Changing DNS Server on Lion OD/Kerberos Master

I have an interesting task ahead of me, but am unsure how best to proceed.
I spent days setting-up my new Lion Server and attached Pegasus RAID array.  There are 140 users, 8 share points, and hundreds of different ACL permutations within the AFP shares that reside on a thunderbolt-attached Pegasus array.  The only services running on the box are DNS, AFP, and OD.
I added a secondary server and intended to use it as an OD replica (redundancy is great, but the speed increase would also be great).  Problem is that I set them both with .local names.  I can't get an OP replica to run unless they are within the same DNS zone, and so that is what I am looking to do.
I have read a lot of Apple support documents and a couple books, and understand that changing the DNS server will likely break OD (certainly Kerberos).
My goal is to re-zone the DNS while preserving OD users, groups, passwords, and most importantly: how they relate to the ACLs on the Pegasus unit (I would very much like to avoid having to re-do all those permissions - particularly within the Lion Server UI).
If I need to do a re-install and then laterally migrate, I certainly can.  I am hoping for the path of least headache to be sure.
If anyone has advise on how to do this as painlessly as possible, I would appreciate it.

Will the OD archive contain the old DNS settings and somehow muck this up?
I don't know the answer to all of your questions but I do know this: If you have an OD archive from a master that had an incorrect hostname, this information was put into your archive.
"Open Directory" is comprised of three components: PasswordServer, LDAPv3 and Kerberos. This is what is backed up during an OD Archive. So if you have a archive from a machine with messed up DNS, I would not trust that everything will be fine after the restore.
Maybe somebody else can chime in and offer you further help...

Similar Messages

  • How to prevent changing DNS server address

    I work for a public school district. We just purchased our first batch of Win 8.1 PCs, but they are not the Pro version, so there is no gpedit.  I want to prevent students from accessing the TCP/IPv4 Properties dialog box in order to ensure that the
    DNS server address is always obtained automatically.  Can anyone tell me how to do this using regedit, or any other way?  Thanks!

    Easiest way is to assign these students a standard user account (without admin rights).. They cant change any system setting then.. Other than restricting privileges I don't think you have option here since you don't have group policy editor ..
    There could be a possibility to do this using regedit But it is not recommended since there are no any official article for this other than below untested third party article form ehow
    http://www.ehow.com/how_8110801_disable-tcpip-properties-regedit.html
    Besides it could be tedious.. enabling and disabling it.. 

  • Can't change DNS server setting on airport express

    new airport express, comcast cable ISP, i cannot change the DNS server settings, they are greyed out.  why  is there no way to change this?

    Mark-
    Did you get the AE to actually use the OpenDNS servers?  I have the new AE and Airport Utility 6.3.1 and while I can enter the OpenDNS server settings (208.67.222.222 and 208.67.220.220), they don't work.  When I use a Wi-Fi connected device (my iPhone, for example) it sill uses the Comcast DNS settings, totally ignoring the OpenDNS settings.  I don't know when they stopped working, but they worked in the past.  I've used the old Airport Utility as well (5.6) and it says the OpenDNS settings are active, but they aren't.
    I want to use the OpenDNS settings for Wi-Fi connected devices in my home for content filtering.  If anyone knows of a DOCSIS 3 cable modem that allows setting DNS servers, that would be an option too, but unfortunately, my Motorola SurfBoard SBG6580 does not.

  • Change DNS server settings

    Hi All, When I log into my router I can not find on any of the tabs where to change my DNS sever any ideas?                                                          Thanks Debbie

    Just came across this when looking for a way to change the server settings as I use my Sky Router as a backup measure (i.e. it's set up, ready to go, but for the moment, just serves the internet over one of the Ethernet ports via a better router and wireless network in my house). Anyway, as there doesn't seem to be a way to sort the DNS settings on the router itself, I would suggest the following to those who are looking to use OpenDNS (which is why I'm looking to do it). Disable the Wireless network on your Sky Box and plug in a cable DSL router (i.e. a router that doesn't have ADSL on it, but has an ethernet internet port for connecting to a router - or one that has that ability (some have multiple options to allow for failsafe - but anyway)).  Google "wireless cable DSL router" and look in the shopping section for an idea of them. Setup the new router as per the manufacturers instructions and connect the new router to the Sky Box by the ethernet port.  Now, assuming you've turned off the Wireless on the Sky Router (found under setup on the Sky router interface (192.168.0.1 from your computer normally unless you've changed it)) when you connect up the new router, this should be the only thing that is supplying internet into your home and you should be able to change the DNS settings on the router (make sure of this before you buy it just in case, but most of them you can do) and that way anything that is passed through the new router, even when it heads out on the Sky connection will use the new DNS settings. Ok, so it's a bit of a hassle and might cost you £20-£30, but if it's to use OpenDNS or such services for the protection of your family when browsing online, it's money well spent IMHO. Of course, if Sky had any nouce about them, they would simply give an option to use either their own DNS servers or the OpenDNS servers, even if they don't allow full customisation of them, especially with all the recent news about eSafety for people at home.  It would just make a lot of sense as far as I see. There are some routers out there now which fully intergrate with the OpenDNS service (Google OpenDNS Router to find some examples - a lot of NetGear ones now do - just makes it easier if you're a bit green on the techy front, though OpenDNS offer a lot of assistance and walk throughs on their own site too. 

