Mac OSX Lion Server Network User Login Issue

We have in the office a server running Mac OSX Lion, and several network users who've all been running happily for quite a will.
About a month ago I was added to the system, and initially we had a few issues relating to the home directory, but we changed 'something' and it all worked.
Fast forward to now, and we've added a new user - Hannah - to our system.
I've added her in the Workgroup Manager, and set her up everywhere I can find on the server. Her home directory creates on the server fine.
She appears in the Logon list on the client machines, and here's where the trouble starts...
Every time she tries to log on, it fails. The logon box just bounces or wobbles as though the password is incorrect. We've tried changing the password, to no avail. We've tried adding new test users - same problem.
We've tried sudo kinet on the Terminal as a local user, with variable results.
I'm at my wits end, and really hoping someone here can help offer some suggestions or advice we can work through to get to the bottom of this.
Thanks in advance!

Your problems are likely occurring because you added her to the directory with Workgroup Manager.
You should really start avoiding WGM when at all possible as Apple is clearly moving away from it. Because of this, things don't always work as expected when using 'legacy' tools like WGM.
My guess as to what your problem is: When you create a new user in Server.app, two things happen for you automatically that WILL NOT HAPPEN if done from WGM.
First the user is added to the default "Workgroup" group.
More importantly (and the source of much confusion), the user is automatically added to SACLs.
Check the SACL for the user in Server.app, I bet you'll notice that they aren't a member of the File Sharing group like they should be. To solve this problem, you can either delete the user and recreate them in Server.app, or manually add them to the appropriate SACL.
I would opt for recreating them in Server.app if I were you, as I don't trust user accounts that originate in WGM on Lion Server.

Similar Messages

  • N00b needs help setting up MAC OSX Lion Server for email.

    I recently purchased a Mac Mini running OSX Lion Server and I really don't understand how to set it up as an email server (which was my main goal). Eventually I'd like to set it up to host just about everything else, but I can't seem to figure out how to set up my router and MX records to point to my server in order to host imap mail. I do have a static IP by the way but this N00b is confused... Please help!

    Funny you should ask, because I have been spending the day trying todo the same. I just need to know what to enter into my mx record in network solutions. I can send mail, but I can't receive it just yet. Any help would be great.

  • Run HTTP File Server on Mac OSX Lion Server?

    Hello!
    I have a Mac Mini running Mac OS X Lion Server.
    I would like to be able to host a Web Server that runs within the built in Apache server that allows the transfer of files from Client to Mac Mini HD and vice versa using authentication from Open Directory.
    My inspiration is HTTP File Server, or HFS (no, not the Disk Format). This, however, is a Windows Program. It allows a HTTP platform to upload and download files from the HD of the machine it is running from. It comes as a nifty .exe that has everything you need. I'd like something similar but to run on the Mac Server.
    Note, the upload and download cannot be done over FTP. It must be using HTTP like HFS does.
    At the very least, I'd like a HTTP (Port 80) Web Server that runs within Apache that allows upload and download to the HD.
    And at best, authentication using the built in Open Directory credentials. And to make even more secure, HTTPS or SSL.
    So it's like iCloud or iWork.com but using my own disk space and credentials.
    Predicted End Product:
    User visits https://192.168.x.x or https://MyDNSName.dns.com
    Greeted with Home Screen (.html or .php)
    Clicks login
    Has a nice login window to use (probably have to be .php to keep simple)
    Logs in using same credentials as they would to logon to Mac Mini locally
    Greeted with view of their files in their Directory, e.g.: /Library/Server/Web/HFS/User1 or /Library/Server/Web/HFS/User2, etc
    Can choose to download present files
    Or upload. Click Upload
    Upload window appears. Selects file on Client machine.
    Over HTTP, file is uploaded to Host Machine to /Library/Server/Web/HFS/User1
    What I'd like to know is what is the easiest way of going about this? Some kind of CMS like Wordpress or software like HFS?
    Many thanks,
    Clark

    I'm a little confused here... what's the requirement for HTTP based transfers vs. traditional file sharing protocols such as AFP?
    Secondly, how does 'HFS' differ from any other HTTP form-based uploader? Any web CGI or scripting system such as PHP or Perl could easily present an upload form.
    Have you considered WebDAV, which is designed as s file transfer protocol over HTTP?
    It integrates at the Finder level, meaning you can copy files by simply dragging and dropping file (and folder) icons in the desktop, just like on a local drive. It's part of the standard Mac OS X Apache installation, too.

