Is this the OS X Server Directory Administrator Account?

Hello,
I have enabled root access on my local user but I accidentally deleted the Directory Administrator account in the Server App the was under the Users tab. Now when I try to gain root access to /LDAPv3/127.0.0.1 the username and password to authentic it is not the same as my local computer administrator account. If anyone can explain to me what the account is that I can't root and how to edit it, I would appriciate it thanks.

There seems to be some general confusion around authentication on OS X lately; you're not the only one that's been wondering about this recently.
There are two separate login systems available within OS X.  These are the local authentication database, and distributed authentication database.  These can coexist.  Local authentication is basically LDAP, but just for your local OS X host.  Distributed authentication is full-on network distributed authentication; it's the same authentication database, but shared across multiple computers.  
An OS X client uses local authentication for the root account, and for other accounts created in the local authentication directory.
An OS X client can use distributed authentication when it has been "bound" to a distributed authentication system.  The distributed authentication system that the client is "bound" to might be OS X Server or Linux running Open Directory and LDAP and Kerberos, or it might be Microsoft Windows Server and a distributed authentication configuration comprised of Active Directory and related pieces.
With Open Directory on OS X Server, the diradmin user is the default user that can administer the distributed authentication database, but it's certainly not the only such user that can be created in the database.  Consider when there's a larger deployment of OS X systems.  You might have folks that can administer a local system, but the folks that administer all systems are usually different.    In some other installations, the local admin user is only a backup, and only used should the Open Directory configuration require maintenance or reconfiguration.  You don't want to run around to all your Mac or Windows systems and add a new user or disable a user that leaves the organization, for instance, or that needs to have their password reset.  You want to do that in one spot.  That's what a distributed directory provides.
The OS X Server 10.6 Open Directory Administration manual might provide an introduction to the environment, and the Workgroup Manager tool is still a common way to manage Open Directory on OS X and OS X Server. (While it was once integrated with the server administration tools, Workgroup Manager is now a separate download.)
To reset and recreate the diradmin user here, I'd probably trash Server.app, reset the Server.app environment, and reinstall Server.app and reconfigure the local setup.  This if you've not accumulated a whole lot of configuration details within the local server configuration.  Here are the closest I've seen to official reset instructions.  This will nuke your Server.app configuration.  (I'd also encourage have a full-disk backup or two, but that's generally recommended, general good practice and geerally appropriate management paranoia.)
FWIW, also have a look at your backup strategy, too.  Even the most skilled folks can and do occasionally make a mistake, and disks and computers do fail, and databases do get corrupted, and computers do occasionally get dropped or stolen.  Have a backup.  Or two.

Similar Messages

  • HT1277 How do I make Mail remove junk/deleted messages from the server? The only option tht works for me now is the "Remove from server" button at Account Info Messages on server.

    How do I make Mail remove junk/deleted messages from the server? The only option tht works for me now is the "Remove from server" button at Account Info > Messages on server. What am I doing wrong?

    Mail > Preferences… > Accounts > Advanced > Remove copy from server after retrieving a message

  • Error when i try to open the Oracle content server workflow administrator

    i have installed the Oracle content server 10g r3 , but when i tried to open the workflow administrator tool i got the following error message during "loading cached tables" process, although i have made all the required steps in the installation manual ; the error is
    "Unable to start the application work-flow. failed to initialize . the database table list was empty using a catalog of (null) and schema 'UCMADMIN'. you may need to configure the database schema explicitly using the configuration entry databaseschmemaname "
    does anyone know what might be the problem ?
    Thanks
    Edited by: user11120147 on Jun 22, 2010 2:22 AM

    It seems that I have specified to manually create the required tables and roles during the installation steps, so I manually run the required SQL scripts which include (creating tables, creating roles, creating users , etc..), and after have successfully login to the workflow administration tool .
    Regards

  • Project Server 2013 administrator account unable to access PWA site

    I've just finished installing and configuring all the appropriate pieces to get PS2013 up and running along with a pwa site. The problem I'm running into is that my designated administrative account for the pwa site is unable to login at all. I receive
    the "Sorry this site hasn't been shared with you." error. The domain account has all the appropriate permissions according
    to the PS2013 guide, the services are all up and running, and the pwa site is provisioned. I'm at a loss as to what to change to access the pwa site.

    Using SharePoint Central admin navigate to PWA site provisioning page
    Hover the mouse point over provisioned PWA site and select view.
    Review Primary administrator's field.
    Let me know if this does not help, we can also find out using querying database but only with SELECT query.
    Since this is brand new PWA, you can delete the PWA site make sure to uncheck the check box delete site collection and re-provision PWA site using same name and database but this time you can either use old account or use new account
    Hrishi Deshpande – Senior Consultant DeltaBahn
    Blog | < |
    LinkedIn
    Please click Mark As Answer; if a post solves your problem or Vote As Helpful; if a post has been useful to you.This can be beneficial to other community members reading the thread.

