10.6 Client and 10.7 Server Open Directory

I´ve got an Mac Mini running Lion Server. It´s configured as an Open Directory Server.
And I´ve got some 10.6 Clients running on the same local network.
All Clients have the Mini Server as DNS Server.
And now I want to use NetworkAccounts form the 10.7 Server on the 10.6 Clients.
I´ve connected the 10.6 Clients to the Server (without SSL) and all Clients say "Network Accounts available".
But if I try to log in on the Client it just shakes the login window. I´ve tried it on all my Clients with different Accounts but nothing worked.
It just won´t work! But why? Can you please help me?
What I´m doing wrong? Or is the combination of 10.6 Clients and 10.7 Server not Supported by OpenDirectory on 10.7 Server ?
Thank you !

Check your authentication against the server from one of the clients using the following command:
dscl /LDAPv3/<server name or IP> authonly <shortname of an account that cannot login>
     The server name should be the same name or IP you used when binding your 10.6 client to a 10.7 server.
If you get the response "Failed to authenticate user <shortname> (tDirStatus: -14103)" you are having the same issue I was having. I found an answer to this, but you are not going to like it.
Apparently Workgroup manager and Server.app deal with accounts differently. If you are using Workgroup Manager to import a long list of accounts, don't. Server.app needs to write an addition setting that is not part of Workgroup manager or in Passenger I doesn't work correctly with accounts that have home folders that are not local. Here are the steps I used to resolve the issue:
Export all your accounts and groups
Using Server Admin, demote your OD to a standalone directory
Once the demotion is complete, use Server.app to promote your server to an OD Master
Update: I've not found it to make a difference if you use server.app or Server Admin to configure your Open Directory Master.
Once the server is again an Open Directory Master, import the users that you exported using Server.app instead of Workgroup Manager.
If you are importing groups, set the Home Directory by editing the account in Server.app before importing groups to avoid overwriting your group settings. Thankfully, you can select multiple accounts at a time.
Import your groups using Server.app
Verify group membership and test the loginsIf you test the login using the dscl command from above, you should get no error after entering the password, but as long as you have a bound client, you should be able to login at this point.
Hope this reaches you in time to help.

Similar Messages

  • Unable to initialize the Microsoft Exchange Information Store service because the clocks on the client and on the server machine are skewed

    Each time I restart this exchange server, the Information Store and System Attendant don't start. If It try to manually start the services, I get the follow errors:
    Event ID 5003:
    Unable to initialize the Microsoft Exchange Information Store service because the clocks on the client and on the server machine are skewed. This may be caused by a time change either in the client or the server machine, and may require a reboot of that machine. Other than that, verify that your domain is properly configured and is currently online.
    Event ID 1005:
    Unexpected error The clocks on the client and server machines are skewed. ID no: 80090324 Microsoft Exchange System Attendant  occurred.
    The clocks on the domain controllers and the exchange server are set to the same time zones. As well, all three clocks are in sync down to the second. Any ideas on what's causing this and how to fix it?

    Run this Command from the Exchange Server
    Net time \\ADServerName /Set
    and confirm the action,
    and then you need to restart the service
    Microsoft Exchange Active Directory Topology Service
    and confirm you are not getting the Error 4001 in the event Viewer.
    Thank you, it resolved my issue after being sweating looking for solution.
    How can I prevent this from happening? I cannot restart services on each server reboot nor lose 5 years of my life!!!
    Sokratis Laskaridis MCP, MCTS, MCITP, Small Business Specialist Netapp ASAP, Symantec STS

  • SAPB1: 64 bits Client and 32 bit Server compatibility

    Dear all,
    SAP B1 2007 A
    is it possible to install SAP B1 client on a 64 bits Windows 7 workstation and connect it to a 32 bits server having SAP B1 2007 and SQL Server 2005 installed?
    64 bit client and 32 bit server can work together?
    Regards
        Emanuele

    Dear Emanuele,
    Yes if you are on SP01 PL07 or higher. You may check SAP Notes 1434624  and 1435183 for more info.
    Thanks,
    Gordon

