Help needed to setup/kerberize OD replica

Hi all!
I have setup an OD master w/o problems. DNS is up and running fine! changeip -checkhostname has nothing to change.
Kerberos-Status is working and the Realm is defined.
Now I wanted to promote a second server to OD replica.
Here I run into the same problem over and over again!
The command
slapconfig -createreplica 192.168.xxx.xxx hbartsch
works fine through steps 1 to 7
but fails in step 8:
+++++ SNIP +++++
8 Enabling local Kerberos server
command: /usr/sbin/kdcsetup -c /LDAPv3/127.0.0.1 -a hbartsch -p ** -v 1 KERBEROS.REALM.IS.HERE
command: /usr/sbin/kdb5_util -r KERBEROS.REALM.IS.HERE load /var/db/krb5kdc/initial.dump
command: /usr/sbin/kdcsetup -e
command: /usr/sbin/sso_util configure -x -r KERBEROS.REALM.IS.HERE -f /LDAPv3/127.0.0.1 -a hbartsch -p ** -v 1 all
command: /sbin/kerberosautoconfig -u -v 1
Unable to set diradmin credentials on /LDAPv3/127.0.0.1: 5000 Credentials could not be verified username or password is invalid.
Failed credentials: hbartsch **
Unable to create our computer account: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to set kODAttributeTypeXMLPlist attribute on our computer record: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to set kODAttributeTypeIPAddress attribute on our computer record: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to set kODAttributeTypeENetAddress attribute on our computer record: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to synchronize creation of our computer record: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Updating ldapreplicas
Unable to set ldap read replicas on the ldapreplicas config record: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to set xmlplist on the ldapreplicas config record: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to retrieve or createcom.apple.opendirectory.group: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to add master to newly created com.apple.opendirectory.group computer group: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to add ourselves to the com.apple.opendirectory.group group: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
Unable to synchronize com.apple.opendirectory.group record: 4001 Operation was denied because the current credentials do not have the appropriate privileges.
+++++ SNAP +++++
diradmin name and password are ok, as I am able to bind client computers to the OD master using the same credentials.
Any ideas what's wrong and how to solve it??
Thanks in advance
Holger

Two things helped me fixing this issue:
1.) Mac OS X Diresctory Services v10.6 by Arek Dreyer and Ben Greisler. Find it @ Peachpit Press
2.) http://support.apple.com/kb/TA23516
This knowledge base article has been written for 10.4. But with a little understanding of 10.6 and the changes between both OS versions it was simple to get back to a clean Standalone server.
With that it was as easy as cake to promote the server to a replica!

Similar Messages

  • WRT160N Version 3; SERIOUS HELP NEEDED FOR SETUP PLZ??!?!?!

    I bought this router probably around 3 weeks ago. 
    The following is a list of chronological scenarios that i have tried in order to install it and everything during the first week that i got it:
    1. I followed the CD's instructions, got LELA, but then when i used LELA to 'add another computer' it just gave an error, and then after this i could not be screwed using LELA anymore and so i uninstalled it, and then went online to 192.168.1.1 to configure the settings of the router, SSID, password and security which i put was WPA2 etc.
    BUT THIS DID not work at all, i have 2 laptops, 1 of them which is new, and the other which was a couple of years old, they could not detect anything.
    2. I then did some internet research, and read on these forums that i needed to change some of its advanced wireless settings, i did that. And then I could actually connect......and was extremely happy at this moment, BUT the next day i noticed, that even though i was about a metre away from the router, my speed was varying BADLY, initially when i first connect with my new laptop which has a Intel Wifi 5100AGN adapter it has a speed of 144mbps, but when i open internet explorer, i see the speed going slower and slower, until it is 1mbps, and sometimes the wireless just cuts out. This happened to my other laptop as well.
    3. I then called for technical assistance, spent so much time talking trying to solve, and downloaded the latest firmware, reflashed the router, but still it has this problem of slowing speeds which is really frustrating.
    And doing some more talking and following more instructions from the person on the phone, both my laptops could not connect to the router, even though it can see it at 'Excellent' connectivity.
    4. And so, the person on the phone concluded that i should exchange the router with new one, which i am planning to do, and will probably get it tomorrow. But i am also thinking to myself whether or not to get a different one.
    SOME NOTES:
    -When it is wired the internet works fine
    -the adapter in the older laptop is a intel 2200BG, so i know that it would probably go at a max speed of 54mbps
    -when i said changing advanced wireless settings, i meant changing frequency/RTS/beacon levels etc to the values i have seen on these fourms.
     CURRENTLY, since i am exchanging i have gone back to the old ASUS router which is G. and it connects well with the old laptop with a constant speed of 54mbps, but havent tried the new laptop as i can not be bothered. Also my main reason of getting a N router is just for range, because with the current one, i just cannot detect the router when i am in my bedroom, which is less than 20m, even if i can detect it is is very poor connectivity, WHERE AS with the WRT160n before i exchanged it, i could detect at first with Excellent connectivity, but as i said, the problems with speed and wireless cutting out etc is what results from this router.
    I guess my main point is that, i want to ask any of you have used the VERSION 3 of WRT160N, and is currently working very well wirelessly. Can u please tell me the step-by-step instructions to help me set this router perfectly?
    regards

