Within the last two weeks we've had a very small percentage of users
begin getting error messages that they can't log into to their hosts
bound by our open directory server. These hosts are using network
homes off of a separate file server, which is bound and kerberized to
the same open directory server.
Both the open directory server and file server are running 10.4.8.
The file server's AFP access log is returning the following:
As I understand, the -5023 error specifies that the user is not
authorized. When I look at the Open Directory Password Service
Server Log, it appears that the user is authenticating successfully.
The timestamps between logs are only a few seconds.
The problem is intermittent and seems to only affect users
temporarily (thus far). It appears there was an issue like this in
10.3, that was addressed with the 10.3.3 update. Has anyone seen
this in Tiger?
Many Thanks--
Luke
The Open Directory Password Service Server Log is returning the
following:
Jan 31 2007 09:18:33 AUTH2: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} DIGEST-MD5 authentication succeeded.
Jan 31 2007 09:18:33 AUTH2: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} DIGEST-MD5 authentication succeeded.
Jan 31 2007 09:18:33 QUIT: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} disconnected.
Jan 31 2007 09:18:33 KERBEROS-LOGIN-CHECK: user
{0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, user1} is in good standing.
Jan 31 2007 09:18:34 KERBEROS-LOGIN-CHECK: user
{0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, user1} authentication succeeded.
Jan 31 2007 09:18:44 QUIT: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} disconnected.
Jan 31 2007 09:18:44 AUTH2: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} DIGEST-MD5 authentication succeeded.
Jan 31 2007 09:18:44 AUTH2: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} DIGEST-MD5 authentication succeeded.
Jan 31 2007 09:18:44 QUIT: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} disconnected.
Jan 31 2007 09:18:46 KERBEROS-LOGIN-CHECK: user
{0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, user1} is in good standing.
Jan 31 2007 09:18:46 KERBEROS-LOGIN-CHECK: user
{0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, user1} authentication succeeded.
Jan 31 2007 09:18:55 QUIT: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} disconnected.
Jan 31 2007 09:18:55 AUTH2: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} DIGEST-MD5 authentication succeeded.
Jan 31 2007 09:18:55 AUTH2: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} DIGEST-MD5 authentication succeeded.
Jan 31 2007 09:18:55 QUIT: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} disconnected.
Jan 31 2007 09:18:56 KERBEROS-LOGIN-CHECK: user
{0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, user1} is in good standing.
Jan 31 2007 09:18:57 KERBEROS-LOGIN-CHECK: user
{0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, user1} authentication succeeded.
Jan 31 2007 09:18:59 QUIT: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} disconnected.
Jan 31 2007 09:19:27 AUTH2: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} DIGEST-MD5 authentication succeeded.
Jan 31 2007 09:19:27 QUIT: {0xBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB,
user1} disconnected.