Jump to content

Recommended Posts

Posted (edited)

Hi there

 

I work for a library that is shared with 3 universities. we have our own AD network which our PC's are joined to. All of our networks are linked, so students can come in and log in with their own university UNIVERSITY\USER

 

I have joined a mac to our AD domain and have tried logging in with my accounts for the other uni's but can't. Is there a way to do UNIVERSITY\USER like we can on the pc? Can it be done without joining to other domains?

 

Thanks

Edited by cshephard
Posted

Thinking about this it should be possible provided whatever the mac is using for DNS can fully resolve all the domains involved? Ideally you should not be using .local on any of the domains. By default any mac bound to Active Directory will allow authentication from any domain in a forest. The domains themselves should already have a trust relationship established and simply binding to one domain should allow users on all domains to login on that mac.

 

This Microsoft TechNet article might help?

 

https://technet.microsoft.com/en-us/library/cc773178(v=ws.10).aspx

 

You could try entering UNVERSITY/USER (note the forward slash) at the login window and this may be enough for the authenticating server for the forest to allow a successful login? What does the system.log say when you compare a successful login on one domain with failed logins on the other two?

 

Unlike PCs you can bind a Mac to multiple domains. Identification, authentication and authorisation is usually handled by the authenticating server in topmost domain listed in Directory Utility's search order. If you bind the Mac to Domain A followed by Domain B and Domain C these should then be listed second and third. When a user presents their credentials at the login window, the authenticating server for Domain A will search their database and if that user does not exist, Domain B's authenticating server should then search their database etc and so-on. When the user is found and provided the three authenticating servers trust each other a successful login should then happen. That's the theory and how and if it works will depend greatly on how well it's been configured (sounds like it has been otherwise your PCs would be behaving the same way?). As ever your mileage may vary. Hopefully their may be others who have a similar situation who might help further?

 

Antonio Rocco (ACSA)

Posted

You can do this.

If the university networks are all in the same forest and traffic is allowed to pass between domains you should only need to bind to one domain.

If the university networks are in separate forests then this is where the fun beings, i think you need to bind to at least one domain and then add someway of looking up information in the other domains.

 

Sorry i can't be more help, its been 10 years since i had this setup.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...