+ Post New Thread
Results 1 to 12 of 12
Mac Thread, Bindings to active directory stop working? in Technical; Hi All, Despite the fact that we have had macs running in our school for the whole school year I ...
  1. #1
    reggiep's Avatar
    Join Date
    Apr 2008
    Location
    In the vast area of space and time
    Posts
    1,550
    Thank Post
    518
    Thanked 56 Times in 50 Posts
    Rep Power
    30

    Bindings to active directory stop working?

    Hi All,
    Despite the fact that we have had macs running in our school for the whole school year I can still not claim that they have worked they way I wanted them to.
    Firstly they were local log on, then they were added to active directory THEN i went on a mac course and set up a mac server so that I could control the user experience while still letting users authenticate to active directory.
    My problem is that when I bind the workstations to both open and active directory the machines tend to lose the active directory and will not let users log on.
    It doesn't happen straight away. But when it does I have to remove the active directory binding and then add it again. The machine may work then for a day a week or more but then it will lose it again? there are 30 machines and every day I have resorted to logging in to them as a test user and then fixing the broken ones. this is time consuming and stupid!
    Does anyone have any ideas?
    Oh yeh I'm on 10.5.6.

  2. #2
    PEO
    PEO is offline
    PEO's Avatar
    Join Date
    Oct 2007
    Posts
    2,096
    Thank Post
    457
    Thanked 152 Times in 96 Posts
    Rep Power
    72
    glad you started this thread.... same boat

  3. #3
    reggiep's Avatar
    Join Date
    Apr 2008
    Location
    In the vast area of space and time
    Posts
    1,550
    Thank Post
    518
    Thanked 56 Times in 50 Posts
    Rep Power
    30
    It's always nice to know you are not the only one!
    Last edited by reggiep; 12th May 2009 at 11:01 AM.

  4. #4
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,491
    Thank Post
    10
    Thanked 502 Times in 442 Posts
    Rep Power
    114
    Server and clients both 10.5? 10.4 will corrupt the AD settings on a regular basis.

    Are you synchronising the time on the machines to the DC? When the stop working do a "sudo dsconfigad -show" to see if the domain name is still correct (this becoming part of the ldap oid was the issue on 10.4).

  5. #5

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,850
    Thank Post
    110
    Thanked 598 Times in 514 Posts
    Blog Entries
    1
    Rep Power
    227
    I recall DMcCoy having a hilarious time with these sorts of issues. I'll try and find his threads.

  6. #6
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,491
    Thank Post
    10
    Thanked 502 Times in 442 Posts
    Rep Power
    114
    Quote Originally Posted by Geoff View Post
    I recall DMcCoy having a hilarious time with these sorts of issues. I'll try and find his threads.
    I'm not sure hilarious is the word. 3 years of Apple hell? That's probably a better description!

    Up to 12 of 25 screens replaced now

  7. #7
    Marci's Avatar
    Join Date
    Jun 2008
    Location
    Wakefield, West Yorkshire
    Posts
    896
    Thank Post
    84
    Thanked 235 Times in 194 Posts
    Rep Power
    83
    Have you moved AD plugin to be positioned ABOVE the OD plugin the SearchPolicy list (Go > Utilities > Directory Utility) on your clients?

    Also, bear in mind that on boot, it takes a few minutes for the AD plugin to connect, so will refuse to login for up to 2 minutes - despite presenting you with a login box, the system still isn't completely ready to connect basically.

  8. #8
    reggiep's Avatar
    Join Date
    Apr 2008
    Location
    In the vast area of space and time
    Posts
    1,550
    Thank Post
    518
    Thanked 56 Times in 50 Posts
    Rep Power
    30
    Quote Originally Posted by DMcCoy View Post
    Server and clients both 10.5? 10.4 will corrupt the AD settings on a regular basis.

    Are you synchronising the time on the machines to the DC? When the stop working do a "sudo dsconfigad -show" to see if the domain name is still correct (this becoming part of the ldap oid was the issue on 10.4).
    I fired up terminal and typed the above.
    My domain is correct but the computer account is not!!

    When I go to sys prefs/sharing I see that the computer name is iMac-u40-011 but below that it says "computers can access this computer by going to iMac-u40-70.local"

    And at the terminal it gives that name too.

    Could this be the problem?

  9. #9
    reggiep's Avatar
    Join Date
    Apr 2008
    Location
    In the vast area of space and time
    Posts
    1,550
    Thank Post
    518
    Thanked 56 Times in 50 Posts
    Rep Power
    30
    Quote Originally Posted by Marci View Post
    Have you moved AD plugin to be positioned ABOVE the OD plugin the SearchPolicy list (Go > Utilities > Directory Utility) on your clients?

    Also, bear in mind that on boot, it takes a few minutes for the AD plugin to connect, so will refuse to login for up to 2 minutes - despite presenting you with a login box, the system still isn't completely ready to connect basically.
    Yep done that.

  10. #10

    Join Date
    Jan 2007
    Location
    The Console
    Posts
    236
    Thank Post
    22
    Thanked 29 Times in 23 Posts
    Rep Power
    22
    You can't bind to both. We bind to AD, but then add in our OD server to the LDAP list but do not bind. This allows logins via AD and management via OD/MCX. This set up (with 10.4 and 10.5 clients) works fine. Management is off a 10.5 server.

    There was a big fat bug in the 10.5.4 AD plug in which caused bindings to be lost whenever the machine felt like it, but using version 1.6.3 which went in to 10.5 works much more reliably.

  11. #11
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,491
    Thank Post
    10
    Thanked 502 Times in 442 Posts
    Rep Power
    114
    Quote Originally Posted by iSteve View Post
    You can't bind to both. We bind to AD, but then add in our OD server to the LDAP list but do not bind. This allows logins via AD and management via OD/MCX. This set up (with 10.4 and 10.5 clients) works fine. Management is off a 10.5 server.
    You can bind to both, it's perfectly fine with 10.5. With 10.4 it would just get upset unless you sorted out the kerberos records manually to stop it getting confused. Not that our OD contains any users anyway!

  12. #12
    PEO
    PEO is offline
    PEO's Avatar
    Join Date
    Oct 2007
    Posts
    2,096
    Thank Post
    457
    Thanked 152 Times in 96 Posts
    Rep Power
    72
    did a lot of swearing today but managed to get all the machines binded to the AD. all working now Dam mac's



SHARE:
+ Post New Thread

Similar Threads

  1. Replies: 0
    Last Post: 6th April 2009, 11:26 PM
  2. active directory
    By MrPstv in forum Windows Server 2000/2003
    Replies: 5
    Last Post: 26th March 2009, 08:26 PM
  3. Active Directory
    By Neville in forum Windows
    Replies: 6
    Last Post: 25th June 2008, 04:24 PM
  4. Replies: 7
    Last Post: 31st January 2008, 01:17 PM
  5. Certain letter keys stop working
    By EL_S in forum Windows
    Replies: 4
    Last Post: 9th June 2006, 05:37 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •