How do I create Local Network Home Folders for Users from an Active Directory binding?

My situation is this... I run an iMac lab at my school.  I have a server set up to manage the network user accounts in the lab.  Currently, I can sucessfully create Local Network Users and log in to them from any of the iMacs.  My school has an Active Directory set up for all the students on campus.  What I'd like to be able to do is configure the server to allow the students to use their user names and passwords from their school accounts to log in to the iMacs and have it automatically build a network user folder on the server for them to use during the lab. 
So far, I have been able to configure access for the Active Directory accounts to use the services on the server, mainly File Sharing, but I cannot figure out how to allow them to log into a user account on the client's machines using their same Active Directory credentials.  I have even attempted to allow the user accounts to create mobile accounts, but that's not working out either.  Entering indivual network user accounts into the server for every student every semester will be a nightmare.  I'm sure there's a way to do it automatically using the exisitng Active Directory structure.
The live server is running 10.8.5 Server still, but I've also got a clone running OS X Server in case it matters.  Please help!

ok reinstalled everything dns seems to be working have done sudo changeip -checkhostname and it says that both names match but then i started open directory and can't seem to get Kerberos started, i've tried changing it to stand alone then back again but it does nothing. I'm wondering why this would happen? i've tried adding a kerberos record but it doesn't do it just does nothing so i don't know what i'm doing wrong. I wondered if it might be a problem with the two network cards and dns as on ethernet one it is getting the dns name xserve.xxxx.ac.uk (which matches what the college server wants to call us) but on ethernet 2 gets xserve-2.local because it tells me that it already exists on ethernet one and renames it to this. I need to set up NAT so have ethernet coming in on port one and out again on port two. I wonder if my dns is backwards as its got the 192. address the NAT uses but its linked to the ethernet port one dns maybe this is the problem. would this cause open directory not to start kerberos?

Similar Messages

  • Networked Home Folders for Linux users

    Is this possible in OS X server? I can't find any mention of it anywhere.
    We recently acquired a group of animators who work in linux and would like their home folders remoted. i would also like to get them sucked into the same OD user structure to avoid multiple logins and such.
    Is this possible and does anyone know of any resources to help?

    All is possible with openLDAP (i.e. OD)!
    So you want linux people to authenticate against OD, and have their home folders hosted by a Mac (or a linux box?)
    I can tell you how I set up my Fedora 8 machine to authenticate against OD:
    1. run authconfig utility as root and select LDAP as a source of authentication info. Since OD uses Kerberos you also want to select the Kerberos option.
    2. enter all your OD info (ip, base to search, TLS or not etc).
    authconfig should update /etc/nsswitch.conf to look to ldap for name services and it should give you a working /etc/ldap.conf and /etc/openldap/ldap.conf. You may need to make some changes by hand.
    restart xserver (logout or reboot) and it should just work.
    If your home folders are on the linux box you will need to set an NFS option so that OS X will properly mount your NFS export.
    1. make sure linux machine has "insecure" option in its /etc/exports file and is exporting to samesubnet as your Macs.
    2.
    .... actually just follow these direction:
    http://www.oreilly.com/pub/a/mac/2007/06/27/discover-the-power-of-open-directory -part-2.html

  • How do i create a drop down menu for selecting from the drop down arrow

    how can i create a drop down menu so that when i click on the arrow in the cell i can select from the menu that appears

    katiesandell wrote:
    how can i create a drop down menu so that when i click on the arrow in the cell i can select from the menu that appears
    Hi Katie,
    Welcome to Apple Discussions and the Numbers '09 forum.
    Numbers vocabulary for this feature is a "Pop-up Menu". It's available as a Cell Format, and is set and edited in the Cell Format Inspector.
    See "Using a Checkbox, Slider, Stepper, or Pop-Up Menu in Table Cells" starting on page 96 of the Numbers '09 User Guide.
    This guide, and the equally useful iWork Formulas and Functions User Guide are available for download through the Help menu in Numbers.
    Regards,
    Barry

  • Network home folders

    Hello All,
    I need help setting up our new school, I am new to Mac, and it's quite some fun to work with. I want to create a network home folder for the students so, they can work from any of the lab computers. My fear is what happen when 50 student logon to there home directory at the same time, working on a video project, this will certainly slow down the server. My questions:
    1) will Portable home directories solve my anticipated problem, if yes how do i se it up?
    2) Can any one give me the best practice in setting up Mac Network for a high school?
    Thanks for you help.

