Jump to content

Macs often refuse authentiaction against AD


Recommended Posts

Posted

We have 20 iMacs in our music department and we used Directory services to set up AD authentication with our Windows 2003 server. Authentication works, but every couple of days it decides not to work and we need to go back in to Directory Services, unbin from the AD server and rebind and then it works fine for another few days. It is driving our head of music mad!

 

Anyone else had this? Anyone know a solution? We will throw money at an Apple server if this is going to fix it but the when the authentication works it is fine and users log on correctly and everything is locked down just like it is on Windows clients.

 

We use Ranger on our network - if that makles any difference.

 

Thanks in advance for any help you guys can offer . . .

Posted

I haven't experienced that problem myself so i don't know what the solution is. Maybe you could post the system.log from an affected mac for us to look at.

I can tell you that buying an OSX server won't hold the problem in any way as it is still the client machines that communicate with your AD servers.

 

Matt

Posted

I would log in locally when you cannot log in and check that the time is correct. I have had problems before with the clock being 1 hour fast.

 

By the way what version of OS 10 do you use?

 

Ross

Posted
You're probably aware of this, but just making sure, with regards to authentication not taking place. Do ensure that the system time on the Mac's is exactly the same as the OS X Server and Windows Domain Controllers. Otherwise authentication fails; a security feature part of Mac OS X I believe.

 

You'd be surprised how long it took me to work out why every now and then a Mac or two would stop authenticating!

 

I posted this a while ago on another thread http://edugeek.net/forums/showthread.php?p=120952.

 

You could possibly be having the same issue. Perhaps running your own NTP server might help?

Posted

Thanks, guys, it could well be the time settings. I will check in the morning and if the time has drifted will set up time syncing with the server.

 

Fingers crossed that you've hit the nail on the head!

 

I will report back.

Posted

Unfortunately it wasn't a clock issue. The time on the Macs and on the servers is in perfect synch :(

 

I tried logging onto a Mac today, which wouldn't log me on. I logged on locally and tried accessing a logfile. Which logfile should I be looking at? System.log? There didn't appear to be anything in it of any relevance to AD authentication.

Posted

I now have a system.log file which shows us trying to log in as an AD user. Some of the messages are a bit cryptic so if anyone can shed any light on the problem I'd be most grateful.

 

The logfile is available by clicking here

Posted
Try putting DirectoryServices in debug mode with a "killall -USR1 DirectoryService", then tail the log with, "tail -f /Library/Logs/ DirectoryService/DirectoryService.debug.log | grep ADPlug" and watch it while you bind. Make sure you reboot or killall DirectoryService again so you don't grow a giant log file.
Posted

I've spent many hours sat in front of the AD debug logs, and its never been very helpful :(

 

What sort of "unable to login" are you getting? The shaking screen or the AFP or SMB share is unavailable message?

 

If it happens at boot then it can be because the DS plugin takes a while to start up.

Posted
We get the shaking screen time after time. If we log in to the local machine and unbind, then rebind, we can subsequently log in successfully with an AD username/password. The first attempt after rebinding always results in an smb error - a message telling us that we are attempting to login to an smb volume. The second time always works fine. Things will remain fine for several days, then we are back to square one.
Posted
We get the shaking screen time after time. If we log in to the local machine and unbind, then rebind, we can subsequently log in successfully with an AD username/password. The first attempt after rebinding always results in an smb error - a message telling us that we are attempting to login to an smb volume. The second time always works fine. Things will remain fine for several days, then we are back to square one.

 

To solve that:

 

sudo nano /etc/hostconfig

 

and change automount from -auto- to -no- (or equivalent, can't remember off hand if it's no or disabled)

Posted

Jan 23 10:51:05 MC-MU1-04 DirectoryService[44]: Active Directory: Could not determine closest Domain Controller from Site information in directory

The above error from your log.

 

When you bind to AD. Try defining the server. I know it's possible but once again can't remember off hand. If you're stuck give me a shout and i'll have a look on a mac on monday.

