Authentication - same account name on 2 LDAP servers

We have our mac clients set up to authenticate against 2 LDAP servers, one Open Directory, one eDirectory - to keep things easy for our users I want to use the same login username for both OD and eDirecotry users - we basically have users logging into both Windows and Macs, I want a specific set of users to have home directories on our Mac server (only when logging into the the Macs), and to pick up their Windows home directories when logging onto Windows machines. I have the Mac server set above the eDirectory server in the Directory Utility search policy (client machines), but when I log in with a network account I am prompted to choose which account to use (eDir or OD similar screen to having managed users in different groups where you are prompted to choose your profile at login). I thought that by specifying the order in the search policy the client machine would authenticate the first account found rather than prompting for which account to use. Any one know of a way to make this happen - ie set up identical accounts on both LDAP servers and have the macs authenticate the first account found on the server specified in the Directory search policy instead of offering a choice? I hope this makes sense. I know it would be easier to mount a network share on the mac server for certain users and have all the accounts authenticate via eDirectory, but I have to do it this way. Anyone have any advice??

I am having exactly the same problem, also with an iMac and a MBP. My iMac is about 6 weeks old, and I migrated via Time Machine. I can read the files from the connected machine, but cannot write, regardless of which is the host. Permissions are all fine.
I did notice one thing: the UUID number for the accounts is the same (accounts have same name as with darrylh). You can find this under System Preferenes>Accounts and right click or control-click on the account name after unlocking it. I am working with Apple support on this, but no resolution yet. I suspect that the UUID (Universally Unique ID) should not be the same on two machines, but I don't know the consequences of changing it or which one to change.
Thanks.

Similar Messages

  • My mac book pro got stolen and i just purchased a new one is there any way i can recover my purchased songs from i tunes. I have the same account name, password and everything

    my mac book pro got stolen and i just purchased a new one is there any way i can recover my purchased songs and movies from i tunes. I have the same account name, password and everything

    Yes. Update to iTunes 10.3.1
    Then go to the iTunes Store and click Purchased "new" under Music Quick Links on the right side of the iTunes window.
    You can re download your purchased content from the next window.

  • SAM Account Name atribute

    Hi all,
    have an issue in Orchestrator which I am trying to debug but after reading some posts on TechNET I am not sure anymore it can be done. To the point. I am creating new mailbox via orchestrator, it's creating user, mailbox... everything is fine. Creating
    name of the mailbox, but when creating ACL for the mailbox, and SAM account name for it, it always croppes the name to 20 characters lenght, because of that somethimes I tend to get an error, that such SAM account name already exisits and mailbox cannot be
    created to the end by orchestrator. On the other hand, creating such mailbox, and giving it some account name manually allows to put there more characters than only 20. I know 20-characters limit comes form desire to be compatible with pre WIN2000 systems,
    hovewer is there a way to change it in Orchestrator or this is pre-defined and it's just the way it is.
    In my company we don't need to keep this 20-characters limitation, neccesarly...
    Thanks for all imput on that,

    Hi Friends
    In Lync 2010/Outlook 2010 clients can show the field "Alias" while the same field is not visible in 2013.My question is, whether we have any option to make this also visible on Lync/Outlook.
    In our company if Sam account name is A12345 then “Alias” will be the same .Also his internal phone number will be 12345 and his DID number will be Tel:+xxxxxxxxxxx;Ext:12345. Hence it is very
    important for us to display ”Alias”  it in the user property page in Outlook /Lync.
    -Sachin

  • Same account name on two computers can't write over network

    I'm having great difficulty synchronizing two computers. One is an iMac and the other is a MBP. They are both used only by me for work. I don't need to share them with anyone else, only with each other. The main account is exactly the same on both of them as the iMac is a Migration of the MBP, so the user name and password are identical.
    Regardless of how I set sharing/permissions on any given folder, I can only read in either direction. Whenever I try to write, it asks for authentication (odd since the volume is already mounted), then says the file already exists (even though it doesn't) would you like to overwrite? I click overwrite, and then it comes back and says "you can't overwrite since the file already exists". Huh?? Looking at the destination the file does exist, but is zero bytes.
    I finally created a dummy admin account on one of the machines, logged into this account from the other, and then things work like you would expect. I can write to those directories of the main account that have write privileges and not to those that don't.
    So my question, is there anyway to just log into the main account, which is exactly the same on both machines and be able to write? This odd behavior seemed to start somewhere around 10.5 as I was always able to do this before.
    Thanks,
    Darryl