  • How to connect to embedded POSTGRESQL on Mac OSX Lion Server

    Hi all,
    I've upgraded my Mac OSX 10.6 server to 10.7 server 2 days ago.
    My web sites databases are still under MySQL server cause it's still running after the upgrade.
    I manage to migrate the databases to PostgreSQL, so i've enabled the wiki from the server.app to launch the PostgreSQL server.
    I can see that it's now running through a ps -ef | grep sql and that it's listening on the unix domain socket 5432 with netstat -an | grep SQL in a terminal shell.
    The problem is that I'am unable to connect to it.
    I tried psql -U postgres, and installed the Navcat for postgreSQL Lite, but they failed to connec to the database server twith the same error :
    psql: could not connect to server : Permission Denied
    Is the server running locally and accepting connections on Unix domain socket "/var/pgsql_socket/.s.PGSQL.5432"?
    It seems that there is a permission problem on the Unix Domain Socket /var/pgsql_socket/.s.PGSQL.5432.
    It has a 0770 permission on it, but i don't know if it's relly the problem.
    I've compared with MySQL server, which I am able to manage through Navcat for MySQL Lite without any problem, and the socket permission are 0777 on /var/mysql/mysql.sock.
    Does somebody able to connect to the embedded PostgreSQL server ?
    Or am I doing something wrong ?
    Thanks.

    Thanks for your replies.
    I was able to connect but not from navcat
    sudo -u _postgres psql template1 (or your database name)
    I am able to connect using this command too
    1. Need to add yourself or the account accessing the database to Postgres Users group (use admin tools)
    So I agree that I have to add my user to the _postgres user group, but how do you did ?
    Using the admin tools, I did not find this Postgres Users group ?
    I don't understand why server's administrators are not members of this group already ...
    2. Create a role on database login in as _posgres
    Ok, I will do.
    3. To login in navcat you need to check socket to /var/pgsql_socket
    OK, I've already set the socket in Navcat to /var/pgsql_socket
    4. I was unable to enable TCP connection yet
    I am unable to enable it too. I tried to modify the config files in /var/pgsql, without success.
    I have no firewall on my server too, it's protected by my router's firewall and NAT.
    Thanks again for your help.

  • Cannot access in a shared folder on Mac OsX Lion Server

    Hello, i've a strange issue with Mac Os X Server 10.7 :
    i created an shared folder, grant r/w permission to everyone group, but when i try to access to him from Pc with windows7 ask me te credential, however if i logon with a registered Mac OSx account it refuse the connection, obviously when connect to this shared folder from Mac i've no problem, of course...
    Someone can help me?
    Thanks Riccardo.

    Maybe someone in the Lion Server Forum would know the answer?
    Regards,
    Colin R.

  • Mac OS X Server Network users and Microsoft Office Documents

    Hello. I have a lab with 10.8 clients and 10.7 server. I have problems copying documents to network users' desktops. Here's the scoop:
    I'm on my teacher machine. I want to copy word docs (.docx) to the student desktops while they are logged in with ARD. The copy works fine, but when they try to open the documents it is always Read Only. They have to resave the documents as something else in order to use them. Permissions on the documents are read/write for me/staff/everyone on my machine (also a network user account) before I copy them through ARD.
    Am I missing something? This issue was around last year when the clients were 10.6 as well.
    Thanks for any help.

    Hi,
    I am trying to do the same exact thing and find that it is best to do this locally (for now). Not only is the network way slower, but it seems to make things worse. For example, things backed up via the client machine are routed from the FTP server/volume mount and different permission wise. When you try to restore them locally, it should work, but the folder had different permissions because they were initially created in root (for me). So, I hope they would come out with something better than what is available now. Thanks!

  • Wiki Server - AD User Login Issues (8002)

