Can't create Local Network Users in Yosemite

I can't create Local Network Users (or change passwords)
Logged on to /LDAPv3/127.0.0.1 as directory administrator
When I try to create a new user (press the [+], fill in the form), it brings up the message:
existing connection is not authenticated or secure: password change denied
I suspect this is emblematic of other issues. I can authenticate for Mail and SMB, but not for AFP or Xcode

So I had this problem last night as well when I upgraded my 10.9.5 OD master to 10.10.
Two obvious problems after that upgrade:
1)  Could not add a new Local Network User
2)  Existing users could not connect via AFP (but could via SMB)
Through a series of trial and error (and with two Apple Support people...), we found that the following actions seemed to help fix some (but not all) of the problems.:
Problem #2 seemed to initially be fixed by archiving the OD Master, destroying the OD Master and then reimporting from the archive.  I archived from the upgraded 10.10, but should probably have tried restoring my 10.9.5 archive (which may end up being why I still have some problems...)
Problem #1 seemed to be solved when I used WorkGroup Manager to reset the password on the Directory Administrator account I use  (I also blew out all references to that account from the Keychain, so everything reprompted me to add that password
However, we think the root cause of this might have been that in /var/db/openldap/migration, the following "dot" files were still present after the upgrade
fs:migration root# ls -la
total 6308816
drwx------  10 root  wheel         340 Oct 30 18:59 .
drwxr-xr-x   6 root  wheel         204 Oct 30 18:57 ..
-rw-------   1 root  wheel           0 Oct 30 18:59 .autossl
-rw-------   1 root  wheel           0 Oct 30 18:59 .enableODProxyd
-rw-------   1 root  wheel           0 Oct 30 18:59 .rekerberize
-rw-------   1 root  wheel           0 Oct 30 18:59 .updateLocales
-rw-r--r--   1 root  wheel      333436 Oct 30 18:57 authbackup.ldif
-rw-r--r--@  1 root  wheel      617453 Oct 30 18:57 backup.ldif
-rw-r--r--   1 root  wheel      617453 Oct 30 18:57 backup.ldif.backup
-rw-r--r--   1 root  wheel  3228537344 Oct 30 18:59 oldsystem.tar
Those 4 .dot files were *not* present in that directory on the two other test OD Master servers that I upgraded without issue.
So we removed them and after having done all the above as well -- I can now add users to the server.   The OD engineer I talked to thought that the presence of those .dot files may have been triggering something to rerun every time PasswordService launched.
When all was said and done, I was then able to "kinit <mydiradminaccount>" correctly and get a "klist" without issue.
ALL THAT SAID:  As of this morning, *some* (most?  I don't know yet) of my existing OD user accounts are able to successfully log into the server.   A couple of them (so far) are reporting that their account is "disabled" (which is different from the "shaking"/can't-log-in behavior) -- but they can still log in via SMB -- so I think there was still a problem migrating OD accounts in the upgrade process.
AND -- I noticed that -- in Server 4.0 -- "change password" is greyed out, so I have to use WorkGroup Manager to change server account passwords. 
Whee...

Similar Messages

  • How do I create Local Network Home Folders for Users from an Active Directory binding?

    My situation is this... I run an iMac lab at my school.  I have a server set up to manage the network user accounts in the lab.  Currently, I can sucessfully create Local Network Users and log in to them from any of the iMacs.  My school has an Active Directory set up for all the students on campus.  What I'd like to be able to do is configure the server to allow the students to use their user names and passwords from their school accounts to log in to the iMacs and have it automatically build a network user folder on the server for them to use during the lab. 
    So far, I have been able to configure access for the Active Directory accounts to use the services on the server, mainly File Sharing, but I cannot figure out how to allow them to log into a user account on the client's machines using their same Active Directory credentials.  I have even attempted to allow the user accounts to create mobile accounts, but that's not working out either.  Entering indivual network user accounts into the server for every student every semester will be a nightmare.  I'm sure there's a way to do it automatically using the exisitng Active Directory structure.
    The live server is running 10.8.5 Server still, but I've also got a clone running OS X Server in case it matters.  Please help!