    I am having exactly the same problem, also with an iMac and a MBP. My iMac is about 6 weeks old, and I migrated via Time Machine. I can read the files from the connected machine, but cannot write, regardless of which is the host. Permissions are all fine.
    I did notice one thing: the UUID number for the accounts is the same (accounts have same name as with darrylh). You can find this under System Preferenes>Accounts and right click or control-click on the account name after unlocking it. I am working with Apple support on this, but no resolution yet. I suspect that the UUID (Universally Unique ID) should not be the same on two machines, but I don't know the consequences of changing it or which one to change.
    Thanks.

  • Authentication and authorization done by different LDAP servers

    Is this possible with iPlanet LDAP Authenticator
    I want authentication to be done against LDAPServer A but authorization [ role
    assignment ] done by another LDAP Server B ?
    the authenticator only permits me to enter one server name
    would I need to write a custom authenticator ?
    help please
    currently on WLS 7.0, plan to move to 8.1
    prem

    "Prem" == Prem <[email protected]> writes:
    Prem> Is this possible with iPlanet LDAP Authenticator
    Prem> I want authentication to be done against LDAPServer A but authorization [ role
    Prem> assignment ] done by another LDAP Server B ?
    Prem> the authenticator only permits me to enter one server name
    Prem> would I need to write a custom authenticator ?
    Prem> help please
    Prem> currently on WLS 7.0, plan to move to 8.1
    Interesting. I believe I'm headed in the same direction. I have a
    company-wide LDAP server that I want to do authentication with, but I'd like to
    store authorization information for a small group of users (giving everyone
    else a "default" role), perhaps in the embedded LDAP server, and I'm hoping I
    can get this all to work in the JAAS framework. I'm still investigating this.
    ===================================================================
    David M. Karr ; Java/J2EE/XML/Unix/C++
    [email protected] ; SCJP; SCWCD

  • Account names can break LDAP logins?

    I've successfully installed and patched (patches 118833-36, 119963-08 and 122032-05) my Solaris 10 system so it's using LDAP against the Sun Java System Directory Server Enterprise Edition 6.2.
    On my test box, I have several test accounts setup.
    On the one that is simply my last name, everything works fine. SSH logins, telnet logins, and password changes. SO I'm sure the pam.conf and nsswitch.conf works right.
    On several other accounts, they work just as well.
    However two accounts do not. getent -v | grep username shows the accounts. I can "su - account" from root and get in fine. However if I try to SSH or telnet in it rejects my password. The password being entered IS correct.
    The one thing they have in common is that they are both contractor accounts, which due to corporate standards are
    8 numeric digits starting with an 8, so something like 81234567 would be a contractor ID.
    Renaming the bad contractor accounts in the LDAP editor (but NOT changing the password) allows me to SSH in.
    Renaming the test account with my last name to a contractor style name breaks it.
    I read "man -s 4 passwd" and couldn't find where our naming standard violates the Solaris system standard.
    Thoughts?

    From the Solaris 10 Basic System Admin Guide at: http://docs.sun.com/app/docs/doc/817-1985/6mhm8o5l8?a=view#userconcept-30
    "User names � They should contain from two to eight letters and numerals. The first character should be a letter. At least one character should be a lowercase letter."
    Sun probably should have used the word "must" instead of "should." ie. First letter must be a letter.
    The system behavior you are describing seems to bear this out.

  • I have enrolled for the apple developer program but apparently have the same account name in iBooks. I need to change the iBooks account but don't know how. Do I change my apple id? Will this cause me problems with iTunes etc etc?

