In Mac OS X, how do I authenticate against IU's Kerberos realm?
Note: Mac systems bound to the Active Directory at Indiana University do not need the Kerberos configuration found here. For detailed information on Mac systems in multiuser environments, local support providers (LSPs) can contact IT Professional Services and Support.
To authenticate against IU's Kerberos realm in Mac OS X, follow the appropriate instructions below.
Mac OS X 10.7 (Lion)
- In the
Applicationsfolder, open theUtilitiesfolder. Then, openKeychain Access.
- From the
Keychain Accessmenu, selectTicket Viewer.
- Click
Add Identity. Enterusername@ADS.IU.EDU, replacingusernamewith your Network ID username.Note:
ADS.IU.EDUmust be in all capital letters. - Enter your Network ID passphrase.
- Click
Continueto get your initial Kerberos ticket.
- To make this your default Kerberos identity, click
Set as Default.
Older versions of Mac OS X
- The easiest way to configure older versions of Mac OS X to
authenticate against Indiana University's Kerberos realm (ADS.IU.EDU)
is to install the IU Kerberos Assistant. Download IU Kerberos
Assistant from IUware.
Note: The Kerberos Assistant will install the
edu.mit.Kerberosfile in the user domain (~/Library/Preferences/), not the local domain (/Library/Preferences/) as in the instructions below. Installing the file in the local domain makes it available to all users on the computer.Alternately, to configure your settings manually:
- Obtain the Indiana University
krb5.conffile. - Rename the
krb5.conffile toedu.mit.Kerberosand place it in the following directory: /Library/Preferences/If you already have an
edu.mit.Kerberosfile, you may already be able to use Kerberos authentication. - Navigate to the directory
/System/Library/CoreServices/. In Mac OS X 10.6, find the Ticket Viewer application; in Mac OS X 10.5 or 10.4, find the Kerberos application. Drag the application icon to the Dock for easy access.Note: In Mac OS X 10.5 and 10.6, you can access the application from the Keychain Access application in
/Application/Utilities/. In theKeychain Accessmenu, selectTicket Viewer(10.6) orKerberos(10.5).
- Obtain the Indiana University
- Open the Kerberos application and do the following:
- In Mac OS X 10.6, select
Get Ticket. In Mac OS X 10.5 and 10.4, in the application window, clickNew. - In the "Name:" field, enter your IU Network ID username.
- Make sure the Realm is set to
ADS.IU.EDU. - Enter your IU Network ID passphrase and click
OK. A Kerberos ticket should appear in the Kerberos application window.
- In Mac OS X 10.6, select
- Try to connect to a Windows share or other Kerberos-enabled resource. You should not need to re-enter your Network ID to make the connection.
Note: Kerberos authentication only works while on the IU network. When you are not on the IU network, you will need to use VPN.
Last modified on November 16, 2011.