    ok reinstalled everything dns seems to be working have done sudo changeip -checkhostname and it says that both names match but then i started open directory and can't seem to get Kerberos started, i've tried changing it to stand alone then back again but it does nothing. I'm wondering why this would happen? i've tried adding a kerberos record but it doesn't do it just does nothing so i don't know what i'm doing wrong. I wondered if it might be a problem with the two network cards and dns as on ethernet one it is getting the dns name xserve.xxxx.ac.uk (which matches what the college server wants to call us) but on ethernet 2 gets xserve-2.local because it tells me that it already exists on ethernet one and renames it to this. I need to set up NAT so have ethernet coming in on port one and out again on port two. I wonder if my dns is backwards as its got the 192. address the NAT uses but its linked to the ethernet port one dns maybe this is the problem. would this cause open directory not to start kerberos?

  • Create a New Local Network User

    Hi,
    I have a Mac OSX (Snow Lion) server on a network with three Mac Computers (2 on Mavericks and 1 on Lion). Our computers are a shared resource among employees. Basically I enable each member of our company to be user on any computer.
    I had a chap come in and create the original employee user accounts (Local Network User). Since our company has grown by two. I now want to create accounts them too. This chap has now moved.
    So far I have gone into Server OSX and created the users. How do I now get these accounts to show up on the client computer login screen. I went into profile manager and read the server documentation. And then got stuck!
    Can anyone coach me through this.
    Thanks
    Andrew

    If you want the local user account to use a specific UID to match an account in your Open Directory setup then it is not necessary to manually create a local user with a matching UID. The normal approach is to set the Mac up to automatically create a mobile account that matches the Open Directory account. When the user logs in on the Mac for the first time the user account would be created with the matching UID, matching short and full names, and matching password and the password will be kept in sync with the Open Directory account. This setting can be done via Workgroup Manager and MCX preferences if you still use that method, or more typically these days via a setting in Profile Manager. (Or equivalent.)
    If you really must create a local account with a specific UID then create the local account as normal, make sure you have if needed unlocked the padlock in Users & Groups in System Preferences and then Option-Click on the user account on the left, a menu will appear listing the choice "Advanced Options..." and this will let you change the UID.
    Note: You may need to later do the following in Terminal.app
    sudo chown -R user /Users/user

  • Local Network User with Local Only or Services Only Home Folder Setting

    Hi all,
    According to the OS X Server Advanced Administration Guide, under the "Choose a user’s home folder location" section, "If you choose Local Only, the user won’t have a home folder on the server and can’t log in using the account information stored on the server."  However, when I create a Local Network User account with a "Local Only" home folder, Server.app creates a home folder in that user's name in the User's directory of the Server itself.  According to the documentation that shouldn't happen, right?
    The documentation gives no mention to the "None - Services Only" setting for the Home Folder.  I will only be giving users access to DNS, File Sharing, NetInstall, Software Update and Profile Manager.  I believe all I need are "Local Network User" accounts.  However, the documentation confuses me on whether the Home Folder setting should be set to "Local Only" or "None - Services Only".  Can someone clarify this for me?
    Many Thanks!

    The idea is that a local home folder will get created, but the home folder will not be available to the outside world via services (e.g. Portable Home Directory). I don't believe anything in the services you provided requires a home folder. So, you should be able to get by with "None - Services Only".

  • I can not create a new user account on eprint

    i can not create a new user account on eprint. I have been trying for over an hour and it repeats telling me that my email addresses are not entered correctly, however they match. ? 

