AFP support for DHX2 authentication mechanism on OES
This document (7008683) is provided subject to the disclaimer at the end of this document.
Environment
AFP
Novell NetWare 6.5 SP 8
Situation
Error: "The version of the server you are trying to connect to is not supported. Please contact your system administrator to resolve the problem".
Unable to mount AFP shares
Resolution
/etc/opt/novell/afptcpd/afptcpd.conf
AUTH_UAM DHX2
If necessary, change it so it shows DHX2 and restart AFP. Take care not to get in a condition where DHX2 has been enabled, but you have followed the following steps previously.
For OES Netware:
Disable DHX2 authentication on the MAC 10.7 or later workstations.
Steps to disable DHX2 on the MAC workstation:
- Using terminal, enter:
sudo defaults write /Library/Preferences/com.apple.AppleShareClient afp_disabled_uams -array DHX2
Unless you are logged in as the root user, you will be prompted for a password.
Now Mac OS X Lion (10.7) and later will be able to mount AFP volumes on NetWare 6.5 SP8 just as it did before the Lion update.
Status
Reported to EngineeringAdditional Information
By default, MAC 10.7 tries to authenticate with DHX2.
Please note that the workaround for NetWare mentioned above essentially removes the 'typical' disabled UAM's (Cleartext, Two-Way Random Number Exchange) and replaces them to disable DHX2 only. This means that IF the administrator has enabled Cleartext on the server-side (not default); it is possible that it will be used. Special care should be taken to ensure the server-side AFP system is set to allow the most 'secure' method of authentication that is feasible for your environment.
If you'd like to roll back these changes, and return to a 'default' setup, execute the following command:
sudo defaults write /Library/Preferences/com.apple.AppleShareClient afp_disabled_uams -array "Cleartxt Passwrd" "MS2.0" "2-Way Randnum exchange" "DHCAST128"
More information can also be found at: http://support.apple.com/kb/HT4700
Disclaimer
This Support Knowledgebase provides a valuable tool for NetIQ/Novell/SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:7008683
- Creation Date:01-JUN-11
- Modified Date:15-NOV-12
- NovellOpen Enterprise Server
Did this document solve your problem? Provide Feedback