  • Need help regarding Simple Data Client and Simple Data Server VIs

    Hi everyone.
    I have a simple objective. I just want to test the 2 example VIs, "Simple Data Client" and "Simple Data Server" between 2 computers. I just want to check whether is this working between the 2 computers.
    What I have done for now is that I changed the "address", from "localhost" in the "Simple Data Client.vi" to the IP address of the computer running the "Simple Data Server". I runned the "Simple Data Server" VI in one of the computers first followed by the "Simple Data Client" in the other computer. Nothing is received and the client just timed out.
    Can anyone please help me troubleshoot and tell me what are the possible problems for this? Are there any wires connections between 2 computers that I am missing or any other configurations I have to make before I can successfully do this?
    Thanks.
    Regards,
    Jonathan

    Hi Lee.P.
    I understand that. I was just feeling frustrated about the project not working. Sincere apologies from me.
    I was wrong about the error number. It is not Error 60. It is Error 59 - The network is down, unreachable, or has been reset.. Yes, I have tried changing the port numbers at the 2 computers when trying to send/receive.
    Could anything else be the problem?
    Regards,
    Jonathan  

  • One RMI client and mutliple RMI server implementation

    Hi,
    We are planning to implement a RMI. In the design approach we are planning to have 1 client and mutiple RMI server and each RMI server register to a system. All the RMI server will have the same functionality. The decision to call particualr RMI server is done at runtime based on some parameter. I am not clear on how to implement the same as I am new to RMI technology, so it would be great if you can suggest some good approach for doing the same.
    Thanks,
    Ramreddy

    greetings,
    your client and server are in the same class?
    i.e. server object (interface implementation instance)
    and lookup are within the same execution thread
    i believe this defeats the purpose of RMI
    the objective is to utilize object methods on different machines
    otherwise, you can just use a local method within your server/client mainline (of course, it ceases to become "remote" at that point)
    logistically, there is also the problem of the runtime not being able to resolve the skeleton/proxy components correctly (since it's probably searching for a client stub which doesn't exist...); maybe you could fake it out by compiling a phony client class - again, this won't provide any advantage but it might run
    perhaps if you shared your system/network setup and a bit more about your design objectives someone in this forum could provide some assistance
    good luck,
    D

  • 10.8 client  and 10.6 server email pop and imap problem

    Hi Guys ,
    My problem is 10.8 client and 10.6 server.
    10.6 server have email server running (pop and imap), when i configure same email account (pop) on 10.7 machine  and 10.8 machines , 10.7 machine works , but 10.8 pop does not working
    let me explaing further :
    when i use 10.8 mail application to  setup pop mail account it does not connecting . But  i used the same account to connect imap it connect on 10.8 machine.
    the same mail account connect to another 10.7 machine  with POP and IMAP for testing reason , it works with out any issues
    POP server is running and this email account's users profile enable POP and IMAP mail settings.
    thanks in advance.

    Try checking the Authentication Type for the POP account.  It is located in Mail > Preferences > Accounts > selected account > Advanced
    10.8 tends to use Apple Token.  I think you will need to use a type of MD5 Challenge-Response or Password.

  • Open Directory or LDAP Problem with 10.5 Client and 10.4 Server

    Yesterday, the client-server setup we've been using successfully FOR YEARS decided not to work on a v10.5.8 MacBook Pro client. Did not do anything to the v10.5 client recently (other than to boot it up). Not sure if any software was updated on the server recently (where do I check for this?). Curiously, a v10.4.11 client running on a Mac Pro (tower) continues to work fine/as though nothing's changed. It appears as though the only difference is v10.4 client (working) vs. v10.5 client (not working).
    Here is what IS working:
    1) Network Home Directories on dedicated drive partition of Mac running OS X Server v10.4.11. AFP, DNS, and Open Directory are all up and running (normally, I think) as shown in Server Admin application.
    2) Mac Pro (tower) client running v10.4.11 binds to and authenticates at v10.4.11 server. Any valid user can access their home directory on the server seamlessly when logging in at this v10.4.11 client Mac.
    3) That same v10.4.11 client Mac also contains a LOCAL admin user with its home directory on the local hard drive. That LOCAL admin account is used to update software on a per machine basis (and preclude users from adding unauthorized software, needing to use a specific machine, etc.).
    Here is what IS NOT working:
    4) On a MacBook Pro client running v10.5.8, the LOCAL admin account looses access to the partition containing its local home directory. The drive partition literally disappears. The only "solution" I've been able to find (and it's not truly a solution) is to turn off the Open Directory/LDAP binding (using the Directory Utility application). With binding turned off, the LOCAL admin user has no problem accessing their home directory on the local hard drive partition. Turn binding on again (using Directory Utility application), and the LOCAL admin user can no longer see its local home directory.
    Again, binding is necessary to allow regular users to use the v10.5 MacBook Pro with Network Home Directories (as in items 1-3 above). Binding should be turned on for this reason. However, with binding on, the LOCAL admin user cannot manage the computer because the local partition containing the admin home directory disappears/is inaccessible. Turn binding off, and the partition containing the admin home directory reappears.
    Perhaps there's something in the sever logs that will help. I don't really know how to read these, so if your help involves the logs, please refer to them explicitly (e.g., "in Server Admin, go to Open Directory->Logs->LDAP log" or similar).
    Any help greatly appreceated.

