If you get an invalid Kerberos ticket with a Login Window profile and FileVault 2

If you turn on FileVault 2 and install an 802.1x Login Window profile, you get an expired Kerberos ticket upon login. Learn how to get a valid ticket.

If you need a Login Window profile and FileVault 2, here are ways you can get a valid Kerberos ticket.

Turn off automatic login

In OS X Mavericks and later, you can turn off automatic login when you use FileVault. You get a Kerberos ticket when you log in via the Login Window.

Use the kinit command

You can use the kinit command to request a new ticket. In Terminal, enter this command and then your password when prompted:


Use the Ticket Viewer app

Here’s how to use the Ticket Viewer app to request a ticket:

  1. Open Ticket Viewer at /System/Library/CoreServices/Ticket Viewer.
  2. Click the Add Identity button.
  3. Enter your identity and password, such as testuser@example.com.
  4. Click Continue.
Last Modified: