scgf Posted January 19, 2008 Posted January 19, 2008 We have 20 iMacs in our music department and we used Directory services to set up AD authentication with our Windows 2003 server. Authentication works, but every couple of days it decides not to work and we need to go back in to Directory Services, unbin from the AD server and rebind and then it works fine for another few days. It is driving our head of music mad! Anyone else had this? Anyone know a solution? We will throw money at an Apple server if this is going to fix it but the when the authentication works it is fine and users log on correctly and everything is locked down just like it is on Windows clients. We use Ranger on our network - if that makles any difference. Thanks in advance for any help you guys can offer . . .
saundersmatt Posted January 19, 2008 Posted January 19, 2008 I haven't experienced that problem myself so i don't know what the solution is. Maybe you could post the system.log from an affected mac for us to look at. I can tell you that buying an OSX server won't hold the problem in any way as it is still the client machines that communicate with your AD servers. Matt
scgf Posted January 19, 2008 Author Posted January 19, 2008 Thanks, saundersmatt, I will grab the relevant part of the system log as soon as the problem next occurs.
Rozzer Posted January 20, 2008 Posted January 20, 2008 I would log in locally when you cannot log in and check that the time is correct. I have had problems before with the clock being 1 hour fast. By the way what version of OS 10 do you use? Ross
plock Posted January 20, 2008 Posted January 20, 2008 You're probably aware of this, but just making sure, with regards to authentication not taking place. Do ensure that the system time on the Mac's is exactly the same as the OS X Server and Windows Domain Controllers. Otherwise authentication fails; a security feature part of Mac OS X I believe. You'd be surprised how long it took me to work out why every now and then a Mac or two would stop authenticating! I posted this a while ago on another thread http://edugeek.net/forums/showthread.php?p=120952. You could possibly be having the same issue. Perhaps running your own NTP server might help?
scgf Posted January 20, 2008 Author Posted January 20, 2008 Thanks, guys, it could well be the time settings. I will check in the morning and if the time has drifted will set up time syncing with the server. Fingers crossed that you've hit the nail on the head! I will report back.
scgf Posted January 22, 2008 Author Posted January 22, 2008 Unfortunately it wasn't a clock issue. The time on the Macs and on the servers is in perfect synch I tried logging onto a Mac today, which wouldn't log me on. I logged on locally and tried accessing a logfile. Which logfile should I be looking at? System.log? There didn't appear to be anything in it of any relevance to AD authentication.
scgf Posted January 23, 2008 Author Posted January 23, 2008 I now have a system.log file which shows us trying to log in as an AD user. Some of the messages are a bit cryptic so if anyone can shed any light on the problem I'd be most grateful. The logfile is available by clicking here
Geoff Posted January 23, 2008 Posted January 23, 2008 Try putting DirectoryServices in debug mode with a "killall -USR1 DirectoryService", then tail the log with, "tail -f /Library/Logs/ DirectoryService/DirectoryService.debug.log | grep ADPlug" and watch it while you bind. Make sure you reboot or killall DirectoryService again so you don't grow a giant log file.
DMcCoy Posted January 23, 2008 Posted January 23, 2008 I've spent many hours sat in front of the AD debug logs, and its never been very helpful What sort of "unable to login" are you getting? The shaking screen or the AFP or SMB share is unavailable message? If it happens at boot then it can be because the DS plugin takes a while to start up.
scgf Posted January 23, 2008 Author Posted January 23, 2008 We get the shaking screen time after time. If we log in to the local machine and unbind, then rebind, we can subsequently log in successfully with an AD username/password. The first attempt after rebinding always results in an smb error - a message telling us that we are attempting to login to an smb volume. The second time always works fine. Things will remain fine for several days, then we are back to square one.
HodgeHi Posted January 24, 2008 Posted January 24, 2008 Can you log in locally and then log out and log back in as a network user straight after?
