gaz350 Posted March 17, 2008 Posted March 17, 2008 we have multiple DC's works fine. Only thing i can think of is something in your domain is setup in a non-standard way.
ahunter Posted March 17, 2008 Author Posted March 17, 2008 Hmm, could be, the only confusing part is our tiger clients will bind/unbind to their hearts content. I would just put tiger on this iMac but 10.4 doesn't have the right drivers for the new iMacs:rolleyes:
kingswood Posted March 18, 2008 Posted March 18, 2008 Hmm, could be, the only confusing part is our tiger clients will bind/unbind to their hearts content. I would just put tiger on this iMac but 10.4 doesn't have the right drivers for the new iMacs:rolleyes: Really sorry you are having problems with this. Have you got the constitution to try one more thing? If you have, try this: 1. Reinstall one of your iMacs and DON'T install the 10.5.2 update. Only update to 10.5.1 if you can. 2. Add the computer name you will be using for the iMac into ADUC on your Windows Server before binding. 3. In Directory Utility you get the option of "Prefer this Domain Controller"- use that option and put your Windows Server IP address in there. Don't let Leopard decide which DC to choose (this will help if you have a multiple DC site). 4. Uncheck "Allow Authentication for any Domain Controller" 5. In the "Directory Servers" screen add your domain controllers 6. Bind and test Do a "dsconfigad -show" if it doesn't work and post the results back here if you have the time. Remember- don't update to the 10.5.2 release yet. If it binds you might want to check that after the update it still works. I really think that this has something to do with particular domain setups, but haven't seen much of a pattern yet because most people haven't the time or inclination to actually post chunk loads of configuration settings etc. Another thing to check is that if you enter an A and PTR record for your Mac before binding whether it then works. This would indicate something DNS related on your domain that Tiger ignored but that Leopard is more fussy about. Also remember that with Leopard Open Directory is now integrated into the client as well as server product- NETINFO has been deprecated. They worked differently at local level and when binding to AD! Hope that helps, Paul
ahunter Posted April 21, 2008 Author Posted April 21, 2008 Hi, Still no joy I'm afraid. When I try to add the directory servers I can add our apple server but it will not let me add anything related to our domain controllers or 03 domain. It just says eDSCannotAccessSession, I cannot seem to find anything on the net which resembles the problems we are having. Starting to get a bit desperate now.
ahunter Posted April 21, 2008 Author Posted April 21, 2008 Really sorry you are having problems with this. Have you got the constitution to try one more thing? If you have, try this: 1. Reinstall one of your iMacs and DON'T install the 10.5.2 update. Only update to 10.5.1 if you can. 2. Add the computer name you will be using for the iMac into ADUC on your Windows Server before binding. 3. In Directory Utility you get the option of "Prefer this Domain Controller"- use that option and put your Windows Server IP address in there. Don't let Leopard decide which DC to choose (this will help if you have a multiple DC site). 4. Uncheck "Allow Authentication for any Domain Controller" 5. In the "Directory Servers" screen add your domain controllers 6. Bind and test Do a "dsconfigad -show" if it doesn't work and post the results back here if you have the time. Remember- don't update to the 10.5.2 release yet. If it binds you might want to check that after the update it still works. I really think that this has something to do with particular domain setups, but haven't seen much of a pattern yet because most people haven't the time or inclination to actually post chunk loads of configuration settings etc. Another thing to check is that if you enter an A and PTR record for your Mac before binding whether it then works. This would indicate something DNS related on your domain that Tiger ignored but that Leopard is more fussy about. Also remember that with Leopard Open Directory is now integrated into the client as well as server product- NETINFO has been deprecated. They worked differently at local level and when binding to AD! Hope that helps, Paul As requested here are the dsconfigad results: Last login: Mon Apr 21 10:05:45 on console rm-918a33376752:~ localadmin$ dsconfigad -show You are not bound to Active Directory: Advanced Options - User Experience Create mobile account at login = Disabled Require confirmation = Enabled Force home to startup disk = Enabled Use Windows UNC path for home = Enabled Network protocol to be used = smb: Default user Shell = /bin/bash Advanced Options - Mappings Mapping UID to attribute = not set Mapping user GID to attribute = not set Mapping group GID to attribute = not set Advanced Options - Administrative Preferred Domain controller = not set Allowed admin groups = not set Authentication from any domain = Enabled Packet signing = allow Packet encryption = allow Advanced Options - Static maps None rm-918a33376752:~ localadmin$
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now