  • EA6500 - using other DNS server only applies to Guest network?

    I have an EA6500. I use OpenDNS.org as my DNS server to provide additonal filtering. I have added the Guest network option to separate my network access.
    When I change DNS server settings on the EA6500 to those for OpenDNS, I've found they only apply to the Guest network. For the 'regular' network, the DNS server provided by Comcast (my cable provider) is used. I have verified this by connecting various devices to both the regular and Guest networks and checking which DNS server is in use.
    I assume this is a bug in the firmware? Or am I doing something wrong? Please advise.

    You're welcome
    Since we're into really in getting this possibly resolve, I suggest you try rolling back the firmware to the classic version then let's see.
    Rolling back the Cisco Connect Cloud firmware to the Classic EA Series router web interface
    http://homekb.cisco.com/Cisco2/ukp.aspx?vw=1&articleid=25856

  • DNS server isn't responding to certain IPs

    Hi,
    I have a laptop with DNS problem. It ping any internal ip but domain controller(my DNS server). if I change dns server to google's public dns, it works but I want to use my own dns server.
    If i change IP address it works. If I give that IP address to another computer, the computer gives the same DNS error. So I figure out that this IP address is the problem and I have 3 IP addresses like this with the same problem.
    How can I find out if My dns block that ip or How can resolve this issue?
    Thank s in Advance.

    Hi  Mugurlu ,
    What do you mean by saying :” It ping any internal ip but domain controller(my DNS server). ” .
    If you mean it can’t ping the DNS server .
    We could check there is route from clients to DNS server .And there is reverse route from DNS server to the clients .The firewall of DNS server should allow the network traffic .
    If you mean it can’t resolve names .
    First we need to ensure the firewall on DNS server allow the network traffic between server and the specific addresses .
    Then we could use network monitor on DNS server to check if the query packets reached or not .
    If not reached , we could check if there is route from clients to DNS server .
    If reached and server responded ,we need to ensure there is route from DNS server to clients .Then we could use Nslookup on client to analyze the process .Open
    Command Prompt ,type nslookup and type
    set d2 .Then type a name ,we could find out the problem through the process .
    If server doesn't respond ,we could enable debug logging on DNS server to analyze the process .Open
    DNS Manager ,right click on DNS server and click Properties .On
    Debug Logging tab ,select the box .
    Here is the guide for Nslookup :
    Nslookup :
    https://technet.microsoft.com/en-us/library/cc940085.aspx
    Best Regards,
    Leo
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Question re DNS settings on Lion Server

    Bit of a newbie question this...
    We have a Windows 2003 domain using SCHOOL.INTERNAL as the FQDN
    We now need to integrate a new Mac server running Lion into the mix
    The Mac server will not be Internet-facing, but will be used to manage internal Mac clients only
    Have added a Windows DNS A name / PTR record for the Lion server (macserver.school.internal)
    When we run the Server utility in Lion and look at the options in the Change Host Name window,the suggested server host name is macserver.school.internal (picked up from DNS I guess)
    Question:
    Does it cause a problem if we use the FQDN instead of the usual .local ?
    If not, do the Mac clients all need to have .school.internal hostnames also ? And do these need to be manually entered in DNS ?
    Thanks

    The DHCP service collects the client names, so you don't have to enter them. Actually, in a Mac network the systems see each other via Bonjour anyway (there's that .local domain again!)

  • How do I properly change the server name in mountain lion server?

    I need to change my server name to a FQDN, but tried this with Lion server in the past without success. I know in lion you'd use server app, but that's no longer avaiable in mountain lion server and I want to make sure I get this right the first time.
    Thanks!

    I was able to get everything working with some assistance from Apple's enterprise support. After changing the host name, the DNS was still not resolving properly and I couldn't turn on open directory so that I'd be able to start profile manager. The DNS interface is considerably different than that in previous versions of server. The network was set to manual ip with dhcp, which was pulling back an external IP. Overriding the DNS info coming in via the dhcp, setting it to localhost, resolved the issue.
    Thanks!

