Jump to content

Problems with macs login to an AD server


Recommended Posts

Posted

I have two mac labs (24 macs each). The way the users access them is with their AD credentials. It normally works fine but from time to time, the students can't access their accounts from the macs, I realised that there was a problem of sync between the mac and the server so I setup the macs to use the AD server as the Time server; but from time to time they loose sync and I have to login in the mac as an admin re-sync the time "manually" and then users are able to log in...

 

Have any of you ever had a problem like this???

 

 

Thanks in advance.

Posted (edited)

I had. It is due to the way OS X calculates the setting of ntp.drift. I never actually tried this because it happens rarely to me so experiment and see what happens.

 

Here's more stuff pertaining to this problem ( for what its worth ).

 

Enjoy

 

PS I believe problem will also go away if the Macs are powered off each night as ntp.drift is recalculated on start up.

Edited by nonmonotonic
  • Thanks 1
Posted

Also, isn't there a way to make the win server or the macs clients less demanding in terms of having the same time to be able to log in????

 

Thanks in advance.

Posted
Also, isn't there a way to make the win server or the macs clients less demanding in terms of having the same time to be able to log in????

 

Thanks in advance.

 

No because the time is a critical component of Kerberos authentication.

 

Kerberos has strict time requirements, which means the clocks of the involved hosts must be synchronized within configured limits. The tickets have a time availability period and if the host clock is not synchronized with the Kerberos server clock, the authentication will fail.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...