www.afp548.com/article.php?story=20060724104018616</a></p>
<p>&#8230; says that each OD replica becomes a Kerberos master server, and changes get replicated back to the other Kerberos masters by some unique-to-OSX mechanism. However, the article was written at the time of OS X Server 10.4. In 10.6, my OD replica doesn&#8217;t appear to be a Kerberos master, and I cannot run kadmin.local on it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GEORGE</title>
		<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/comment-page-1/#comment-914</link>
		<dc:creator>GEORGE</dc:creator>
		<pubDate>Fri, 08 Aug 2008 07:08:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard/#comment-914</guid>
		<description>thank you for the answer, the thing is that I am still not able to start xgrid with kerberos authentication.

Here is the error from kadmin.local any other ideas would be really appreciated:

$ sudo kadmin.local
Password:
Authenticating as principal root/admin@SERVERNAME.DOMAIN.RO with password.
kadmin.local: No such file or directory while initializing kadmin.local interface</description>
		<content:encoded><![CDATA[<p>thank you for the answer, the thing is that I am still not able to start xgrid with kerberos authentication.</p>
<p>Here is the error from kadmin.local any other ideas would be really appreciated:</p>
<p>$ sudo kadmin.local<br />
Password:<br />
Authenticating as principal root/admin@SERVERNAME.DOMAIN.RO with password.<br />
kadmin.local: No such file or directory while initializing kadmin.local interface</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/comment-page-1/#comment-913</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Thu, 07 Aug 2008 16:31:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard/#comment-913</guid>
		<description>George, it must be executed with root privileges.  Prefix with &quot;sudo&quot;.</description>
		<content:encoded><![CDATA[<p>George, it must be executed with root privileges.  Prefix with &#8220;sudo&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GEORGE</title>
		<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/comment-page-1/#comment-912</link>
		<dc:creator>GEORGE</dc:creator>
		<pubDate>Thu, 07 Aug 2008 12:09:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard/#comment-912</guid>
		<description>hello

Interesting postings

I have the folowing:

$ sudo klist -k &#124; grep xgrid
   4 xgrid/servername.domain.ro@SERVERNAME.DOMAIN.RO
   4 xgrid/servername.domain.ro@SERVERNAME.DOMAIN.RO
   4 xgrid/servername.domain.ro@SERVERNAME.DOMAIN.RO
   3 xgrid@SERVERNAME.DOMAIN.RO
   3 xgrid@SERVERNAME.DOMAIN.RO
   3 xgrid@SERVERNAME.DOMAIN.RO


2. $ kadmin.local
Couldn&#039;t open log file /var/log/krb5kdc/kadmin.log: Permission denied
Authenticating as principal adminuser/admin@SERVERNAME.DOMAIN.RO with password.
kadmin.local: Permission denied while initializing kadmin.local interface</description>
		<content:encoded><![CDATA[<p>hello</p>
<p>Interesting postings</p>
<p>I have the folowing:</p>
<p>$ sudo klist -k | grep xgrid<br />
   4 xgrid/servername.domain.ro@SERVERNAME.DOMAIN.RO<br />
   4 xgrid/servername.domain.ro@SERVERNAME.DOMAIN.RO<br />
   4 xgrid/servername.domain.ro@SERVERNAME.DOMAIN.RO<br />
   3 <a href="mailto:xgrid@SERVERNAME.DOMAIN.RO">xgrid@SERVERNAME.DOMAIN.RO</a><br />
   3 <a href="mailto:xgrid@SERVERNAME.DOMAIN.RO">xgrid@SERVERNAME.DOMAIN.RO</a><br />
   3 <a href="mailto:xgrid@SERVERNAME.DOMAIN.RO">xgrid@SERVERNAME.DOMAIN.RO</a></p>
<p>2. $ kadmin.local<br />
Couldn&#8217;t open log file /var/log/krb5kdc/kadmin.log: Permission denied<br />
Authenticating as principal adminuser/admin@SERVERNAME.DOMAIN.RO with password.<br />
kadmin.local: Permission denied while initializing kadmin.local interface</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/comment-page-1/#comment-910</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Fri, 04 Apr 2008 07:07:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard/#comment-910</guid>
		<description>Also, try running:

&lt;fixed&gt;sudo serveradmin settings xgrid&lt;/fixed&gt;

If the FQDN of your kerberos server isn&#039;t in the prefs:ControllerName field, you can set it with:

&lt;fixed&gt;sudo serveradmin settings xgrid:AgentSettings:prefs:ControllerName = &quot;myserver.netmojo.ca&quot;&lt;/fixed&gt;

Yet another place to look for problems is in the plaintext xml file:

&lt;fixed&gt;/Library/Preferences/com.apple.pcastserverd.plist&lt;/fixed&gt;

I&#039;m interested to know how it goes.  Good luck!</description>
		<content:encoded><![CDATA[<p>Also, try running:</p>
<p><fixed>sudo serveradmin settings xgrid</fixed></p>
<p>If the FQDN of your kerberos server isn&#8217;t in the prefs:ControllerName field, you can set it with:</p>
<p><fixed>sudo serveradmin settings xgrid:AgentSettings:prefs:ControllerName = &#8220;myserver.netmojo.ca&#8221;</fixed></p>
<p>Yet another place to look for problems is in the plaintext xml file:</p>
<p><fixed>/Library/Preferences/com.apple.pcastserverd.plist</fixed></p>
<p>I&#8217;m interested to know how it goes.  Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brent</title>
		<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/comment-page-1/#comment-909</link>
		<dc:creator>Brent</dc:creator>
		<pubDate>Thu, 03 Apr 2008 21:30:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard/#comment-909</guid>
		<description>Did you have to change the &lt;fixed&gt;/private/etc/xgrid/controller/service-principal&lt;/fixed&gt; file?  If so, did you restart Xgrid and the KDC after changing it?  Is your actual FQDN equal to the name in that file, and does DNS resolve your IP address (forward and reverse lookups) to that name?</description>
		<content:encoded><![CDATA[<p>Did you have to change the <fixed>/private/etc/xgrid/controller/service-principal</fixed> file?  If so, did you restart Xgrid and the KDC after changing it?  Is your actual FQDN equal to the name in that file, and does DNS resolve your IP address (forward and reverse lookups) to that name?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jussi</title>
		<link>http://www.netmojo.ca/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard-server/comment-page-1/#comment-908</link>
		<dc:creator>Jussi</dc:creator>
		<pubDate>Thu, 03 Apr 2008 07:15:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.netmojo.ca/blog/2008/03/19/kerberos-issues-with-podcast-producer-xgrid-on-leopard/#comment-908</guid>
		<description>Hi,

for me this did not solve the problem with “agent could not determine the expected controller service principal”. My xgrid service principal and the one expected are the one and the same. Any ideas?

/jussi</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>for me this did not solve the problem with “agent could not determine the expected controller service principal”. My xgrid service principal and the one expected are the one and the same. Any ideas?</p>
<p>/jussi</p>
]]></content:encoded>
	</item>
</channel>
</rss>