    Portable home directories would work just fine, however each time the client syncs (usually at logon) it will take extra time to actually complete the logon.  My experience is that students are VERY impatient.  From time to time, you get sync conflicts as well.  Students, and teachers for that matter, will get hung up on the simplest of dialogue boxes.
    I suggest that you use non-portable (regular) home directories and educate the students on saving their projects to the shared folder on the local hard drive.  /Users/Shared   The down side to that is that the students will have to use the same computer each time they want to work with their documents.
    If you're using Final Cut Express/Pro, then you can just tell the program to switch scratch disks.
    If you're using iMovie, then you have to create a folder on the root level of the hard drive and allow all users read and write permission.  I forget what you have to name said folder but....
    Just google "iMovie 09 Network User Accounts" and you should see the problems that people are having.
    I really suggest keeping the video files off of the server just for the simple fact that video takes up a BOAT LOAD of bandwidth.  My guess is that the bottle neck won't actually be the server, but it'll be the switches in between if you have a bunch of people editing video simultaneously.
    HTH
    -Graham

  • Network Home Folders - Sometimes

    Is there a way to have network home folders sometimes?
    Here is the situation. (all servers and clients are at 10.3.9, but could be upgraded to 10.4.x)
    In a school there is a 29 unit eMac lab and an iBook cart. The students each have a home folder on the server. When they log in to an eMac they use their OD/LDAP username and password. The OSX server authenticates them and then they use their network home folder. This works just fine.
    But when they use the iBooks, they are using Airport to connect to the network. Network home folders are too slow to work over a wireless network, so they have to log in using a local account and then mount their network home folder to save files.
    What I would like to do is have them login to the iBooks with their OD/LDAP information so that they can be authenticated using OD/LDAP but not use home folders when using the iBooks. (I could then put their home folders in the dock)
    Is this possible?
    Thanks
    too many to list   Mac OS X (10.3.9)  

    Considered, but won't work for this application.
    The students use different computers at different
    times. For instance the question is about users on
    eMacs some of the time and iBooks some of the time.
    So they would have at least 2 different computers and
    many people might use either of them at a different
    time. So a single computer could have many, many home
    folders.
    Just to press the issue: is there a reason this is a problem (disk space, for example, or security)? Because the whole point of PHDs is that you'll be getting synchronization even when multiple machines are involved. If you're worried about home directories piling up, you could implement a cron job to clean them. I'm not trying to suggest that PHDs really will work in your instance--just trying to suggest possibilities.
    In any event, it IS possible to modify your users' home directory settings on a client-by-client basis. You could, for example, have your users' accounts set to use network home folders for your wired machines, but override that setting on your iBooks to point to homes on the client. To do that:
    1. Open Directory Access on your iBook, select your LDAPv3 configuration, and edit it (Services pane > LDAPv3 > Configure, select it in the next window and click Edit. If you've checked "Use DHCP-supplied LDAP Server" you'll need to uncheck that and create a configuration for your server; consult the server documentation for more information.
    2. When you click the Edit button, you'll get a window for the selected configuration, with tabs for "Connection" and "Search & Mappings." Click the Search & Mappings tab.
    3. In the Record Types and Attributes pane on the left, click the disclosure triangle next to Users, and do two things:
    - Select "HomeDirectory" and delete it.
    - Select "NFSHomeDirectory" in the left pane, and replace the corresponding "homeDirectory" entry in the right pane with the following: #/Users/$uid$. Then, click OK to save your changes.
    4. Reboot the client, and log in as one of your network users. Here's what should happen: on this particular client, Directory Access will still log your users in with the account settings on the server, except the HomeDirectory attribute will be reset with the value /Users/<short user name>. That's what the NFSHomeDirectory line does: the sharp sign tells Directory Access to ignore the attribute in the user's server account, and overwrite it with the string that follows. The $uid$ tells Directory Access to substitute the field with that value (the LDAP uid field). So, for user John Smith, whose short name is smithj, the client will create a folder called smithj in the folder /Users, which is on the local client.
    You could in theory use this technique to place the home folders anywhere on your client (like in /tmp), but it's best to use the default /Users folder unless you have strong reasons not to.
    The advantage of this scheme is that you only set up the Directory Access preferences this way on the clients where you want to have local homes--e.g., your iBooks. Once you've correctly configured the Directory Access preferences and have verified that everything works, you can copy the folder /Library/Preferences/DirectoryService to your other iBook clients, so you don't have to go through this process on every machine.
    There is one caveat, however. Configuring Directory Access this way will effect ANY user who logs in to your iBook--that is, any network user on your server. You can't set this up differently for different sets of users on your server--for any client workstation, all users on the server get treated the same. This is presumably what you want, given that you don't want to server network homes over wireless, but it's important to understand the implications of what you're doing.
    The instructions above assume that you're familiar with setting up configurations in Directory Access. If not, you might want to read up on it.
    Power Macintosh G5 1.8/PowerBook G4 15 1.42   Mac OS X (10.3.9)  

