Can't Login to New OD Master - Even when bound to OD

This is a completely new server installation on a multi-core MacPro of Leopard Server 10.5. I have followed best practice standards by configuring DNS first and double checking with changeip command. I than went from Standalone to OD Master and all the setting checked out. I configured DHCP for our small network. That worked fine. I than configured a home directory share with automount, created one new account and created home directory. I verified login to the server and creation of the home directory. Server updates are also done now.
Now the confusing part. I took a Mac OS X Leopard client machine, fully updated and used Directory Utility to bind client to server. Directory Utility reports bind is operational and working. I can use the Directory app to see myself as a user. HOWEVER - I can NOT login to the OD Master as the user I setup. The login screen just shakes me off as if the password is wrong. It is not.
I looked at the OD logs and I am being successfully autheticated by server. The client just refuses to login. I have tried 10.4 and 10.5 clients.
What have a messed up? <grin>

Hi
I'm guessing when you supply the user name and password there is a slight delay before you get the shake? is that correct? Or do you provide the user's credentials and you get the shake immediately with a message telling you the AFP or SMB Server can't be found?
To start with verify if the created user is a principal of the Kerberos Realm. On the server issue:
sudo kadmin.local -q list_principals
amongst other things you should see an entry for that user. Something like [email protected]
What you can do is to unbind. Remove the DirectoryServices folder and the edu.mit.Kerberos file from /Library/Preferences, restart the client and then place the Server's IP address in the client's DNS Server's field as well as the Domain name in the Search Domains field. Use Terminal and the host command to resolve the server's fqdn and then its IP address from the client. This will qualify the server's DNS service on the forward and reverse pointers. Use Directory Utility to bind to the Server using its IP address alone and don't bother with authenticated binding. Double-check the edu.mit.Kerberos file has been created in /Library/Preferences (this is evidence that you have received a TGT - you can refer to the server logs as well that should show this happening), log out of the local admin account and select Other. Go for the log in again and hopefully you should be now logged in with a network user's account and home folder.
Hope this helps, Tony

Similar Messages

  • How can i stop open new tab on safari when i click  on link or anything ??

    how can i stop open new tab on safari when i click  on link or anything ??

    Check the links below for options to remove the Adware.
    The Easy, safe, effective method:
    http://www.adwaremedic.com/index.php
    If you are comfortable doing manual file removals use the somewhat more difficult method:
    http://support.apple.com/en-us/HT203987
    Also read the articles below to be more prepared for the next time there is an issue on your computer.
    https://discussions.apple.com/docs/DOC-7471
    https://discussions.apple.com/docs/DOC-8071

  • I have an iphone 4 and I can't get cloud or ios 5 even when i download all updates

    I have an iphone 4 and I can't get cloud or ios 5 even when I connect my iphone to the computer and download all updates. Can someone help?

    Are these SMS messages or iMessage type messages (the recipient has to use an iOS phone)?  It sounds like you are trying to send an iMessage and the receipient's phone or current setup is not on.

  • How can I open a new page (using "Pages") when I already have another page open?  It just keeps reverting to the page I have opened already and won't let me open another one?

    How can I open a new page (using "Pages") when I already have another page open?  It just keeps reverting to the page I have opened already and won't let me open another one?

    To make a new document, go to File > New From Template chooser and choose the type of document you wish to create.
    To add a new page to an existing document go to Insert > Sections > Blank.

  • My computer can not recognize the new Apple iPod touch when it is connected via the USB cable (that goes with it) attempt to attach it to the computer.

    My computer can not recognize the new Apple iPod touch when it is connected via the USB cable (that goes with it) attempt to attach it to the computer.

    You do have iTunes installed right?
    See:
    iOS: Device not recognized in iTunes for Windows

  • My Ipad turned itself off for no reason and I can't turn it on. Not even when I'm charging it. What can I do??

    My Ipad turned itself off for no reason and I can't turn it on. Not even when I'm charging it. What can I do??

    iPad: Not responding or does not turn on

  • Can't login to Azure from Visual Studio when creating new app.