    Try updating both of your laptops wireless cards that could fix the problem (you know may not be compatible with your WRT160N).
    I know you said you changed the channel your router broadcasting in but do you have a lot of other wireless networks in your area???
    GoodLuck
    Matt

  • Help needed to setup template item list to send attachement within email te

    Hi! I read everything there was in the bookshelf on the setting of template on Outbound communication, advanced template and my main concern, template items list and I still can not send a template email with an attachment inside. I managed to send the email with the attachment in the message body but not send mail with an attachment separately.
    Is there a special feature or setting to the template items list or in the Siebel file system that needs to be done ? I've try to put a tag pointing to the template item in the advanced template but got no result. I've tried everything but got no result.
    My main goal is to send a template email containing the attachement of an official letter inside. Ideally, I would like the letter as an attachment to be populated by the data of the BC associated (values substitution). This is already working in the advance template. But that's another story. I would be happy if only I can send the email template to include the letter as attachement.
    Thanks in advance for helping me!

    Yes we do. Even if we go with F9 or by the send email from the file menu, the sending of emails is ok. It's just that it wont send attchment as define in the template item list. All settings are ok and are as specified in related bookshelf. By now, i'm looking if there is any activex control missing for outbond email OR if there is any html tags to put inside the advanced template so that the application could properly attach the file to the email. If you have aswer on you side, it would be appreciated.
    Jean.

  • Help needed to setup my Printer to work on home network...Please!!!

    I recently purchased my first Mac, a G5 PowerPC. I have connected it to my home network (3 windows PC's and my G5) by way of a LAN router and everything works fine except getting my printer to function correctly.
    I have an Epson DX4850 which works fine when connected directly to my G5 via USB but I cannot get it to work properly when connected to one of the Windows's PC's, its prefered location.
    I have done the following;
    Opened the Printer Setup Utility and clicked "Add"
    In the Printer Browser I selected "More Printers"
    In the 2 drop down menu's I selected "Windows Printing" and "Network Neighborhood"
    Then selected the name of my home network, then the name of the computer the printer is connected to then the actual printer.
    The problem seems to be that the Printer Model is listed as "Generic". When I try direct it toward my specific printer all I can find are GIMP drivers under Epson. If I select "Other" in order to navigate to my specific printer driver I seem to have trouble locating it.
    Any help would be appreciated
    iMac G5   Mac OS X (10.4.3)  