  • Network home folders: iCloud password question re-appears at every logon

    Hello,
    Is there any way to enable iMessage and Facetime together with Network home folders. Im using Mavericks server (Directory services enabled) and two Mavericks clients. Every time a user that was using machine A logs on to machine B the iClouds password prompt re-appears and subsequently security questions are sent to iOS devices that a new device was added.
    Is there a way to circumvent this? I think I tried once in combination with mobile home folders. However, even if I excluded iMessage/Facetime system files from syncing, questions still re-appeared.
    The more iCloud services are tied into the system, the more you would like to use them; even if you are using network home folders.
    Regards,
    Thomas

    I also have this question.

  • InDesign CS1 Unexpectedly quitting with Network Home Folders

    Hi
    We have a Mac OSX 10.4 Server installation running on a G5 XServe with 5 Mac Users running Network Home Folders as well as other services. When the Mac users are working off the server with their files, InDesign unexpextedly quits or when they try to save their work back to the server it reports that they don't have access gto the sharepoint to save their files.
    Any ideas?
    Paul

    Paul,
    We have had similar problems with CS1 and CS2, the only fix i have found is when the user cannot save, is to use the connect to server dialogue and to reconnect to the share point that way, in most cases the user can save after doing this. I have also seen this when the user is close to their disk quotas limit (some adobe programs need something like 2/12 times the file size to be able to save properly). For some reason it seems that CS will regularly lose its connection to the server, and i checked the Adobe site once and i am sure it said it was not supported in a network environment. It is certainly the worst program we have for problems since i have set up network home folders for students, second is Microsoft Orifice which also does the same thing.
    Hope this is some help, its been driving me and the students mad for the last year.
    Good luck,
    Kevin.

  • Network Home Folders on NAS

    hello all-
    i have recently purchased a QNAP TS809U-RP. i want to move all my network home folders to it. here are the steps i have taken thus far:
    1) created a new share on the QNAP via the QNAP web utility. the share is xServeData
    2) created a folder called "Home" in the xServeData - this is where i want all the home folders to reside
    3) went to Server Admin and created a new share for the "xServeData" share i created in the QNAP web utility
    4) went to Workgroup Manager and created a test user called, oddly enough, "Test"
    5) clicked the "Create Home Folder" for that user
    when i look on the QNAP a Home folder is created called "Test" but with only 2 folders inside of it:
    Library
    Sites
    when i go to one of the iMacs on the network i type the username and p/w for the user "Test" and the login starts but i get the error:
    "You are unable to log in to the user account "Test" at this time
    Logging in to the account failed because an error occurred."
    when i go back and check the new "xServeData" share's permissions versus the permissions where the home folders currently reside (on Drive 2 in Bay 2 on the xServe) i see that the permissions are:
    serveradmin, Allow, Read & Write, This folder
    staff, Allow, Read & Write, This folder
    others, Allow, Read Only, This Folder
    on the new "xServeData" share these permissions are:
    serveradmin, Allow, Read & Write, This folder
    staff, Allow, NO ACCESS, This folder
    others, Allow, NO ACCESS, This Folder
    when i try and change the new share to match the old share and save it just reverts back to the "NO ACCESS" for staff and others. i am sure this is probably what is causing the user "Test" from logging in but i don't know how to solve the issue. i am new to NAS's and am certainly not the most advanced OS X Server user. i have this in my home and my users are my family. this is really more of a hobby but i love to learn and play with this stuff.
    if someone has any experience setting up Network Home Folders on a NAS and hopefully on a QNAP NAS i would sure appreciate your help and knowledge to resolve this. it seems that i am very close but that i am just overlooking one or two issues......