  • DNS server provided by VPN to Mountain lion doesn't work

    We are producing proprietary VPN server and client. After upgrade to Mountain lion the DNS stopped working. I noticed that if_index is now in the dns resolver decription when scutil --dns is used for listing. This if_index refers to the physical network interface. So I tried to send public DNS server from our VPN server. It helped because the DNS resolution is done over physical interface. Problem is that we need to use private DNS server, that is the purpose of VPN. The only suspicious piece of code is
    str = SCDynamicStoreKeyCreateNetworkServiceEntity(0, kSCDynamicStoreDomainState, gs_dynamicCache.m_serviceId, kSCEntNetIPv4);
    whic copies IPv4 settings from primary IPv4 sesrvice. Can you recommend good article where I would find and understand DNS reolution guidelines for Mountain lion? It is impossible to find something about that if_index. And we are pretty sure that it works correctly on Lion.

    cima.m wrote:
    We are producing proprietary VPN server and client.
    Please don't. People absolutely detest those things. MacOS X includes perfectly good VPN clients that work far better than any proprietary VPN. Why don't you just change the server to work with what ships with MacOS X?

  • Change of DNS server setting caused Exchange outages!

    I am trying to google/bing my way through this, but here are the main points:
    All remote Exchange servers had a) static IP addresses and b) were instructed to use DNS servers in Edmonton and Calgary
    If WAN links dropped, they lost DNS
    SOLUTION! Point remote servers to the domain controller in that location as the primary DNS server. WAN outage means Exchange still resolves names locally.
    Well the day came and we add the local DNS server for each remote site as the primary DNS server at the top of "DNS server addresses, in order of use" portion of advanced TCP/IP settings dialogue box.
    A reboot is performed
    Voila! Exchange shits the bed! Hub transport servers in Edmonton and Calgary cannot resolve remote server names; as in no host(a) record exists for them anymore. And we have a 91 minute outage until the DNS is sorted out (ipconfig /registerdns run on each
    server).
    Has anyone encountered this or have some deep knowledge of DNS (relative to my own) that could at least throw out a theory as to why this might happen?

    Hi, please issue Get-ExchangeServer -Identity "ServerName" -status | fl and check:
    CurrentDomainControllers
    CurrentGlobalCatalogs  
    CurrentConfigDomainController
    The server must been linked to the wrong server. You can change that in powershell too.
    Regards, Philippe
    Don't forget to mark as answer or vote as helpful to help identify good information. ( linkedin endorsement never hurt too :o) )
    Answer an interesting question ? Create a
    wiki article about it!

  • Lion DNS Server not answering reverse IP queries

    I just upgraded my server to 10.7 lion. Everything works great, except that the DNS sever will not answer queries about reverse IPs. Interestingly OD isn't affected yet though as I add more replicas I'm afraid that problems might start cropping up.
    Queries for forward zones work fine. Reverse zones don't
    I tried restoring from backup without luck.
    I found a directory called "/etc/dns.migrated-2011-08-06-002722" with the standard "loggingOptions.conf.apple", "options.conf.apple" and publicView.conf.apple.
    I checked another server that was also upgraded to Lion, the DNS service is running (it only has the original DNS name of the server when it was set up) and it shows the same symptoms; forward zone works, reverse doesn't.
    Has anyone seen this? Any tips for "fixing" my 200+ IP addr zones?

    I've got this problem, too.  I've tried a few things that have not worked.
    1. importing a plist from another working (SL) DNS server.  The zones all get imported, including reverse; however, the reverse zones are missing their nameservers.  After I fill in all ~50 rev zone NS entries (it validates to make sure they are all filled in), it looses all of its data.  All that time I spent is wasted.
    I've tried this on my backup server with a fresh lion/admintools install and again after software update
    2.  I've deleted /etc/named.conf and /etc/dns/db.* and placed a fresh named.conf in /etc
    added one reverse zone, setting its NS.  same thing.
    i was much happier with snow leopard, which is what i ordered from cdw, but they delivered these

  • DNS Server change

    Forgive me if this has been asked before, I've been searching for an answer and can't seem to find one.
    i am using the previous version of iweb and i have just published my site.
    I am trying to figure out how to use my registered domain name.
    I know i need to change my DNS server but don't know how to find out what the .mac one is..
    and if iweb 06 can even do this.
    also, when i published my site to my .mac account the first page comes up but none of the other pages that i linked from the main page.
    any thoughts or suggestion would be greatly appreciated.
    aavalenti

    Hi aavalenti,
    For the Domain I'd like you to have a look at the following page
    http://alyeska.altervista.org/en/iWeb_Domains.html
    However .mac doesn't provide DNS servers.
    For the question about the page and not working links you need to reupload the site from iWeb by making a publish all. Seems like some pages aren't on the server.
    Regards,
    Cédric

  • How to manage DNS in mac Lion Server

    I just upgraded my Mac Mini Server from snow leapord to Mac OSX Lion Server, but in Server Admin, DNS is not displayed as a service.
    Where you do you now manage DNS. The console contains messages that woudl seem to indicate that DNS did start up successfully.