    I have tried to create an account via ePrintCenter and it seems that the published application has several flaws in interpreting the provided input.
    1) In the Filed for last Name I enter my last name, which consist of only Alph Characters. The form however thinks that there is some sort of special character and rejects my Input.
    2) E-Mail address. is not identical; OK, so I do a quick OCR on the E-Mail and guess what they are identical. Again the form Fails to recognize this.
    3) Enter a password (2 Fields) and a third is displayed which is marked as "*required" but is not labeled as to what the required info could possibly be. Or is it a 3 password confirmation box, who knows.
    All I know is that a simple registration is a major pain with this HP site.
    Any Help as to how to alleviate this would of course be greatly appreciated.

  • Can I Create a New User Account and Move Existing Account ???

    Lion was reinstal.
    I'm suspecting issue with one user account.
    Can I creat a new user account and move all my files to that new user?
    What are the impact?
    How about permissons on this files?
    What about the Library Folder?
    Thank you for your help and support.
    BigBlaze

    This should help you out after  you have created the new user account. You are trying to make it much more complex than it needs to be. Just follow the directions in:
    Transferring files from one User Account to another.

  • How can i create a new user with only read rights ?

    How can i create a new user with only read rights ?

    You are asking about a Database User I hope.
    You can look into the Oracle 8i Documentation and find various privillages listed.
    In particular, you may find:
    Chapter 27 Privileges, Roles, and Security Policies
    an intresting chapter.
    You may want to do this with the various tools included with 8i - including the
    Oracle DBA Studio - expand the Security node and you can create USERS and ROLES.
    Or use SQL*Plus. To create a
    user / password named John / Smith, you would login to SQL*Plus as System/manager (or other) and type in:
    Create user John identified by Smith;
    Grant CONNECT to John;
    Grant SELECT ANY TABLE to John;
    commit;
    There is much more you can do
    depending on your needs.
    Please read the documentation.
    -John
    null

  • How can i create a new user in OID DIT tree programmatically  ?

    Dear All,
    How can i create a new user object in the OID DIT tree programmatically ?
    any help will be appreciated.
    Regards,
    Mohammed Amin

    Dear Eng. Jaime.. 
    Thank you so much  for replay...
    Can yon  explain 
    Do you want to create a contact in Jabber?
    Do you want to enable Jabber for a user?
    And what you meant last question..

  • A particular network user can't login to a mac in a classrom but other network users can. Then the network user can login to other identical macs in same classroom. Anyone seen this before?

    A particular network user can't login to a mac in a classrom but other network users can. Then the network user can login to other identical macs in same classroom. Anyone seen this before? It has happen twice. Two different teachers in two different classrooms entering the correct user name and passwords and computer won't allow them to login. Then they try in different computers in same classroom and have no problem login.

    Yes. I can login with a test user. And any other network user can login as well to this particular mac. Actually the mac has bootcamp and boots into either mac or windows. The same user entering the same login username and password can login into the windows side, but not the mac side.
    I had this same issue last semester in another classroom, another mac and a different teacher. This summer I reformatted and imaged that mac and I asked that teacher to login today to that reimagened mac and she had no problem today doing so.

  • Could any one tell me that How can i create the service User ie j2ee SID

    hi all,
    In the implementation of SPNego Authentication schem in my portal system.
    i want to create the service user ie .j2ee-<SID>.
    <b>could any one tell me that How can i create the service User ie j2ee-<SID> in my visual administrator??</b>.
    any help will be highly Appretiated .
    thanks and regards.
    vinit soni.

    Vineet,
    the user management tab opens in Read Only mode - thats why the button is coming as disabled. There is a button for switching into Edit mode - it looks like a pen / pencil on the top bar. Click on that - your "Create User" button would be enabled.
    Also regarding creation of Service User via code level you can see <a href="https://www.sdn.sap.com/irj/sdn/thread?messageID=1057074">THIS</a> thread. And <a href="http://HERE">http://help.sap.com/saphelp_nw04/helpdata/en/f9/e3162ec55f4df6922d161f3785012a/frameset.htm</a>HERE[/url] is the SAP Help documentation on required permission settings.
    Regards,
    Shubhadip
    Message was edited by:
            Shubhadip Ghosh
    Message was edited by:
            Shubhadip Ghosh

  • Wifi Bug - Can't create a network

    Installed Snow leopard, upgrade to 10.6.2, Airport client 2009-002.
    Can't create a network thru airport menu

    Try a new post in the 10.6 Networking forum.
    DALE

  • Can I create a network for printing & music alone ?