  • HT2954 CAnnot change the incoming mail server for iCloud account

    I cannot recieve mail because the imap setting is wrong, but I cannot highlight it to change.

    Hi, was it maybe setup as a MobileMe or dot Mac account in the first place?
    You cannot use .mac or MobileMe as type of Account, you have to choose IMAP when setting up, otherwise Mail is hard coded to change imap.mail.me.com to mail.me.com & smtp.mail.me.com to smtp.me.com, no matter what you try to enter.
    iCloud Mail setup, do not choose .mac or MobileMe as type, but choose IMAP...
    On second step where it asks "Description", it has to be a unique name, but you can still use your email address.
    IMAP (Incoming Mail Server) information:
              •          Server name: imap.mail.me.com
              •          SSL Required: Yes
              •          Port: 993
              •          Username: [email protected] (use your @me.com address from your iCloud account)
              •          Password: Your iCloud password
    SMTP (outgoing mail server) information:
              •          Server name: smtp.mail.me.com
              •          SSL Required: Yes
              •          Port: 587
              •          SMTP Authentication Required: Yes
              •          Username: [email protected] (use your @me.com address from your iCloud account)
              •          Password: Your iCloud password
    Also, you must upgrade your password to meet the new criteria:  8 characters, including upper and lower case and numbers.  If you have an older password that does not meet these criteria, when you try to setup mail on your mac, using all of the IMAP criteria listed above, it will still give a server error message.  Go to   http://appleid.apple.com         then follow directions to change your password, then go back to setting up your mail using the IMAP instructions above.
    Thanks to dpepper...
    https://discussions.apple.com/thread/3867171?tstart=0
    http://x704.net/bbs/viewtopic.php?f=19&t=5807&p=69967#p69967

  • OC4J administrator account not configured

    Hi,
    I'm trying to run a JSF / ADF BC project that make use of a custom loginmodule. The module needs to be configured with the embedded OC4J server from JDeveloper 10.1.3. When I run the project, I'm getting this error:
    Error initializing server: OC4J administrator account is not configured correctly. Please make sure that at least one administration account is created and configured correctly.
    Can anyone tell me where what settings I need to configure and where to solve this problem?
    greetz
    Sofie

    Hi Spicer,
    First of all thanks for your post.
    I read the thread "How to? Using custom login module in JDev 10.1.3 embedded OC4J" from John, I leaved the "role.mapping.dynamic" property out of my general settings in jazn.xml and added a new jazn-data.xml in my project for project specific settings. I reference to it from orion-application.xml like this:
    <jazn provider="XML" location="jazn-data.xml" default-realm="jazn.com">
    <property name="role.mapping.dynamic" value="true" />
    <property name="jaas.username.simple" value ="true" />
    </jazn>
    (jazn-data.xml is located in src/META-INF like orion-application.xml)
    I guess it's better to put your setting in the project itself, this way the settings can also not affect the other applications. I also going to take a look at the blog of John for further solutions.

  • Accidentally deleted "Directory Administrator" user in OSX Server (10.9.1)

    I was under Users in the OS X Server and deleted the "Directory Administrator" account that was put there after configuring "Device Management" under Profile Manager. I made a new administor account that is a local account as well but was it the same as the (DA) account? How do I to make changes to the username and password on the "Directory Administator" account? Thanks for the help.

    perhaps a bit extreme, but you can force the server to restart from a blank slate, by deleting the .ServerSetupDone file.
    sudo rm /var/db/.ServerSetupDone
    Read more here:
    http://krypted.com/tag/serversetupdone/

  • Built-in domain Administrator account not given full access to new Exchange 2013 server

    I migrated from Exchange 2010 to 2013 over the weekend.  I cannot log into the EAC with my domain administrator account I use to log into all my other servers.  I also cannot run the clean-mailboxdatabase cmdlet logged in as this user.  I
    had no trouble moving mailboxes from the old server to the new server with this account though.
    This account is a member of: Domain Admins, Enterprise Admins, Exchange Full Admin, Exchange Organization Admin, Organization Management, Schema Admins, Server Management.
    I can log into the EAC with another admin account that has the same memberships as the Administrator account.
    I tried giving the account the role of "Databases" as suggested by others to fix the clean-mailboxdatabase issue but that did not work for me either.
    The Administrator mailbox has been moved to the new database on the Exchange 2013 server.  The Exchange 2010 has been decommissioned and is turned off.