    I have enrolled for the apple developer program but apparently already have an account with iBooks, cant have this it seems.how do I change my iBooks account, is this the apple id for my iPad and if I change this will it cause problems accessing iTunes etc?

    I guess nobody knows if the crash that occured was legitimate or not?  Apple phone support could do nothing for me, so I guess I am left to drive 45 minutes to the nearest store.

  • Different pop3 servers - different mailboxes in same account?!?

    When I change pop3 server in e-mail client it seems that e-mail client keeps separate mailboxes for each pop3 server, even though they are on the same account. So when you change pop3 server you can't access mail that was received on the previous pop3 server, instead new mailbox is created. To access old mail, you must change pop3 back to one previously defined (?!?).
    I would like to know is it possible to keep all mail on the account on the same place, that means if I change pop3 server in settings I want to see all mail that is received on that account on all pop3 servers and not only the one that is currently defined.
    And since my iPad now has 2 separate mailboxes on the same account for 2 different pop3 servers, is it possible to merge both mailboxes to be available at all times, no matter which pop3 server is defined in account?
    Thanks!

    Unfortunately, I would have to forward 2 GB of mail so that option cannot be used .
    When will IOS4 for iPad be available then?
    Thanks.

  • Should I have the same admin account name on multiple computers

    Currently I have a Macbook with an admin account plus 2 user accounts. When get a 2nd macbook, should I use the same admin name on the 2nd computer? I was thinking of making all admin account names the same for multiple macbooks, time machine, network etc. Maybe it doesn't really matter and it just means remembering multiple login names and passwords. On a related question, should the same account name be used on multiple computers. This would create a home directory on each computer with the same name. Would it be best to keep seperate names? I am refering to computer accounts, not itunes or app store accounts.

    It doesn't really matter, but my vote is for different Admin names and passwords and for different computer/disk names.
    The first one is for increased security (if someone breaks your password on one, they won't have access to the other). The second one is to easilly distinguish the different macs and disks in a file sharing, network browsing and syncing situations.

  • There are multiple users with the same display name

    Hi,
    We have a user and when she get an item assigned to her she sees the following alert:
    "There are multiple users with the same display name USERNAME and at least one of them does not have read permissions to some of the files"
    Now I looked in the database and when I run the following query with the username:
     SELECT     
         [ProviderDisplayName]  
        ,[DisplayName]  
        ,[HasDisplayName]  
        ,[Domain]  
        ,[AccountName]  
        ,[UniqueUserId]  
        ,[LastSync]  
      FROM [Tfs_Configuration].[dbo].[tbl_Identity] where displayname like '%USERNAME%'  
    Then I get 2 same usernames back, How can I get rid of one of them ? When I access TFS trough the portal I only find 1 occurence of this user.
    We use VS2013 and TFS2013 update 4
    Best regards

    Hi DSW,  
    Thanks for your post.
    In your query result, please check if these two users have the same Account Name. if they are two different Account Name in result, it indicate there’s two users have the same display name in your AD, please check that two users’ information in
    your AD. We suggest change one user’s display name in AD.  
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • More then one student license on same account

    Hello. Can i have more then one student license on same account. The 60% of thingy. One for home, one for work and one for the notebook. They may run simultaneously because of the friends using the computer. All 3 computers will use same account name and password.

    You may install software on up to two computers. These two computers can be Windows, Mac OS, or one each.
    If you install on a third computer, it will request you to de-activate on the other two computers.  You can then reactivate one of the previous two computers, and use Creative Cloud apps on it.
    If you regularly need to use the Creative Cloud on more than two computers then it would be best to purchase an additional subscription.  This is the same licensing btw which we have for our prepetual product.  An advantage though for Creative Cloud over the perpetual product is that you can install on Mac and Windows with the same subscription!
    As it stands, the EULA states that you can install it on up to two computers at a time, however, you cannot use applications on those computers simultaneously. This is the case even when you are not using the same application
    http://www.adobe.com/legal/licenses-terms.edu.html
    Regards
    Rajshree

  • Multiple LDAP Servers

    Is it possible to configure and use two or more LDAP servers to authenticate OBIEE users? We have users with logins in two different domains that need to log in to our OBI servers.