    I am in the same boat. I would like to create mobile accounts but never sync. This is like having a local account but this way the password is in sycn with OD.  Then the Time Machine can do the backups to the home folder on the NAS instead of using home synching.
    How do we get the NAS box folders available to WGM? I need to know what to enter in the home folder section and be able to hit create home now and save.
    This will be using Snow Leopard 10.6 od master.
    Lannie

  • Network home folders, collaboration sharepoint and Microsoft Word 2008

    I'm hoping someone who knows how Microsoft Word 2008 works on network volumes can shed some light on our situation.
    We run a small managed network with about 15 leopard clients and a leopard server. We've got two sharepoints, a "homes" share for network home folders, and an "Office" share with our shared office document folders.
    Several times a week, users will encounter a situation where Microsoft Word 2008 will claim that a file is open by another user, or that the file can be opened in "read only" mode, even though the file is not in use. Naturally, the problem cannot be replicated when I am present.
    ### My Hypothesis ###
    My users are in the habit of quickly borrowing machines from other users to pull up documents in the "office" share by using the "connect as" button. So, for example, userA is logged in to her machine (and is thus connected to the network home folder on the server). userB comes along and borrows her machine -- without logging out, will connect to the shared office folder, pull up and edit/print a document, etc. We're not currently auto mounting the office share.
    I know that Microsoft Word creates lock folders located in the .TemporaryItems folder at the root level of the "office" share. The folders are named "folder.xxxx", where xxxx is the userid of the account that created the lock folder. Everyone uses a network account, so everyone has a unique userID. If I list the .TemporaryItems folder using the CLI, i can see lock folders that are several days or a week old. So Word doesn't seem to be cleaning up after itself immediately, at least not always.
    So my question: when userB connects to the office share on a borrowed machine (logged in to the client machine using the network home folder of userA), is it possible that word will now create lock folders for userB, and will be unable to clean up lock folders created by userA?
    Anyone have other ideas for investigating the "file in use" problem?

    Switched user back to the network home folder and adjusted the MS Word preferences so that the autorecovery files would be stored on the local client machine. There doesn't seem to be a comparable setting in the Excel preferences.
    My initial testing suggests that this has reduced how often this problem occurs, but has not eliminated it. I tested by repeatedly opening and closing a couple of different word files in rapid succession -- i was able to replicate the "file opens as read only" problem occasionally.
    I've talked to Apple server support about this issue. While they were helpful, they didn't have an explanation or solution for this problem. There are a number of postings in the microsoft mactopia discussion boards site where people report similar problems.

  • Newbee question on network home folders

    I have 3 or 4 networked Macs in my home and I want everyone to have access to their own home folder from any Mac. Therefore the necessity for networked home folders. But I know nothing about how to set them up or even if it is possible in this situation. I have a copy of Mac OS X 10.5 server but have not set it up yet. Some Macs are a mix of 10.4 and 10.5.
    How do I go about learning how to set this up? What are PHD (portable home directories)? How does mail work in a network home directory environment? All family members are on .mac mail.
    Thank you for your help in getting this set up in my home.

    A Network Home folder is simply where your Home Directory is stored on the Server rather than locally on you Mac.
    The experience of using the Mac does not change so Mail and all other applications behave as they do with a normal local home. As you say this allows you to log in from any Mac. but before you set this up it is advisable to make all of your Macs identical, e.g make sure they all have the same Application, fonts, plugins etc because it is only the files that are normally in HD > Users > yourhomefolder
    that are stored on the server, everything else stays local.
    As for setting it up http://www.afp548.com/ has some good guides for Tiger server that can be adapted for Leopard
    Portable home directories are similar in that the Home Directory is stored on the server, but a PHD syncs the directory to your local mac as well, so in theory this is the best of both worlds in that you work on a local home folder and everytime you log in and out your changes are sync'd back to the server.
    This still allows you to log in from another Mac, and also means you can work on a laptop away from your network.
    But like I said "in Theory" this is best of both worlds, and for the majority of the time it works well, but you can run into complications, such as errors syncing and the potential to loose work if you log into the account on two macs at the same time.

  • Locking Applications Folder-Network Home Folders

    I am managing about 225 macbooks out on campus over OD/Network Home Folders. All is working great. One issue I've run into for the last three years is that kids can drag an application out of the Apps folder and drag it to their network home desktop. They then try to run it from there and all sorts of mayhem ensues.
    Any ideas on how to stop that from happening? I've read some about using sticky bits. I am using WGM to lock down pretty much everything else but kids can still drag apps to their desktops.
    Thanks for any info in advance.

    As long as they have permissions to read the folder, (usually by membership of a group) the home directories are created when they log in. You can create them manually using the button in the Home tab of Workgroup manager.
    If they are not automatically created, then there is a fault.

