hhymwaa Posted February 26, 2015 Posted February 26, 2015 I have about 40 10.9 Macs on my AD Domain (plus OD server). Recently the two MacPros (one aluminium case and one black shiny ash tray) have lost their binding to the AD, so I have unbound them from both servers. I have then bound the MacPro to the OD, with no problem, but when I try to bind to the AD through the OD Utility >AD service (entering the FQDN then the domain admin account and password or DOMAIN\admin and password) I immediately get the message “Authentication server could not be contact acted”. · To resolve this I have checked · Server/client time is spot on · Pinging the DC is fine · DNS nslookup - fwd and rev to the DC is fine · I can mount a DC share · Dig –t ANY soa returns both DCs · Console – when console is cleared and I try to bind I get no log entries · Wireshark – I can’t see any traffic between the client and server except one MDNS entry I am not sure what steps to take next any thoughts
Quackers Posted February 26, 2015 Posted February 26, 2015 Is the time on the client the same as on your DC's?
hhymwaa Posted March 19, 2015 Author Posted March 19, 2015 Solved! We spent a lot of time trying to find this fault and trying to figure out if it was an OD AD or client Mac problem, we looked closely at our AD DNS as we had also noticed that our Global Catalog was slow to respond. We then remembered that Openhive/captia had asked us to turn off our DNS dynamic updates (last November) as they said that our DNS was trying to update their DNS server, we did this, and there seemed to be no problem, PCs would bind OK, DNS worked fine. So having tried almost everything we could think off we turned on the DNS dynamic updates, and within half an hour our Global catalog worked and the Macs bound to the AD! Here's Reg setting Captia sent us, we have now deleted this DWORD Value Click Start, click Run, type regedit, and then click OK. Locate and then click the following registry subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ Tcpip\Parameters On the Edit menu, point to New, and then click DWORD Value. Type DisableDynamicUpdate, and then press ENTER two times. In the Edit DWORD Value dialog box, type 1 in the Value data box, and then click OK. Note By default, the DNS update is enabled (0). Exit Registry Editor.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now