    I recently purchased my first Mac, a G5 PowerPC. I
    have connected it to my home network (3 windows PC's
    and my G5) by way of a LAN router and everything
    works fine except getting my printer to function
    correctly.
    I suspect that I know why. Several printer vendors, including Epson & HP, have for reasons which make sense to them elected to NOT properly support the CUPS print system which OS X uses and has used since 10.2. Those who support CUPS properly deliver drivers which will work with any connection, including being shared across a network. Those who don't, well...
    In the particular case of Epson, they're trying to push this thing: <http://www.buyepson.co.uk/Catalog/ProductDetails.aspx?PID=C12C824025>.
    Actually, it does make more sense to use a device which puts the printer directly on the network than to share it from a computer. However, it seems... unlikely that anyone with sense will actually buy a 160GBP thingie to attach to a 100GBP MFD... Buying a second MFD would appear to make more sense.
    I have an Epson DX4850 which works fine when
    connected directly to my G5 via USB but I cannot get
    it to work properly when connected to one of the
    Windows's PC's, its prefered location.
    I have done the following;
    Opened the Printer Setup Utility and clicked "Add"
    In the Printer Browser I selected "More Printers"
    In the 2 drop down menu's I selected "Windows
    Printing" and "Network Neighborhood"
    Then selected the name of my home network, then the
    name of the computer the printer is connected to then
    the actual printer.
    The problem seems to be that the Printer Model is
    listed as "Generic".
    There should be a specific GIMP driver for it. I think. I'm not sure, as the DX4850 isn't sold in the US, and many/most of the GIMP drivers for Epsons are written in the US. Which means that there may not be a driver specifically for that device, because the guys who'd write the driver for it haven't been able to get their hands on a machine to work with. If you can find out which print engine is at the heart of the MFD (the Stylus C86 or C88 engine is a possibility, but I don't know, I've never actually touched a DX4850) you can use the driver for that printer and it'll work just fine. At least, my old CX5400 used to work using the C84 GIMP driver.
    When I try direct it toward my
    specific printer all I can find are GIMP drivers
    under Epson.
    This is because Epson's own drivers don't do sharing. This is a Feature, according to Epson. That way it doesn't interfere with their external, expensive, USB-to-ethernet print thingie. The GIMP drivers do do sharing.
    If I select "Other" in order to
    navigate to my specific printer driver I seem to have
    trouble locating it.
    There isn't one from Epson. (Unless you have 160 pounds you're not doing anything with...) There may be a GIMP driver which will work.
    Any help would be appreciated
    iMac G5 Mac OS X (10.4.3)

  • Help needed to setup wireless printing

    I have less than a month's experience of using a Mac but am really enjoying my purchase so far.
    The one issue that I have not been able to solve is printing.
    I have a HP Photosmart P1000 which I can successfully print to via USB but I have had no success when trying wirelessly using a Belkin Wireless Print Server (model F1UP0001). My PC was easy to setup using Belkin's setup disk but they omitted to add Macs to their list of operating systems!!
    I've tried following instructions given in a post on here but it didn't work
    Could anyone please offer any suggestions to find a fix?
    Thank you.
    PowerBook G4   Mac OS X (10.4.5)  

    The driver provided by HP doesn't work for network printing, because it bypasses the CUPS system. The only comm protocol you get is what was written into the driver - USB. Install the hpijs and ESP ghostscript driver set from:
    http://www.linuxprinting.org/macosx/hpijs/
    Second issue - the windows setup software enters the server queue name during setup, but we don't have that software on OS X. You need to find the queue name in the print server docs, then enter it next to IP address in OS X Printer Setup. Common queue names are L1, lp, lpt1, etc.
    Wait - just remembered I downloaded that manual for someone elses's question. The queue name is lp1 (el-p-one). So in Printer Setup select IP printer > LPD, and enter IP address and that queue name.
    Good luck.

  • Help needed to setup AX as a router for Wild Blue Internet

    Hello,
    I have new satellite internet service with Wild Blue and for three weeks now I have been trying to figure out how to set up a router, so my husband and kids can get online on their laptops. The modem is currently attached to the oldest desktop we have (the one listed below). They told me I could use any router, but that doesn't work, because the two routers I got I had to bring back to the store because I could not read the windows based setup "wizard." Tonight, once again, I plugged in the AX and connected the ethernet cable of my modem to the ethernet port of the AX. When I try to run airport utilities, it's not showing me anything, however. It's not picking up anything at all. This desktop does not have an airport card, but that should not be the problem according to the documentation I read. All the laptops naturally have airport cards. I am at my wits end, and confused too, since my modem only has one ethernet port and I cannot connect my desktop and connect the airport express at the same time. Is that the problem ? Any help would be appreciated. Wild Blue specifically states to not offer help with routers, I read somewhere on their site. If I had known that I would not have signed a two year commitment

    Hello PClaus. Welcome to the Apple Discussions!
    In order to administer your new AirPort Express Base Station (AXn), the computer has to have the AirPort Utility installed. This will either be available with OS X Leopard or on the installation CD that came with the AXn. If your desktop Mac is not wireless, then the only way to access the AXn would be to connect the AXn directly to the Mac with Ethernet or connect both the AXn and your Mac to an Ethernet switch. Since you state that your laptops are wireless, I suggest using one of them to do the administration. Let me know if you were successful.