    Hi,
    Based on my research, to retrieves the mailbox statistics for the disconnected mailboxes for all mailbox databases in the organization, we can try the following command:
    Get-MailboxDatabase | Get-MailboxStatistics -Filter 'DisconnectDate -ne $null'
    http://technet.microsoft.com/en-us/library/bb124612(v=exchg.150).aspx
    Additionally, The Identity parameter specifies the disconnected mailbox in the Exchange database and it can be display name instead of mailbox GUID.
    http://technet.microsoft.com/en-us/library/jj863439(v=exchg.150).aspx
    Hope it can help you.
    Thanks,
    Angela Shi
    TechNet Community Support

  • XI Content Server directory

    hi,
       I am doing a EDI scenario using Itemfields Conversion agent(Content master).It is a FILE-XI-R/3 scenario. I have done the necessary configurations in the Conversion agent. I need to deploy this in the "XI Content Server directory"
    Can anyone tell me where do i find the path of the "XI Content Server directory"...?

    Hi mithun,
    Import the ESR content by first copying the export files provided into an import directory on the host of the Enterprise Services Builder and then importing the files into the Enterprise Services Repository. In the following steps, <systemDir> denotes the path for the system directory of the host (generally, <systemDir> corresponds to \usr\sap\<SAPSID>\SYS\global).
    For more info http://help.sap.com/saphelp_nwce711/helpdata/en/48/d113f7b4073254e10000000a42189b/content.htm
    Rgds
    joel

  • How do I specify the gmail outgoing server if I have multiple gmail accounts in my mail? I have 2 business accounts and when I send mail from one account, it is sent from the other account and the sending email is not from the correct account.

    I love my apple email and do not want to use google mail on safari. However, I have 2 gmail accounts set up on apple mail, but when I send mail from one of my gmail accounts (I choose the specific gmail account in the drop down window), it actually goes out as if it is from the other gmail account. I can't have that happen because one is my job, the other is a personal business account and unfortunately, the mail from both gmail accounts want to send through the personal business account. How do I make it send from a specific gmail account? I even tried deleting the accounts and setting them up again hoping I set it up wrong in the first place, but to no avail, it is still doing the same thing except this time I set the job account up first and then the personal business account and now everything goes from the job account! The only good thing is that the incoming messages work properly and they go into the correct inbox. Somebody please fix my outbox!

    In Mail Preferences/Accounts/each GMail account, set up the SMTP Outgoing Server for each account separately, going into SMTP name/edit/Advanced and specify the Username of each account.  The Outgoing servers must be two different servers, authenticated by the Username and Password of each.
    Otherwise, the GMail SMTP server will change the from address to that of the account where the SMTP server was setup.
    Ernie

  • How do I remove the "MATRIXx License Server" from my WinXP control panel?

    I am running Windows XP and have a "MATRIXx License Server" applet that appears in my control panel. I have been unable to remove it. In the "About" window of the applet, the following information is given:
    Flexlm Version 6.0 Copyright 1996-1998
    Copyright 1996-1998
    Globetrotter Software
    San Jose, California USA
    I looked briefly at the Macrovision web site (pointed to by the globetrotter link above), but there is nothing obvious about this.

    The MATRIXx License Server is part of the MATRIXx License Manager installation and is the utility that you use to manage the MATRIXx licenses, especially if you are using floating licenses. As of MATRIXx 7.1 the LM Tools utility is used instead, and it can be accessed from the MATRIXx category on the Start Menu. I would not recommend removing the MATRIXx License Server from the Control Panel, but here is a KB from the Microsoft website that gives instructions:
    http://support.microsoft.com/default.aspx?scid=kb;en-us;261241&sd=tech
    It mentions Windows 2000, but the steps are very similar for Windows XP. Once removed you will not be able to configure the license manager until you unhide it again.
    Carl L
    National Instruments
    www.ni.com/matrixx

  • Says I need to login with the Administrator account even though I am

    Ok, I'm trying to install the printer driver for my new printer, its an HP Photosmart C3100. When I run the installer it prompts me to enter my password (The details tab says that it is specifically requesting system.privilege.admin), but when I do it says the following:
    "The software to be installed requires Administrator or higher level access privileges."
    The thing is that the account that I login as and the password I use are for the Administrator account.
    I've tried everything I can think of to solve this. I've made new administrator accounts and it won't accept them, I've run disk utilities and another application to repair my computer's permissions, nothing seems to work.
    Anyone have any idea how to solve this short of fully reinstalling OS X.