    Hi,
    I already tried this at two different computers.
    Install VS 2013
    Get VS Update 2
    Get VS Web Essentials
    Get Azure SDK 2.3
    Launch VS, Log-in with MSDN acc.
    File-New Project - ASP.NET Web Application (pick MVC + Web API)
    Use "Create remote resource - Web Site"
    OK
    Get asked for Azure login again (sigh..)..I log in.
    Get error message: "Unable to create remote resource. 'One or more errors occured'" .. really? eh.. :D
    Ok, so now i try the Manage Subscriptions link to check the azure account.
    Nothing is there.so I guess I need to sign in again because my previous login got forgotten
    I log inagain.
    Get dialog with "The task argument contains no tasks. Parameter name: tasks"
    Ok, no Azure for me I guess.
    btw: I then logged into web Azure portal and noticed I am over the spending limit now, so my subscription was disabled, but if this is the case why I can't login to Azure from VS, then just tell me. Skip those unrelated (for me) error messages.
    Screenshot: 
    https://www.dropbox.com/s/06olj5icdn9brbo/Screenshot%202014-04-12%2013.23.00.png

    Hi,
    Based on your description, it seems that your azure subscription was over the spending limit, about this account issue, I suggest you contact with azure support, it's the best choice for you. Please contact support team by creating a support ticket at
    http://www.windowsazure.com/en-us/support/contact/
    Or if that doesn't work because you don't have an active subscription you will need to contact general customer support to have them create a support ticket for you
    http://support.microsoft.com/gp/customer-service-phone-numbers?wa=wsignin1.0
    About this incorrect error message, I suggest you submit this feedback at:
    http://feedback.azure.com/forums/34192--general-feedback
    Best Regards
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • Can't Login to new username created by Migration Assistant.

    Brand new to the world of Macs and getting a bit frustrated.
    I started a discussion earlier about how Migration Assistant created a new account and wanting to get those files to my original account. I got no response but now I'm finding a bigger issue. I can't figure out how to log on to that new user account. Initially I went to the the Users and Groups settings, and reset the password for that new user. Now when I try to log in as that new user, I get a message that says I must reset the password before loggin in. So I enter the password twice, hit reset, the window shakes and nothing happens. I've tried 3 different passwords thinking maybe it just isn't log enough, but to no avail. It won't let me reset the password at the log in screen so how am I supposed to get into the account? FWIW, its listed as a Admin account under Users & Groups if that makes any difference.
    Assuming I can get in...what's the easiest way to get the files over to the original Admin account? I'm just transfering over iTunes (music and apps)...and nothing else. Is it easiest just to transfer files between the user accounts (which doesn't look terribly straightforward)? Should I delete the files and copy them over from a hard drive? Since the machine is only a few days old should I just wipe it clean and start again as if its brand new out of the box again? Again, just trying to get iTunes info copied over so my wife can sync her iPhone from the MacBook Pro instead of the PC.

    First, note the short name of the account. This is the same as the name of its home folder, but not necessarily the name that appears in the login window.
    Restart your computer, and while it is starting up, hold Command-S.
    This will start up your Mac in Single User Mode. Once it has started up, you will need to enter three lines of code.
    Enter sh /etc/rcand press return.
    Then enter passwd yourusername and hit return. Now you will have to enter a new password twice.
    What you type won't appear on screen, but it is working. Once you have done this, type reboot and hit return.

  • How can I know the new Material Master has been created?

    Does anyone have been tried about how to trigger the new Material Master has been created at a time interaval(maybe an hour or a day)?
    I want to transfer the new Material Master within a given period from SAP R/3 4.6C to .NET Application through standard BAPI or RFC and .NET Connector 2.0. How can I do?
    Any suggestion is wellcome. Thank You.