  • Phantom item issue, help needed with setup

    Hello,
    we are currently facing an issue that we have two goods which are exactly the same, apart from one component. These are marked as item number X and Y
    We want to integrate this into our system with one item numer Z with the option for the puchaser to choose which of the Z item they like.
    For example, this is the setup we are looking for;
    Customer has two item numbers X and Y. This is inserted as a purchase request, we then want the SAP System to assign this as item Z (component Y) or Z (component X).
    We want to have this setup so we have to maintain one item record while still keeping two items which are slightly different in the component setup. We are trying to avoid keeping two item numbers in stock
    Is there a way to have this setup?
    Thanks in advance!

    It sounds like you need to remove the attachment from the Publishing field to allow the OOTB approval to flow for the item's attachments. Have you contacted the migration tool vendor regarding this bug in their tool?
    Dimitri Ayrapetov (MCSE: SharePoint)

  • Urgent help needed to setup Forms 6i Server on Windows Server 2003

    Hello,
    I am trying to install Forms 6i Server from the Forms/Reports 6i Release 2 CD onto a server with Windows Server 2003 Standard Editon (services pack 1) installed.
    The Oracle Installer produced the following error when I tried to install the Forms 6i Server From the Forms/Reports 6i Release 2 CD:
    user1.pin(20); os_error while spawning ifsrv60 -install forms60server port=9000 mode=socket batch=yes.
    Has anyone successfully installed Forms 6i Server from Forms/Reports 6i Release 2 CD onto a Windows Server 2003 server?
    Any help is appreciated.
    Phil

    You it obtained to install the FORMS 6i SERVER in Windows 2003 ?
    I am with the same problem and not yet I obtained solution.

  • Help needed to setup to Network Print Server

    Hi,
    I am trying to configure the following to print from my Mac:
    D-Link DP-301U USB print server
    HP Color LaserJet 3500
    MacBook Core Duo OS X 10.4.8
    Very little information is available on both D-Link and HP website.
    The D-Link installation guide says to install via AppleTalk.
    AppleTalk has been activated on my AirPort as well as on the Web configuration of Print Server. However I cannot see any printer on adding a printer.
    In the Add Printer Browser, I can see my print server on Bonjour. When selected, I am supposed to choose my HP printer, but it is no on the HP printer list.
    Only Generic PostScript can be selected, however when printing, it prints our garbage.

    A long time ago, I worked on a print spooler and was lent a JetDirect
    box from HP to test with. A JetDirect card is in your LaserJet, I believe.
    (One of the protocols it supported was localtalk, BTW). I think the
    d-link isn't forwarding your localtalk packets. Anyway, one of the
    things I remember is that the JetDirect spoke PCL, so that's another
    consideration a driver has to deal with. The garbage you're seeing
    is raw postscript. It needs to be rasterized and translated to PCL.
    Please bear with me, my experience is very old, and there are gaps
    in my knowledge. But I think this is do-able. I think the first step is
    to add the printer directly by clicking here,
    The location of the printer should be the address of the print server
    (or canonical name if you're ever going to change addresses). The
    device should be appsocket/jetdirect. The device uri should be
    socket://nameoripaddressofdevice. The make should be HP and
    the model/driver should be one of the Laserjet series, gimp-print.
    I don't know which one, my experience ended around Laserjet 5, and
    so do the drivers! But fundamentally they have to do the same thing.
    They use the gimp-print package to rasterize the postscript and
    encapsulate it into PCL. So I would bet the LaserJet 6 driver will work.
    I'm sure everything posted here is correct, and that my experience
    is too old and I don't know enough to know why this won't work,
    but it's not a lot of effort, and if I were you I'd give it a try.
    -Phil
    Powerbook G4, iMac (Intel), and tons of hardware sitting in the closet   Mac OS X (10.4.8)  