    Open the netinfo manager (/Applications/Utilities/Netinfo Manager)
    click on groups in the window that pops up and then admin.
    Make sure that your admin account is a value under the users property.
    If not, you may not be able to change it if you are having authentication problems...
    in that case you might want to quit the application and open the terminal and type (without the quotes) "sudo open -a /Applications/Utilities/NetInfo\ Manager.app/"
    That should prompt you for the admin password, hopefully it will work from the terminal. If not you might have to start from the install cd and reset the password from there.

  • TS3899 the connection to server has failed

    I have tried deleted the email accounts registered to both my phone and ipad and reinstalling them. I've also switched off both devices by the hard reset. I've deleted all of my mail and I am still getting this 'the connection to server has failed' when i go into the mail app, and when i try to send an email it doesnt allow me either. I am not a techie - what else can i do?

    Hello Madi_kay2030,
    I recommend this article to help troubleshoot what might be happening.
    iOS: Unable to send or receive email
    http://support.apple.com/kb/ts3899
    The symptoms described a a bit different than what you describe but the troubleshooting is relevant.
    Restart the iOS device.
    Tap Safari and attempt to load a webpage to ensure that the device has Internet access. If you're unable to load a webpage, try the Wi-Fi assistant.
    Try an alternative Internet connection.
    If your email is provided by your Internet provider, try connecting from the home network.
    If your iOS device has an active cellular data plan, try to disable Wi-Fi:  Tap Settings > Wi-Fi and turn off Wi-Fi.
    If not, try a different Wi-Fi network.
    Log in to your email provider's website to ensure that the account is active and the password is correct.
    Delete the account from Settings > Mail, Contacts, Calendars and then add the email account again on the iOS device.
    If you're still unable to send or receive email, contact your email provider and verify the account settings are correct. You will need to gather this information (PDF).
    Additional Information
    Using more than one device to check the same POP email account may create a lock-out issue that is easily resolved.
    Regards,
    Sterling

  • Directory Adminitrator account disabled....HELP!

    Hi,
    I was disabling old user accounts in WGM this and in a moment of sheer stupidness i've managed to disable the directory administrator account and now i can't authenticate to OD. I've tried resetting the password using terminal but this hasn't helped.
    Can anyone help please?

    Open WGM and cancel the connection dialog. Press 'CMD k' on the keyboard. Enter the IP or FQDN of the OD server, use 'System Administrator' or 'root' as the username, enter the password. Click 'Connect'. Change the account settings for the Directory Administrator.

  • Administration Account and Domains

    Hello gents,
    i'm in a situation where we need to install BPC 7 in a production environment which is not in the same domain where the users are. The servers are in a LAN with its own domain (i.e. DomainProd) and I can ask both domain accounts and, of couse, machine accounts to get access to them. The users are in a separate domain (i.e. domainUsers).
    I read somewhere in this forum  that it is better that the accounts I need to use during the installation process be domain accounts. I believe that, in a situatione like this one, this doesn't apply. What are the drawbacks of using local machine accounts?
    cheers
    elio

    I agree with both Raman and Sebastien.
    If BPC is installed using local account then it will not be able to authenticate to the domains, making it impossible to use domain users. So using domain accounts for the installation is required in this case.
    I would add that the BPC sysadmin domain account (used for installation) should be added explicitely to the local administrator group on the web/app server.
    That account needs to be able to browse the user domain, which sould have a trust relationship to the server domain.
    after that it should just be a matter of defining the proper group in server manager
    Bruno

Maybe you are looking for

  • MBP Bootcamp install of USB Windows 7 , Thunderbolt Display

    We need support from APPLE! BootCamp Here are my issues. Like many users, I must abandon the marvelous os x, and head to the darkside -  Windows 7 for work. I have a MBP early 2011. I must use Bootcamp, because of the resource hogging the 3d CAD prog

  • Move file with ftp adapter

    Hello everyone, Should I move some files when they appear in a specific directory. In particular, I have a SQL query that extracts the absolute file path list. Then I move these files to another server. How you can configure the process to periodical

  • Thank you for the SOLUTION!

    Somewhere, out there,there is a GOD. I saw it on one of the posts that the "workaround" for all of this error 1402 stuff was to download a Quicktime Alternative ("Media Player Classic"). This WORKED! when nothing else would...I am happily downloading

  • Using TRUNC in timestamps

    Sir, As you know we were using TRUNC function in DATE datatype. But I want to use it with TIMESTAMP datatypes. For example: select trunc(systimestamp,'hh24:mi:ss') from dual; The main idea to get some part of given timestamp without using type conver

  • Changing date time group

    I've been searching for a few days, but can't find an answer to this.....Can the default MM/DD/YYYY group be changed? I've be trying to change to DD/MM/YY or something similar with no luck.