    Thank you Jiri Ehrlich for answering my question..
    I choose the third way as you suggest..
    ".. 3) Create your own ABAP function to export whole Material Master, call this function from your .NET application and do synchronizing on .NET side (so your .NET application will be RFC client).."
    I've tried RFC that retrieve Material Detail by using BAPI_MATERIAL_GETLIST. It works fine but if I want to retrive the new Material or modified within a given period of time(for example 15 or 30 minutes). How I can do? Is there any standard BAPI or RFC to call from .NET or I have to write new RFC.
    I have little background of ABAP so help me please. If I have to create new RFC, is there any ABAP Function to call or which table I can retrive those information.
    Anyone can suggest?? Thanks in advance

  • Can't login to new Client 100

    Hi,
    I have installed SAP Netweaver 7.0 SR1 SP3 ABAP Trial Version on Windows.
    I have defined a new Client 100 with transaction SCC4.
    I can't login to this new Client, it fails with message "name or password is incorrect". I have tried multiple credentials.
    sap*/minisap
    sap*/pass
    sap*/06071992
    None of them work
    Please can you help?
    Thanks, Olivier

    > I can't login to this new Client, it fails with message "name or password is incorrect". I have tried multiple credentials.
    > sap*/minisap
    > sap*/pass
    > sap*/06071992
    sap*/pass is the one you need. For this to work you have to set the profile parameter login/no_automatic_user_sapstar to 0 (zero) and restart the instance. This parameter defaults to 1.
    see [SAP help|http://help.sap.com/saphelp_nw04s/helpdata/en/22/41c43ac23cef2fe10000000a114084/frameset.htm] for more info.

  • 9i can't connect to a data base, even when I use another user's tnanames.or

    I can't connect to a data base, even using tnsping with a tnanames.ora file that I copied from a user's PC that was able to connect. It's a new install of 9i on my PC. What did I miss? I'm on a Win 2000 box and Oracle is on a UNIX server.
    Here's the description from the tnsnames.ora file:
    HISTA02A =
    (DESCRIPTION =
    (ADDRESS_LIST =
    (ADDRESS = (PROTOCOL = TCP)(HOST = bkodv1)(PORT = 1521))
    (CONNECT_DATA =
    (SERVICE_NAME = HISTA02)
    The file is from the previous version 8.1.7, should that matter? 9.2.0.1 is the server now.

    Yes, I even pinged it to make sure. When I do a tnsping HISTA02 I get :
    C:\>tnsping HISTA02
    TNS Ping Utility for 32-bit Windows: Version 9.2.0.1.0 - Production on 28-FEB-2007 14:25:53
    Copyright (c) 1997 Oracle Corporation. All rights reserved.
    Used parameter files:
    C:\Local\network\ADMIN\sqlnet.ora
    TNS-03505: Failed to resolve name
    My SQLNT.ora looks like this:
    # SQLNET.ORA Network Configuration File: C:\orant\network\admin\sqlnet.ora
    # Generated by Oracle configuration tools.
    NAMES.DEFAULT_DOMAIN = cboent.cboe.com
    SQLNET.AUTHENTICATION_SERVICES= (NTS)
    NAMES.DIRECTORY_PATH= (TNSNAMES, ONAMES, HOSTNAME)

  • Why can't I connect to App Store even when I am connected

    Why can't I connect to my App Store even when I'm connected to the internet

    Reset the device:
    Press and hold the Sleep/Wake button and the Home button together for at least ten seconds, until the Apple logo appears.
    If that doesn't help, tap Settings > General > Reset > Reset All Settings
    If that doesn't help, tap Settings > General > Reset > Reset Network Settings
    You will have to re enter your Wi-Fi password.

  • How can I restore my new iMac back to when I first switched it on?