    I don't have DSL or any type of broadband - still using dial up.
    If I buy an Airport Express can I configure it to wirelessly print and stream music or do I need a wireless network in the background to make this work ?

    Can I create a network for printing & music alone ?
    Yes
    If you also want internet access at the same time you will need to tweak things a bit.

  • Can I create group in users' My sites?

    Hi All,
    Can I create group in users' My sites? Also, Is it possible to create a personal site as https://<My site host site collection url>/managed path/username ? I am creating host based site collections with My Site Host site template.
    Thanks,
    Moohak

    Yes You can create group in users mysites.
    Create Host header site collection, then create my site host in that host header site collection.
    Then update this URL as shown below in my site settings
    http://technet.microsoft.com/en-us/library/ee624362%28v=office.15%29.aspx
    In the My Site Host section, type the URL of the My Site host site collection that you created earlier in this task.
    If this helped you resolve your issue, please mark it Answered

  • Installed OSx Lion. Can't see my network user on launch

    Hello,
    installed OSx Lion a few hours ago but on OSx launch I can't see my network user anymore.
    Network user was appearing properly on Leopard.
    Please help as I can't get access to our company network anymore.
    Thanks!

    I figured out the answer. unfortunately, the Belkin router I have does not support a HDD formatted in Mac OS. I guess I have to decide whether to stay with FAT32 for my netweork drive or get a new router...

  • Can't see local network

    I have 3 computers networked together. One is plugged directly into the router, the other two use wireless cards to connect. The computer I use most is one with a wireless connection. Sometimes my computer doesn't see my network. I know the router card works, because at those times I can see other wireless networks in my neighborhood, I just can't see the one in my own house. During those times my son's computer, which is about 3 feet away, sees and connects to the local network just fine, so I know the router is working. When I can see my local network, the signal is strong, so I don't think it has anything to do with signal strength. I'm stumped. When the problem occurs I've tried rebooting my computer, but that doesn't make a difference.

    Hi…….
              Well in this case what you do is from your hardwired PC log into the setup page of the router with http://192.168.1.1 username leave blank and the password is admin.
    Under the wireless tab change the channel to 11. And under advanced wireless settings lower the Beacon to 75 > Fragmentation Threshold to 2304 and the RTS Threshold to 2307. And then you can check the connection with your wireless PC
       Also try to reinstall the wireless card in your Pc once.

Maybe you are looking for

  • "This Accessory..." pop-up message

    I have not had a problem with my iPhone until a couple of says ago. I keep getting the following pop-up message "This accessory is not made to work with iPhone would you like to turn on airplane mode....." Nothing is connected to it, not even headpho

  • Price refresh for new Shopping Cart created from a model

    I'm looking for a solution for the following problem. When i create a shopping cart from a model that has been previously created with a certain price, i'd like the system to update this price if it has been updated between model creation time and ne

  • Boot from external Firewire Drive-cannot repair or optimize internal drive.

    Hi all Connected my new 300 GB Seagate External Firewire Hard Drive today. Installed Tiger from DVD. Updated to 10.4.3. Installed Tech Tool Pro 4. Updated to 4.1.1. Booted from External Firewire Drive. Disk Utility cannot Verify or Repair internal dr

  • Material Master Field Selection Group

    Hi Experts In Material Master Under MRP2 View - Field # Prod Stor Loc, (MARC - LGPRO)  appears & Work Scheduling view, under Field Selection Group: 77 Now I want to also add/extend  this field:  MARC - LGPRO  in Plant Storage 1/2 view. Possible ? Wha

  • Backup iPod to External Hard Drive

    I backed up my iPod to an external hard drive. It created a file with the the extension "bkf" but when I try to open it, it won't let me. Help Please