  • Slow Firefox Start up when using network home folders on OS X server, Would like to speed it up

    So firefox crawls when starting up using network home folders. I'm wondering if there is a way to keep the caches local and only save personal settings to the home folder located on the server.

    upgrade your browser to Firefox 8 and try
    * getfirefox.com

  • Changing location of Network Home Folders

    Hi
    We're about to add two 500GB mirrored drives to our Xserve in place of the two 250GB drives we have already. This means re-locating user's network home folders to a new sharepoint.
    Is this simply a case of setting up the new home sharepoints, moving the homes to the shares and allocating the appropriate new home share path in the user's home folder setting? I tried a test user and the only thing that didn't work was the shortcuts in the sidebar, which can be replaced.
    Any pointers welcome, thanks

    I've never tried this, but you may be able to use Carbon Copy Cloner (http://www.bombich.com/software/ccc.html) and backup everything to a USB/Firewire drive. Then put in your 500GB drives and restore the backup to the new drives. You then wouldn't have to create new sharepoints, everything would still be the same, just with more storage. Someone correct me if I'm wrong on this though....

  • Syncing problem with network home folders

    Deaar Community,
    I recently obtained a Mac Mini Server. I had a problem syncing my iPhone after moving all my data to network home folders.
    Everytime I got the following message:
    "Syncing cannot be enabled on this computer"
    "Multiple computers are logged in to this same network home folder."
    "Please turn off syncing on all other computers..."
    There were no other computers syncing into the same directory.
    This turned out to be a wrong error message.
    I solved the problem by turing off the firewall on the server.
    That was strange. Although the firewall rules were set to allow all traffic within the local zone iTunes had a problem with its presence.

    Please be also sure that the permissions for the files are set correctly. In my case it turned out that the permissions for the iTunes Library were set in a way that the directories were owned by the server administrator's account. I had to reset the owner.
    I also feel that there is a bug in the permissions administration in snow leopard server. I ended up with files that had a lot of permissions entries which were completely identical.
    i. e.
    Angela read only
    Steve read+write
    Steve read+write
    Steve read+write
    everyone none
    Stll, a different error occurs randomly, but I finally managed to completely sync the iPhone. The error message now says that the iPhone could not be synced because the sync server could not sync the iphone. (?! This is somewhat redundant.)

  • Moving Network Home Folders

    I would like to consolidate our network home folders onto one drive, into one volume. Is there a "best practice" limitation on how many home folders you should have per volume, disk, etc?
    /Volumes/Disk1/users move these (aprox 50) to:
    /Volumes/Disk2/users currently contains 350 HF
    What is the best procedure and tool to use to move the home folders?
    Thx in advance for any advice!
    G5 Dual 1.8   Mac OS X (10.4.8)  

    we did this in our district over the summer....went from 9 drives on 5 servers down to 2 drives on 2 servers
    insofar as copying is concerned, we found the quicked(and least user-intesive) was to just mount the "old" drive to the new one and use the ditto command via terminal
    it was most useful because we could set it and then go do other things

Maybe you are looking for

  • Cannot insert data from local database into remote database using subquery

    I have two oracle databases on different host. One is version 8i in Host A and the other is 9i in Host B. First, I try to create a dblink in 8i to 9i, but it fail. Then, I create a dblink in 9i to 8i, it success. I have already tried some select stat

  • Adobe Acrobat Pro extended batch watermarks trouble on 3d PDFS

    Hello there we are very interested in buying a license of your software but we have a few reservations I cannot get the batch watermark facility to work on a batch of 3d PDF encoded from pro engineer wildfire 2. When i apply the watermark the waterma

  • Does Migration Assistant move Mailbox (mail.app) IMAP data?

    Recently I used migration assistant to move a user from a Lion machine to a Mavericks machine. I couldn't get it to work via direct ethernet (famous "1 minute remaining" bug) [1] so I migrated from a Time Capsule backup. After migration the User's ma

  • Unable to create AAM,or Recurring Document/Sample document

    Hi, I am not able to create AAM,or Recurring Document/Sample document, it comes up with a ABAP runtime error, dont know what to do, Can some one Advise? Regards, Raj

  • I'm having trouble using the Ipod Updater

    Itunes is not recognizing my ipod. I was told by the apple support to download the Ipod Updater and restore my factory settings. I downloaded the Ipod Updater as instructed, but when I go to open the program is keeps saying "Error reading setup initi