    I was so keen to get my new iMac working that I got my name wrong in the setup and I stupidly skipped the migrate settings step which would have taken everything over from my old Mac.
    How can I get back to how things were when I first switched on so I can go through the whole procedure again - this time the right way?
    Thanks in anticipation.
    GeoffT.
    iMac 24"   Mac OS X (10.4.9)  

    Thanks Matt. Your comments are reassuring.
    But I also need to reset the name that I typed in at the beginning as I started to set up the machine for my business partner (we bought two - one for him, one for me) but he finished up taking the other one. So I need to go back to that first switch-on screen again.
    GeoffT.
    iMac 24"   Mac OS X (10.4.9)  

  • I can't login to Store from my ipad2 when my Wi-Fi is working

    It said "i can't login to iTunes Store", but my wi-fi connection is working. I can Online and I can see apps in the app store, however I cannot download any apps, please someone can help ? Thank you

    I've been trying to update and install a few apps within the last hour with limited success. I'm inclined to believe the app store may be having some issues like earlier this month (2 June) with iPad installation of apps. I get "unable to connect to iTunes store" and my apps that need updating are blank squares that all say waiting. I'm pretty sure it will be fine in a few hours. There may be maintenance of some sort. My husband is having the same problem. I'm using an iPad 2, iOS 4.3.3 and he is as well.

  • Can't login to new open directory users

    I have a Mac Mini Server running 10.8.2 Server. I have existing users, most with no home directory and a couple with network home directories.
    However, any NEW users I add (in LDAPv3), they aren't able to login. When I create the user, the "access account" option is checked and stays checked after the user is configured & saved, and stays that way when I relauch Workgroup Manager.
    However, when I attempt to login to this user from a network comptuer, the "access account" checkbox gets unchecked. I can check it again and save the account, but when I reopen Workgroup Manager, it's unchecked.
    Help???

    Good tip from Francis.
    Last night I finaly was able to get things back to semi normal to summarise here are some tips that worked for me.
    Things first went wrong when I tried to add a new user in work group manager. After doing this I got some quite strange behaviour.
    The server appeared to hang when loggin on with the new user. but ssh to the server was working.  Finally after about 10 minutes I hit the reset button on the server it appeared to go into sleep mode then automagically it logged in the user. Wow did it work .... no,   Bad news other users could no longer ssh to the server... Arrrr.  Cause tracked down to Kerberous reported as no longer running... Clients (my family )  startign to report cant access services like email ... help... 
    Rather than all the pain of tryig to fix that this is what I did.
    1) Back up OD in Server Admin ( not Server.app) OD dosent show up there dont know why ??
    2) Make sure the DNS is working
    nslookup, dig, hostname commands ... all reported correctly  forward and reverse MYSERVER.MYDOMAIN.COM. domain and IP address.  I even re-ordered the DNS name so that the local address 192.168.10.X was reported first  on my local netwrok before the external ip of the server.
    3) Create a completly new OD by deleatign the old one by setting is as a stand alone then re-creating is as a new  master ( use Server Admin tool )
    Finally Kerbrous all reported as runnig ... Try again to add a user...
    4) Add new user in Workgroup manager open on server not remotly this didnt work.
    5) set home account with apf://fqd.name/Users/ 
    6) make sure home account is accessable on network.
    6) set shell
    7) in Server Admin give all permissions to services new user will need. such as ssh login as required.
    8) in Server.app ( not Server Admin or workgroup manager )
    check that new user appears.  The local OD must be in the Directory Exployer search path for this to happen
    and the server must be binded to this path.
    I added both /Ldap3/127.0.0.1  but also importantly /ldap3/MYSERVER.MYDOMAIN.COM
    9) in Server app click on the user then select the Advanced settings. Make sure user has home dir selectd as the correct /Users folder on the server
    ( this was not set at first and had the value of 99  no idea why ) there are also other important settings here.
    10) Finally restore OD with perevious backup to add back the rest of the users.
    Apparantly this actually does a merge not a overwrite.
    End state every thign finaly working .....
    except the iChat/jabber server for some reasion wont accept authanicate users.... rrrr.
    Bonjour works on the local network but well the point of havign a jabber server was for family in countary A to talk to grandparents  and have private secure video phone with country B so would have been nice if that worked
    Good luck
    Hope that helps 

Maybe you are looking for