  • Help needed with setup

    Used migration assistant to transfer files BUT dont  want the two accounts on the computer.  Tried reinstalling  Lion with no joy the second acccount survived
    ty
    g

    Used migration assistant to transfer files BUT dont  want the two accounts on the computer.  Tried reinstalling  Lion with no joy the second acccount survived
    ty
    g

  • Hi I need to setup my email account  on my ipad2 coz I deleted, accidentalli it ask me for a server os something like that can u help me please

    Hi I need to setup my email account  on my ipad2 coz I deleted, accidentalli it ask me for a server os something like that can u help me please

    I'm from Kuwait and there is no technical support for our hope I find a solution to have

  • Help needed in PS module on CJ9ECP/CJ20N for revaluating CCR??

    help needed in PS module on CJ9ECP/CJ20N for revaluating CCR??
    How to handle method on_costing_component_to_outtab which belongs to badi gui_itemization_ck. This is to revaluate CCR in CJ20N.
    From sale transaction(va01/va02) i need to call cj20n/cj9ecp for revaluating cost estimates. Can anyone say how to proceed with this thing.
    Can any one say how to handle pop up window in CJ20N/CJ9ECP when clicked edit ecp button. Later how to revaluate cost estimates. For this should i need to go for call transaction or is there any method available. If so how to handle method for revaluating cost estimates for ECP of WBS elements

    Thanks Amol for the advice.
    My friend doesn't belong to an engineering background and had not worked in a manufacturing environment.
    He holds an MBA degree specialised in systems and has worked in software companies supporting software projects and the functions(like HR,Procurement in the same setup) as a software quality guy.
    Moreover the modules mentioned by you requires engineering background with manufacturing exposure.
    He had enquired for the course at siemens and they said that he may not be suitable for any of the modules offered by them as per the above reasons.They also mentioned that they have to check with SAP Labs for expert opinion.
    Please provide your inputs.
    regards,
    Zubair.

  • Help needed for using BASIC authentication through JDBCRealm

    Help needed.
    Hello,
    I am doing a degree project, so far it works fine in my local machine, I need to try it on my virtual hosting (as it is a live server).
    My project requires JDBCRealm, that is BASIC authentication loading access data from mysql database. Normally this setup can be done in Server.xml file, because my Tomcat hosting is a virtual one, I only have permission to access the web.xml file.
    My question is: is it possible to get it done in an alternative way? In web.xml? Some properties file maybe?
    Thank you very much.

    You can set this up for your context using META-INF/context.xml instead of working with server.xml.
    Make a directory called META-INF under your webapp ( it'll be at the same level as WEB-INF ). Under this, add a context.xml with all your context specific configuration including the realm. A sample is below
    <?xml version="1.0" encoding="UTF-8"?>
    <Context path="/myApp" reloadable="true">
        <Realm
            className="org.apache.catalina.realm.JDBCRealm"            
            driverName="com.microsoft.jdbc.sqlserver.SQLServerDriver"         
            connectionURL="jdbc:microsoft:sqlserver://127.0.0.1:1433;DatabaseName=myDB;SelectMethod=Cursor;"
            connectionName="username" connectionPassword="password"
            digest="MD5" userTable="users" userNameCol="userid" userCredCol="userpassword"
            userRoleTable="user_roles" roleNameCol="rolename"
        />
    </Context>Hope this helps.
    People on the forum help others voluntarily, it's not their job.
    Help them help you.
    Learn how to ask questions first: http://faq.javaranch.com/java/HowToAskQuestionsOnJavaRanch
    ----------------------------------------------------------------

  • Urgent help needed on deployment facts

    Hi
    I had completed a Java Web based application using JApplet, which in turn uses Java Media Framework and Java Communications APIs. So when i deploy this application and let the clients use this application. I need to dump some jar files and properties files into the clients JRE so that all the APIs will work properly. Without any installations. I tried doing this manually by copying these files into client machines So is there a direct method for performing the task. Or i need to add some additional code to my applet so as to find the clients current JRE version and place the required files under using FTP? Can i write a setup routine or something which does all these operations once the client access the applet?
    Help needed in the above issues
    Thanks in advance
    Swaraj

    What you will want to do is look into JNLP and Java WebStart. They allow you to write a setup for your product that makes installation as easy as InstallShield&trade; does for the Windows&trade; platform (ie: it allows customers who cannot tell Java from Perl to install your product).