    Nope. Never used sso_util.
    I try to use Apple's GUI server management tools unless absolutely necessary/at the end of my rope (i.e., last step before re-install etc.). I figure there's just too many things going on under the hood: using the command line may fix one setting, but not re-configure the two or three others that Apple NEEDS in order to have the whole thing working in harmony. Unless you really know what's going on with all the configuration files, it's best to let the GUI manage the settings.
    In my particular circumstance, I've now got ALL Leopard clients, one Leopard v10.5 server, and one Tiger v10.4 server. Everything is working fine now, but it was not a simple matter getting the Tiger v10.4 server re-integrated into the otherwise ALL Leopard environment. OD/Kerberos is on the Leopard v10.5 server. Home directories are still on the Tiger v10.4 server.
    Two keys to getting THIS/MY set-up working:
    1) Tiger v10.4 server needs to have Open Directory set to "Connected to a Directory System" and has to be joined to the Kerberos realm that was set-up on the Leopard v10.5 server (use Server Admin to do all of this).
    2) Sharepoint on Tiger v10.4 server has to have SOME, but NOT ALL checkboxes for guest access enables/checked. See:
    http://discussions.apple.com/message.jspa?messageID=10903468#10903468
    Number 2 immediately above is contrary to what Apple manual for User Management reads, but this is what worked for me/my set up, after pulling my hair out following the manual's instructions to the letter and not getting the thing to work!

  • Error 61 when sending data from client and back from server.vi

    Trying to generate and send a data from client.vi and adding the numbers generated and sending it back to the client .In client the data is received only once and an error 61 occurs .How do I get rid of this error?I have attached the two files for reference
    Attachments:
    Sguruserver.vi ‏63 KB
    client1.vi ‏100 KB

    You can certainly use and application started by WebStart to send data to a server.
    However, the Sandbox restrictions allow you to contact the server the application was loaded from without asking for permission first (i.e. signing your application and requesting the proper permissions in your JNLP file).
    The JNLP BasicService can be used to retrieve the URL (and therefore the server) the application was loaded from.

  • IPhone SDK : Communication between iPhone client and a remote server

    Hi,
    This is w.r.t iPhone Cocoa Touch native application.
    i need to populate my application 's data from a remote application server ( which in turn connects to the database) . I require some tips in the communication between client sitting on the iPhone and the remote application server. I am planning to proceed in XML transaction way.
    I referred the SeismicXML sample application provided by Apple. In this sample,client reads the physically existing xml file from @"http://earthquake.usgs.gov/eqcenter/catalogs/eqs7day-M2.5.xml"; and the client parses the xml file and display the content on the table view.
    i have following 2 queries ,
    1. I do not want to read from a physically present file,i want the data to be transferred on the go.
    Means, request should be sent from the client to a application server and the server process returns the data in form of xml file ( but its not creating any physical xml file) .
    Basically i am looking for request - response concept.
    2. Can we call a java process(which returns xml data) running on a remote server from the cocoa touch client.? If not java process,what would be other best way...
    i am going through the Apple provided frameworks. Do any of the iPhone SDK frameworks support this request? If some one has any idea on the above mentioned queries, pls help me.
    any pointers will also be helpful.
    It might be too early to talk about these,but i have to take some business decision related on this.
    thanks in advance.

    You already know how to send a string via HTTP Post? And you know how to make XML into a string? Put the two together.