saundersmatt Posted January 26, 2008 Posted January 26, 2008 We get the shaking screen time after time. If we log in to the local machine and unbind, then rebind, we can subsequently log in successfully with an AD username/password. The first attempt after rebinding always results in an smb error - a message telling us that we are attempting to login to an smb volume. The second time always works fine. Things will remain fine for several days, then we are back to square one. To solve that: sudo nano /etc/hostconfig and change automount from -auto- to -no- (or equivalent, can't remember off hand if it's no or disabled)
saundersmatt Posted January 26, 2008 Posted January 26, 2008 Jan 23 10:51:05 MC-MU1-04 DirectoryService[44]: Active Directory: Could not determine closest Domain Controller from Site information in directory The above error from your log. When you bind to AD. Try defining the server. I know it's possible but once again can't remember off hand. If you're stuck give me a shout and i'll have a look on a mac on monday. Matt
Rozzer Posted January 28, 2008 Posted January 28, 2008 Jan 23 10:56:52 MC-MU1-04 /System/Library/CoreServices/mcxd.app/Contents/MacOS/mcxd: DSOpenNode(): dsOpenDirNode("/Active Directory/All Domains") == -14002 That looks to be your error. Just a few questions. Have you binded your mac server to Active directory? Did you add a kerberos realm as well if you added the mac server to AD? Also try the auto mount fix that fixed a lot of problems for me. You may also wanna try the easy fix is to rebind the workstation to AD. Ross
scgf Posted January 28, 2008 Author Posted January 28, 2008 (edited) Thanks for your help, guys. I am trying the /etc/hostconfig automount solution this morning. In reply to Ross, we don't have any sort of Mac server, we are authenticating directly against AD. I used Directory Services to set up AD authentication and binded it. Not sure what a kerberos realm is :-( Cheers. Edited January 28, 2008 by scgf
DMcCoy Posted January 28, 2008 Posted January 28, 2008 I've found an even worse bug in 10.5.1 that you can look forward to. Once I have logged in, no other users can login until the machine is rebooted due to some permissions issue on the mount.
DMcCoy Posted February 28, 2008 Posted February 28, 2008 Resurrecting an old topic, but I've just had two machines with broken AD. When I looked in the AD plugin the details for the AD domain were some random entries, not the correct domain. It's a bit odd that it has managed to change all by itself, but I don't think anyone else could have changed it as the binding was still active.
GrumbleDook Posted February 28, 2008 Posted February 28, 2008 We had a music technician with local admin access on the music macs and after there had been some building work in the lab the macs were all out of order. Rather than pick them up and move them he decided to rename them ... or rather he renamed the share name as he understood bugger all about how they were hooked up to the AD (not that we would have given him that access!). This did cause us problems of bizarre computer names that didn't match up to those in the AD and so binding was subsequently broken. The annoying thing was that this tool a few weeks to develop and it happened a bit at a time. It was only after we had to rename and fix 4 machines that I went round and check them all.
DMcCoy Posted February 28, 2008 Posted February 28, 2008 The biggest problem I find with os x is problem diagnosis. While there are extensive logs, they don't actually contain very much useful information. This leads to a great deal of shouting at various machines because the "shaking log on box" doesn't actually convey much as an error
swintle Posted February 29, 2008 Posted February 29, 2008 I've found an even worse bug in 10.5.1 that you can look forward to. Once I have logged in, no other users can login until the machine is rebooted due to some permissions issue on the mount. Hi, Did you ever resolve this problem, I am getting the same issue. I can login as one user on my imac (AD user). Try to login as a different user and no avail. Are there any fixes for this. Regards Steve
DMcCoy Posted February 29, 2008 Posted February 29, 2008 Hi, Did you ever resolve this problem, I am getting the same issue. I can login as one user on my imac (AD user). Try to login as a different user and no avail. Are there any fixes for this. Regards Steve I've not fixed it as so far it's only my machine running 10.5. I think it might be something to do with administrative privileges though and what happens to the auto mount folders. Try a non admin test user after a reboot and then see if another normal user can login afterwards.
Ravening_Wolf Posted February 29, 2008 Posted February 29, 2008 I have another one for the 10.5.1 buglist - it won't authenticate with our ISA 2006 firewall.
swintle Posted February 29, 2008 Posted February 29, 2008 Now the iMac seems to have a mind of its own, I can log off from an AD account and it refuses to logon to another. Ill try the first account and it refues, try another account and this time it will log me on. There doesn't seem to be any hard and fast rules. Has anybody out there had a similar issue. Regards Steve.
DMcCoy Posted April 15, 2008 Posted April 15, 2008 I have worked out what the problem with trying to relogin as another user is with 10.5. When the first user logs in, the sharepoint for their home folder is mounted, when they logout it is not unmounted and remains "busy" is you try to unmount it manually. If the next user to attempt login has a folder on the same sharepoint then they can login. If they do not, you get the error message appear when you try to login (not just the shake). I've been testing (a little - need more) with disabling automount for network drives, the user still gets their home folder mounted by the ad plugin, but it no longer remains mounted when they logout so another user will login sucessfully. I have no idea if there are any bad side effects yet, but I really don't want a single sharepoint for all user folders. I have commented out the the following in the /etc/auto_master config file as below #/Network/Servers -fstab
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now