> On 01/06/2007, at 3:51 AM, Randall R. Saeks wrote:
> > On May 31, 2007, at 11:49 AM, David Colville wrote:
> >> Hi Randall,
> >> Have we still got AuthenticationAuthority values in the OD for
> >> these accounts?
> Hi Randy,
> That's interesting - and I'm assuming other accounts still have both
> records?
> > All it shows for that is the ;ApplePasswordServer;. I don't have
> > the Kerberos attribute.
Have you tried recreating the Kerberosv5 attribute (if its a small number of users ) ?
The only items user specific are the shortname (principal name) and the password server slot ID. i.e.
;Kerberosv5;0x455a0be17083b9270000001c00000017;
email@hidden;MY.EXAMPLE.COM;
The rest of it is just the public key for the password server,So if you have ApplePasswordServer attr then you already have a template to copy off of as they are almost identical. Just use dscl or the inspector in Workgroup Manager.
This most likely would only solve your symptom ( UI disabled ) and not the originating problem though.
You might also just that the still exist in the KDCs database as well
sudo kadmin.local -q listprincs | grep shortname
-Zack
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/email@hidden
This email sent to email@hidden