  • Informatica 9.5 client and 9.6 server

    Kids, the answer is extremely simple: Informatica does NOT support any combination of server X and clients Y. Both versions have to match exactly. Yes, there have been times when e.g. a 8.6.1 Hotfix 5 client could be used with a 8.6.1 Hotfix 9 server. But those times are gone.Nowadays Informatica requests that client and server versions have to match exactly, including hotfix version. You are not allowed to use e.g. a 9.6.1 HF1 client with a 9.6.1 HF2 server. Everything else is just a game of luck and may destroy your repositories. And it's not supported, so in case you're killing your repository this way you're on your own. And to make that clear: I don't give a damn about whether anyone tried it and didn't find any errors. It's not supported by Informatica, period. There's no use in discussing this any further. Regards,Nico

    If i have informatica server as 9.6 but my informatica client is still 9.5. will it still work.  I know infa 9.6 server and infa 9.1 have issues. We cannot access 9.6 with 9.1 client. is it the same with 9.6 server and 9.5 client??

  • OSX server open directory users and logic

    Hi guys,
    Can anyone shed light on this issue, I can't be the 1st person to encounter it. We have a lab with 10 emacs, plus a OSX Xserve, which is set up as a Open Directory Master, the students log in to the workstations through the xserve.
    When they try and run logic, we get a load of permission errors, I have tried changing the ownership and permissions to read write everyone, but it doesn't help, has anyone got a fix for this problem

    I am assuming you are not using network home directories here, purely using open directory for logging in right? Logic does not play well over a network, but using OSX server for managing users should NOT affect being able to run logic locally on a machine. If you are using network home directories for users then this WILL be a problem. For example, you will get permission errors when trying to record something.

  • SMB issue 10.4 client and 10.5 server solved?

    I searched for days to solve the problem to connect via SMB from a 10.4 client on shared files on 10.5 server. But I did not find any answer except unable guest access (what is no real solution).
    Why this error code -36 appears when trying to connect from the client (because encrypted password IS enabled)?
    Why SMB still works using 10.5 clients and Windows PC's?
    Why SMB works when guest access is unabled, but connected with defined accounts?
    Does anybody can answer this questions?
    Best regards,
    Tom
    Settings:
    10.5.3 Server version
    virtual LAN environment
    mixed network (Mac, Windows)

    I had a similar issue and I was able to make things a bit better by letting all users have access to SMB under the server access settings. You can still limit who has access to each individual share. I still have some other odd issues but I can at least connect.

  • Re: Informatica 9.5 client and 9.6 server

    Duly noted, thank you - and thank you for sharing the real-world experience. I will avoid server/client mis-matches at all costs.

    Nico -Addressing your customers as "Kids"? "Don't give a damn"? "no use in discussing this any further"? Really? That's rather harsh and unprofessional - especially coming from an employee of Informatica, don't you think?... Had you been drinking?  There's nothing wrong with asking the questions. Sure, I think it's pretty easy to assume Informatica wouldn't officially support such a mismatch, but you know what else Informatica doesn't "support"? running their products on overprovisioned virtual environments - which is ridiculous considering over-provisioning is the reason many companies go to virtualized hardware in the first place. So sometimes the official statement of support is nothing more than a technicality. Of course a customer should not expect the vendor to officially list support for myriad combinations of client/server versions, but that doesn't mean it can't work - you even state that in your reply regarding v8. And you know, in the real world outside of a lab environment, there are some very legitmate reasons why such a mis-match scenario might be the only option, at least for a short period of time. In my case it's because my company requires all workstation software to go through a lenghty certification process before it can be packaged for distribution, but I need to get my upgrade going on the server side asap. We've got the 960HF1 client already certified, and the 960HF2 client certification is underway, but I need to upgrade to 960HF2 server now. The reason I asked is to try to find out if anyone in the real world is doing this and if there are risks. I wasn't really interested in the "official" response considering that's what I get from Informatica Global Support after paying who knows how many hundreds of thousands of dollars in annual support fees. What about another hypothetical scenario: an installation with hundreds of users goes through an upgrade but not all those users get the client install completed immediately. A developer "really needs to get some work done now" and doesn't have time to perform the client install so they use the old client with the new server. I'm sure this happens multiple times per day, every day among Informatica customers in the real world so maybe Informatica should consider developing clients that can more easily tolerate a minor version or hotfix mis-match. Makes sense, doesn't it? Backwards compatibility is certainly not a new concept... I know our team in India routinely has major problems trying to get their clients updated in a timely fashion due to the fact that the client tools package is a whopping 2.8 GB - that can take hours to download in some places, assuming the transfer isn't interrupted... Maybe next time check your labcoat and attitude at the door before coming in, thanks.