 

Matt

Posted
Jan 23 10:56:52 MC-MU1-04 /System/Library/CoreServices/mcxd.app/Contents/MacOS/mcxd: DSOpenNode(): dsOpenDirNode("/Active Directory/All Domains") == -14002

 

That looks to be your error.

 

Just a few questions. Have you binded your mac server to Active directory? Did you add a kerberos realm as well if you added the mac server to AD?

 

Also try the auto mount fix that fixed a lot of problems for me. You may also wanna try the easy fix is to rebind the workstation to AD.

 

Ross

Posted (edited)

Thanks for your help, guys. I am trying the /etc/hostconfig automount solution this morning.

 

In reply to Ross, we don't have any sort of Mac server, we are authenticating directly against AD. I used Directory Services to set up AD authentication and binded it. Not sure what a kerberos realm is :-(

 

Cheers.

Edited by scgf
Posted

I've found an even worse bug in 10.5.1 that you can look forward to.

 

Once I have logged in, no other users can login until the machine is rebooted due to some permissions issue on the mount. :mad:

  • 5 weeks later...
Posted

Resurrecting an old topic, but I've just had two machines with broken AD.

 

When I looked in the AD plugin the details for the AD domain were some random entries, not the correct domain. It's a bit odd that it has managed to change all by itself, but I don't think anyone else could have changed it as the binding was still active.

Posted

We had a music technician with local admin access on the music macs and after there had been some building work in the lab the macs were all out of order. Rather than pick them up and move them he decided to rename them ... or rather he renamed the share name as he understood bugger all about how they were hooked up to the AD (not that we would have given him that access!).

 

This did cause us problems of bizarre computer names that didn't match up to those in the AD and so binding was subsequently broken. The annoying thing was that this tool a few weeks to develop and it happened a bit at a time. It was only after we had to rename and fix 4 machines that I went round and check them all.

Posted

The biggest problem I find with os x is problem diagnosis. While there are extensive logs, they don't actually contain very much useful information.

 

This leads to a great deal of shouting at various machines because the "shaking log on box" doesn't actually convey much as an error :p

Posted
I've found an even worse bug in 10.5.1 that you can look forward to.

 

Once I have logged in, no other users can login until the machine is rebooted due to some permissions issue on the mount. :mad:

Hi,

 

Did you ever resolve this problem, I am getting the same issue. I can login as one user on my imac (AD user). Try to login as a different user and no avail. Are there any fixes for this.

 

Regards

 

Steve

Posted
Hi,

 

Did you ever resolve this problem, I am getting the same issue. I can login as one user on my imac (AD user). Try to login as a different user and no avail. Are there any fixes for this.

 

Regards

 

Steve

 

I've not fixed it as so far it's only my machine running 10.5. I think it might be something to do with administrative privileges though and what happens to the auto mount folders. Try a non admin test user after a reboot and then see if another normal user can login afterwards.

Posted

Now the iMac seems to have a mind of its own, I can log off from an AD account and it refuses to logon to another.

 

Ill try the first account and it refues, try another account and this time it will log me on. There doesn't seem to be any hard and fast rules.

 

Has anybody out there had a similar issue.

 

Regards

 

Steve.

  • 1 month later...
Posted

I have worked out what the problem with trying to relogin as another user is with 10.5. When the first user logs in, the sharepoint for their home folder is mounted, when they logout it is not unmounted and remains "busy" is you try to unmount it manually. If the next user to attempt login has a folder on the same sharepoint then they can login. If they do not, you get the error message appear when you try to login (not just the shake).

 

I've been testing (a little - need more) with disabling automount for network drives, the user still gets their home folder mounted by the ad plugin, but it no longer remains mounted when they logout so another user will login sucessfully. I have no idea if there are any bad side effects yet, but I really don't want a single sharepoint for all user folders. I have commented out the the following in the /etc/auto_master config file as below

 

#/Network/Servers       -fstab

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...