    Yes, It is.
    Just list out all the LDAP servers with domain identifiers.
    then In your authentication initialization block add all the LDAP servers. So the BI Server will authenticate against each server until it finds a match. or based on domain identifier it will go to the correspondent LDAP server.
    - Madan

  • I just received a new ipad and presently have an ipad 1. I was wondering how i can transfer everything from my old one to my new one and keep the same accounts and passwords or is it even possible or do you have to repurchase all of your apps

    I have an ipad 1 and just receive the new one.  I was wondering how i can transfer the apps and things that i have on my old one to my new one and keep the same account names and passwords.  Or do I have to purchase averything over again.

    How to Transfer Everything from an Old iPad to New iPad
    http://osxdaily.com/2012/03/16/transfer-old-ipad-to-new-ipad/
     Cheers, Tom

  • AD authentication : SAM and UPN not matching

    BO XI R2 SP1
    Windows 2003
    We have this environment where SAM account name and UPN are different for all users;
    for example, service account SAM is SVC_ACCT_ACNP, but my UPN is apps.center.svc @ pso.dns.com; just like any email address
    When UPN and SAM are different, the BO deployment guide on page says to use UPN when trying to log on to Infoview;
    we have tried with UPN and everytime we get 'Cannot get realm' error message;
    I'm wondering if the deployment guide is not referring to use exact UPN but the UPN like format; for example
    SVC_ACCT_ACNP @NW.PSO.DNS.COM where NW.PSO.DNS.COM is the REALM
    The reason I'm asking this because after looking at the log file with debug = true in the bscLogin.conf; I found when we use
    SAM (SVC_ACCT_ACNP), it passes username as SVC_ACCT_ACNP @NW.PSO.DNS.COM
    but when we try to log on to Infoview with UPN (apps.center.svc @ pso.dns.com), then it passes the username as it is; apps.center.svc @ pso.dns.com
    Appreciate any help on this. Thank you

    If using java SDK 1.5 then you should always try shortname(your normal AD logon name) @DOMAIN.COM where DOMAIN.COM = the Full Qualified Domain Name that the user belongs to, but you should be able to use the AD attribute UPN as well, even if they are different.
    If you are on an older version of XIR2 with java SDK 1.4 you will run into quite a few bugs in this regards, best bet is to ensure you have XIR2 SP2 or later and upgrade java SDK to 1.5 if you plan on using java/kerberos. We have it notes key words upgrade java SDK will find it on SMP.
    Regards,
    Tim

  • Changing the account name

    When I setup my new Mac, I created the same account name as my old Mac. This is creating problems during my migration.  How do I change the main account name?

    No need for response.  I was able to solve this through some trial and error.

Maybe you are looking for

  • How can I upgrade to 10.8.4... ?

    I am Using Mac Book Pro Mac OS X 10.7.5  Can any One give Some suggestion

  • Error in converting

    The first file I tried to convert worked fine. Now each time I try I get "error when accessing the service" Any thoughts on what I need to do now? I have tried several times with different files.

  • Header condition Percentage Value

    Dear Gurus, I have created a Header condition, wherein with calculation type as %. Now if i try to enter 5.5% it is not allowing and giving format error. System is accepting only rounded numbers only like 5,6,7 %. But i need as 4.5/ 5.5 . Please thro

  • Why is Downloading Creative Cloud desktop taking so long?

    It is an unusually large file size, or are many people experiencing this issue? It seems to have been stalled for two hours - no movement. My internet connection is fine.

  • Gnormalize failed to start, HELP...[RESOLVED]

    i got this error while start gnormalize any one know the problem? it happen after i performed a pacman -Syu Possible unintended interpolation of @segu in string at /usr/bin/gnormalize line 1086. Possible unintended interpolation of @segu in string at