  • OS X Server Open Directory Remote Login

    In short, I can't bind a remote machine to authenticate users at the remote location. I can get the machine to initially setup using RFC2307 search and mappings. Once I let that, "marinate" for a bit. I can then go in, change the mappings to Open Directory, and all will work. However, that doesn't persist across reboots. The only thing that will persist across reboots is RFC2307 search and mappings. But with only RFC2307, I don't get home directory access. In the above scenario, when I switch it to Open Directory, I can get home directory access. But, again, not feasible if doesn't persist across reboot.
    It works flawlessly in house / local LAN so far. Although this environment is being built from ground up as we speak. So much testing has yet to be done. This is just one big hurdle that came along.
    I sincerely appreciate any one's help or advice that could point me in the right direction to achieve this goal.
    I should note, I have check all DNS records, connectivity, but am willing to try anything again.
    Thanks in advance!!!

    Describe for me your network.  When you say remote location, do you mean two physical locations separated by distance that are connected via a VPN tunnel?  or do you mean that you punched some holes in a firewall to attempt to allow the clients to bind to the server?  I am hoping the first option.
    If you have a VPN tunnel between the two locations and DNS is available on both sides of the fence, you likely don't need to define the mappings.  I tend to leave the option set to "from server" and I've never run into any issues. 
    When you are binding, are you using the simple bind via System Preferences or are you using Directory Utility?  Are you performing authenticated binds or unauthenticated binds?
    If you have two locations, Main office 10.0.0.0/24 and Remote office 10.0.10.0/24.  Make sure that the Remote side is using DNS that resolve to devices in Main.  For example, if the server is at 10.0.0.10 and it is the DNS server, then the clients on the 10.0.10.0/24 network should be hitting 10.0.0.10 for name resolution (unless you have replicated DNS to the 10.0.10.0/24 network.
    Since you are building this from scratch, you might want to consider using two OD servers, Master and Replica, placing a replica in the remote office and then using OD Locales to better direct your clients.
    Reid
    Apple Consultants Network
    Apple Professional Services
    Author "Mavericks Server – Foundation Services" :: Exclusively available in Apple's iBooks Store

  • IChat Server - Open Directory trouble

    Hello All!
    I have exactly the same problem as stated in this thread: http://discussions.apple.com/thread.jspa?threadID=1373399&tstart=-1 -- I see that there is indeed a problem between OD and the jabber server running (check the source code, it's on Apple's OpenSource page: http://www.opensource.apple.com/darwinsource/Current/ChatServer-263.1/jabberod_auth/appleauthenticate.c)
    The function in question is:
    int odauth_check_servicemembership(const char* userName, const char* service)
    which shouldn't return "No such file or directory".
    regards,
    P

    The only way i got it working is :
    • using a second shortname (first is not accapted in my case it containd uppercase and login is done lowercase
    • not using kerberos
    • manueel adding all collega clients .. :S
    I did a advanced install.
    Message was edited by: Patrick Savelberg (Private)

Maybe you are looking for

  • Schd. for delivery quantity in MMBE - Vl09

    Dear We had one sales order which was having 375 quantity to be delivered. Also the same stock was available in the plant, storage location and batch. So we created delivery order through vl01n. Then for some reason we need reversed that delivery ord

  • Can't buy Final Cut Pro X Error 100

    Tried restarting and logging out but the Mac App store gives me an error 100 when I try to purchase Final Cut Pro X.

  • ABAP : Running total in alvgrid

    Dear ABAP Experts, How can I add running sum in alvgrid.? I have developed a code but when user sorts on anycolumn then the total becomes wrong because it has been calculated in the code. Is there any auto feature in alvgrid.? Regards Aneel

  • HT4236 HOW CAN YOU VIEW PHOTOS ON IPHONE IN CHRONOLOGICAL ORDER AS THEY APPEAR IN THE DESKTOP?

    When photos are sync'd on my iphone, they appear in random order.  But on my computer desktop, they are identified in chronological (dated) order.  How can i get the photos to follow the same chornological order on the phone and ipad?

  • Erratic quality in a single track?

    I am experiencing a rather strange problem with burned CDs - the sound quality varies widely within a single track. It goes from loud to soft, then loud again. With the current CD I'm trying to burn, I notice that the solo vocals are very soft, and t