PDA

View Full Version : Unable to install software when requiring admin password




tdubbz
Apr 11, 2013, 09:44 AM
I've been having an issue on an up to date 10.8 macbook pro retina-

I'm unable to install any software, such as java updates, flash, etc. WHen running the installer it prompts for my user password (which is an admin account) then does nothing. Any help appreciated!

System.log shows

Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_authenticate(): Got user: tdubbz
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_authenticate(): Got ruser: (null)
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_authenticate(): Got service: authorization
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in od_principal_for_user(): No authentication authority returned
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in od_principal_for_user(): failed: 7
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_authenticate(): Failed to determine Kerberos principal name.
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_authenticate(): Done cleanup3
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_authenticate(): Kerberos 5 refuses you
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_authenticate(): pam_sm_authenticate: ntlm
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_acct_mgmt(): OpenDirectory - Membership cache TTL set to 1800.
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in od_record_check_pwpolicy(): retval: 0
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in od_record_attribute_create_cfstring(): returned 2 attributes for dsAttrTypeStandard:AuthenticationAuthority
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Establishing credentials
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Got user: tdubbz
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Context initialised
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Got euid, egid: 0 0
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Done getpwnam()
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Done setegid() & seteuid()
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): pam_sm_setcred: krb5 user tdubbz doesn't have a principal
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Done cleanup3
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Done seteuid() & setegid()
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): Done cleanup4
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): pam_sm_setcred: ntlm
Apr 11 10:24:58 MBP.local authorizationhost[1227]: in pam_sm_setcred(): pam_sm_setcred: no domain found skipping
Apr 11 10:24:58 MBP.local com.apple.SecurityServer[15]: UID 501 authenticated as user tdubbz (UID 501) for right 'system.privilege.admin'
Apr 11 10:24:58 MBP.local coreservicesd[31]: Application App:"Install Adobe Flash Player" [ 0x0/0x8e08e] @ 0x0x7f8594024a90 tried to be brought forward, but isn't in fPermittedFrontASNs ( ( ASN:0x0-0x8f08f:) ), so denying.
Apr 11 10:24:58 MBP.local WindowServer[99]: [cps/setfront] Failed setting the front application to Install Adobe Flash Player, psn 0x0-0x8e08e, securitySessionID=0x186a6, err=-13066


I googled around and found this might be a gatekeeper issue.

I disabled it with sudo spctl --master-disable

Tried to install again -

Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_authenticate(): Got user: tdubbz
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_authenticate(): Got ruser: (null)
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_authenticate(): Got service: authorization
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in od_principal_for_user(): No authentication authority returned
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in od_principal_for_user(): failed: 7
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_authenticate(): Failed to determine Kerberos principal name.
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_authenticate(): Done cleanup3
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_authenticate(): Kerberos 5 refuses you
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_authenticate(): pam_sm_authenticate: ntlm
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_acct_mgmt(): OpenDirectory - Membership cache TTL set to 1800.
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in od_record_check_pwpolicy(): retval: 0
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in od_record_attribute_create_cfstring(): returned 2 attributes for dsAttrTypeStandard:AuthenticationAuthority
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Establishing credentials
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Got user: tdubbz
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Context initialised
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Got euid, egid: 0 0
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Done getpwnam()
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Done setegid() & seteuid()
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): pam_sm_setcred: krb5 user tdubbz doesn't have a principal
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Done cleanup3
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Done seteuid() & setegid()
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): Done cleanup4
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): pam_sm_setcred: ntlm
Apr 11 10:40:05 MBP.local authorizationhost[1407]: in pam_sm_setcred(): pam_sm_setcred: no domain found skipping
Apr 11 10:40:05 MBP.local com.apple.SecurityServer[15]: UID 501 authenticated as user tdubbz (UID 501) for right 'system.privilege.admin'
Apr 11 10:40:11 MBP com.apple.launchd[1] (com.apple.auditd[1410]): Exited with code: 1
Apr 11 10:40:11 MBP com.apple.launchd[1] (com.apple.auditd): Throttling respawn: Will start in 10 seconds


I then thought it was tied to the user account, so I tried to go to sys pres, users. I then clicked the lock to allow changes, entered the password, and it did nothing! It did not unlock the lock.

This was in the log

Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_authenticate(): Got user: tdubbz
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_authenticate(): Got ruser: (null)
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_authenticate(): Got service: authorization
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in od_principal_for_user(): No authentication authority returned
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in od_principal_for_user(): failed: 7
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_authenticate(): Failed to determine Kerberos principal name.
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_authenticate(): Done cleanup3
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_authenticate(): Kerberos 5 refuses you
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_authenticate(): pam_sm_authenticate: ntlm
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_acct_mgmt(): OpenDirectory - Membership cache TTL set to 1800.
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in od_record_check_pwpolicy(): retval: 0
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in od_record_attribute_create_cfstring(): returned 2 attributes for dsAttrTypeStandard:AuthenticationAuthority
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Establishing credentials
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Got user: tdubbz
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Context initialised
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Got euid, egid: 0 0
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Done getpwnam()
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Done setegid() & seteuid()
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): pam_sm_setcred: krb5 user tdubbz doesn't have a principal
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Done cleanup3
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Done seteuid() & setegid()
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): Done cleanup4
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): pam_sm_setcred: ntlm
Apr 11 10:42:52 MBP.local authorizationhost[1435]: in pam_sm_setcred(): pam_sm_setcred: no domain found skipping
Apr 11 10:42:52 MBP.local com.apple.SecurityServer[15]: UID 501 authenticated as user tdubbz (UID 501) for right 'system.preferences.accounts'
Apr 11 10:42:52 MBP.local coreservicesd[31]: Application App:"System Preferences" [ 0x0/0xa30a3] @ 0x0x7f859142f3b0 tried to be brought forward, but isn't in fPermittedFrontASNs ( ( ASN:0x0-0xb20b2:) ), so denying.
Apr 11 10:42:52 MBP.local WindowServer[99]: [cps/setfront] Failed setting the front application to System Preferences, psn 0x0-0xa30a3, securitySessionID=0x186a6, err=-13066