  • HELP NEEDED PLEASE

    Hi everyone
    Programming help needed here. Any advice would be greatly appreciated!!!
    I have been assigned some work for a program called Processing 1.0 availale at http://processing.org/download
    I was give the 9 individual programs I needed to make however they were converted to Java files from .pde files. The program is based on Java but only runs .pde files and NOTHING else!
    I decompiled the files and got the source code, but it is a slight variation of the original someone made in processing, and needs some tidying to get it to run.
    I think the programs are very simple for a programmer, although I AM NOT.
    CODE is BELOW
    // Decompiled by DJ v3.10.10.93 Copyright 2007 Atanas Neshkov Date: 02/05/2009 13:15:00
    // Home Page: http://members.fortunecity.com/neshkov/dj.html http://www.neshkov.com/dj.html - Check often for new version!
    // Decompiler options: packimports(3)
    // Source File Name: Assign2_1.java
    import processing.core.PApplet;
    public class Assign2_1 extends PApplet
    public Assign2_1()
    SquareSide = 20;
    Rank = Nums.length;
    Side = SquareSide * Rank;
    Green = color(0, 255, 0);
    Yellow = color(255, 255, 0);
    BG = Yellow;
    public void setup()
    size(Side, Side);
    background(BG);
    fill(Green);
    for(int i = 0; i < Rank; i++)
    rect(i * SquareSide, 0.0F, SquareSide, SquareSide * Nums);
    public static void main(String args[])
    PApplet.main(new String[] {
    "--bgcolor=#ece9d8", "Assign2_1"
    int Nums[] = {
    6, 14, 8, 9, 2, 3, 4, 2, 8, 3,
    9, 2, 0, 5
    int SquareSide;
    int Rank;
    int Side;
    int Green;
    int Yellow;
    int BG;
    Edited by: chevy1 on May 2, 2009 7:32 AM

    HELP NEEDED PLEASEShouting is a good way ensure you don't get help. Also you should give a meaningful subject.
    Any advice would be greatly appreciated!!!I suggest you ask a question after providing enough information to be able to answer it.
    Also use CODE tags when posting code as it make the code more readable.
    We are more likely to help people who are trying to learn Java rather than someone who might be looking for an easy way out of doing an assignment.

Maybe you are looking for

  • Eliminate page heading in the spool of ALV report

    Hi, We are running the ALV report in the background, and when we view the spool the page heading and the column heading is displayed for all the pages, Is there some way to eliminate this. The download from the on-line exec is fine,but the download f

  • Get Photos from PSE 7

    If I'm to make the leap to LR (and likely DNG), I'll require it to support the work I've already put into the PSE7 Organizer.  I see that LR 2.4 supports PSE 6 and earlier; I find it odd/concerning that LR 2.4 would not support getting photos from th

  • Error in microsoft office professional plus 2013

    hi this is jeyachandran from national payments corporation of india.in outlook 2013 professional plus we facing some send and receiving error that we cannot receive mails.during send and receive we getting error 0*8004060c.please find attachment imag

  • Why are previews in Adobe RGB (1998) ?

    In experimenting with emailing previews from Aperture I noticed they were washed out when displayed on the Windows PC that received them. I dragged a preview to the Mac desktop and choose "get info" to see that the Profile Name is Adobe RGB (1998) If

  • Help reload free Apps on iPad air that I deleted on Setup

    I just got a new iPad Air, but stupidly set it up usind a saved old iPad in my Mac (iTunes). I seem to have lost all my free programmes (iMovies, Pages, Keynote, etc). Any ideas how to retrive the free stuff? I've gone back to iTunes, set it up as a