    Greetings,
    You need to go here:  http://support.apple.com/kb/DL1419
    The DNS server, which remains a part of the Server Admin, has been separated from the Server.
    By the way, beware.  I tried to to the Lion upgrade in place and the Server (not Server Admin) piece failed and after I installed Server Admin my DNS set got hosed.  So I am now trying again using a clean install.

  • Script to Change DNS Servers on Remote Server

    I am new to powershell and I am trying to construct a script to change the DNS servers settings on a whole list of machines remotely. I have the list of machines that I want to change in a txt file. I have read several posts on this and tried several different
    methods but I cannot seem to get it to work. Here is my code, any help is much appreciated.
    $servers = Get-Content C:\PathToFile\computers.txt
    foreach($server in $servers)
        Write-Host "Connect to $server..."
        $nics = Get-WmiObject Win32_NetworkAdapterConfiguration -ComputerName $server -ErrorAction Inquire | Where{$_.IPEnabled -eq "TRUE"}
        $newDNS = "10.1.1.1","10.2.2.2"
        foreach($nic in $nics)
            Write-Host "`tExisting DNS Servers " $nic.DNSServerSearchOrder
            $x = $nic.SetDNSServerSearchOrder($newDNS)
            if($x.ReturnValue -eq 0)
                Write-Host "`tSuccessfully Changed DNS Servers on " $server
            else
                Write-Host "`tFailed to Change DNS Servers on " $server

    http://blogs.technet.com/b/heyscriptingguy/archive/2012/02/28/use-powershell-to-configure-static-ip-and-dns-settings.aspx
    Ed Wilsons Blog.
    $computer = Get-Content C:\PathToFile\computers.txt
    $wmi = Get-WmiObject win32_networkadapterconfiguration  -computername "$computer" -filter "ipenabled = 'true'"
    $wmi.SetDNSServerSearchOrder("10.0.0.15", "255.255.255.0")
    I dont have the feasibility to check as of now. Please test and let me know.
    Thanks
    Azam
    Mark As an Answer if it answered your question or helpful if helped.

  • Osx lion dns server, forward certain domain searches to other dns server

    Hi!
    i'm configuring the DNS service in OSX 10.7.1. I want to forward all queries to certain domain (f.e. *.special_domain.com) to certain dns server (f.e. 192.168.0.1 & 2)
    i remember in previous OSX Server versions that you can do that in an easy way:
    there were a /etc/resolver directory where you can place a text file in order to forward certain domain queries to certain dns server, like this:
    filename: /etc/resolver/special_domain.com
    content of this file:
    nameserver 192.168.0.1
    nameserver 192.168.0.2
    now in lion there is no such directory... someone knows how to do that??
    thanks for reading and regards!
    D

    i've just read about the "scutil" tool
    From the reply of the command "scutil --dns" i understand that is possible and also supported (i guess)
    Now i have to discover what files that tool reads, and which is the proper way to modify that
    I'll keep investigating tomorrot, now i'm saved by the bell!!

Maybe you are looking for

  • Update ios 7.0 failure

    Hi, please cuold you help me? i've got a pc using windows vista, any time i try to update my iphone or my ipad i fail. Downloading updates for the Os is ok but, when itunes tries to install new iOs release, an error occur and my iphone step into "rec

  • Sound too low on iPhone 4S

    This problem occures during conversation. I tried to use volume controls on the rim  but it helped only partially to solve the issue. Is it due to the connection quality or can I adjust on my own?

  • Ebay ask member question, enter code in box will not work, works fine in IE8

    I am using Firefox 19.0. While on Ebay if I go to "Ask seller a question", you have to enter a random generated security code in a box. In the past this worked fine, but in the past year or so has quit working with Firefox and several versions of it.

  • Be able to change prices, in a PDF price book, in accordance to the multiplier entered.

    Hi, We have a 250+ page list price book and our customers are requesting the option to change the prices in accordance to what their discount multiplier is; what is the best way to accomplish this? (Can it be done through Acrobat, LiveCycle, Javascri

  • Java.sql.SQLException: [POL-5150] access violation

    Hi all This is the error am getting when trying to connect to LITE db from JDK 1.4.2 Exception:: java.sql.SQLException: [POL-5150] access violation at oracle.lite.poljdbc.LiteEmbJDBCConnection.jniDriverConnect(Native Met hod) at oracle.lite.poljdbc.L