    I'm in the process of getting wiki server functioning in an AD integrated environment. We have login, portable home directories, and many other integrated services working properly, but I'm having trouble with wiki server. When logging in to the server using OD credentials, things function properly. However, when logging in with AD credentials, users are presented with "Invalid Session (8002)" in a web browser popup, and the server notes the following in its error logs:
    2008-07-02 09:29:45-0400 [HTTPChannel,12,127.0.0.1] Unhandled Error
    Traceback (most recent call last):
    File "/usr/share/caldavd/lib/python/twisted/web/http.py", line 598, in requestReceived
    self.process()
    File "/usr/share/caldavd/lib/python/twisted/web/server.py", line 150, in process
    self.render(resrc)
    File "/usr/share/caldavd/lib/python/twisted/web/server.py", line 157, in render
    body = resrc.render(self)
    File "/usr/share/wikid/lib/python/applexmlrpcserver/WebAppServer.py", line 70, in render
    d = defer.maybeDeferred(function, request, *args)
    --- <exception caught here> ---
    File "/usr/share/caldavd/lib/python/twisted/internet/defer.py", line 107, in maybeDeferred
    result = f(*args, **kw)
    File "/usr/share/wikid/lib/python/applexmlrpcserver/WebAppServer.py", line 91, in xmlrpc_login
    session = SessionHandler.sessionHandler.sessionForID(session_id)
    File "/usr/share/wikid/lib/python/apple_utilities/SessionHandler.py", line 155, in sessionForID
    return self.authProvider.avatarForSession(sessionid)
    File "/usr/share/wikid/lib/python/apple_utilities/Authentication.py", line 349, in avatarForSession
    return self.sessionFactory.getSession(sessionId)
    File "/usr/share/wikid/lib/python/apple_utilities/Authentication.py", line 210, in _func
    return f(self, *args, **kwargs)
    File "/usr/share/wikid/lib/python/apple_utilities/Authentication.py", line 269, in getSession
    raise InvalidSessionError(sessionId)
    apple_utilities.Authentication.InvalidSessionError: Invalid Session:
    2008-07-02 09:29:45-0400 [HTTPChannel,12,127.0.0.1] 127.0.0.1 - - [02/Jul/2008:13:29:44 +0000] "POST / HTTP/1.1" 200 1758 "http://cts-fs01/groups/cts/" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 1054; en-us) AppleWebKit/525.18 (KHTML, like Gecko) Version/3.1.2 Safari/525.20.1"
    Any suggestions or ideas? Smells like a bug to me unfortunately...
    Many thanks,
    Josh

    Clear text authentication must first be enabled for both Wiki and iCal in order for certain functionality to work in the OD/AD config. So there are a couple of workarounds that must be applied.
    For Wiki, there is a KBase article that provides instructions and background info on this subject:
    http://docs.info.apple.com/article?artnum=306750
    For iCal, you must edit the caldavd.plist file for the following:
    <key>Authentication</key>
    <dict>
    <key>Basic</key>
    <dict>
    <key>Enabled</key>
    <false/> <----- change to true
    </dict>
    <key>Digest</key>
    <dict>
    <key>Algorithm</key>
    <string>md5</string>
    <key>Enabled</key>
    <true/> <---------- change to false
    <key>Qop</key>
    <string></string>
    </dict>
    <key>Kerberos</key>
    <dict>
    <key>Enabled</key>
    <true/>
    <key>ServicePrincipal</key>
    <string></string>
    </dict>
    </dict>

  • Mountain Lion Server: Network users Home directory mount problems

    I am having several problems with my server after a latest name change of the server via Server.app. (A first name change made problems, after that I have been trying to repair, changing the name a few times more. With latest name change, I also changed the server name itself from Foo to Bar while changing domain name from domain.com to bar.domain.com after which I repaired DNS so it covers the whole domain.com domain).
    The users in the Network directory think their home directory is on afp://domain.com/Users, but the server is now called bar.domain.com. /Network/Servers/bar.domain.com does not exist on the server. Client machines (with mobile home directories) are now able to sync, because I added an A record for domain.com to DNS (not  nice, but does the job, or more specifically that job). Also on the clients, I can go to a SHARED folder in Finder with the name Bar and go to Users and see al the home directories there. But:
    bash-3.2# ls -l /Network/Servers/
    total 4
    dr-xr-xr-x  2 root  wheel  1 Apr 14 11:14 domain.com
    dr-xr-xr-x  2 root  wheel  1 Apr 14 11:14 foo.domain.com
    bash-3.2# ls -l /Network/Servers/*
    /Network/Servers/domain.com:
    total 2
    dr-xr-xr-x  2 root  wheel  1 Apr 14 11:14 Users
    /Network/Servers/foo.domain.com:
    total 2
    dr-xr-xr-x  2 root  wheel  1 Apr 14 11:14 Users
    bash-3.2# ls -l /Network/Servers/*/Users
    /Network/Servers/domain.com/Users:
    ls: Users: Input/output error
    /Network/Servers/foo.domain.com/Users:
    ls: Users: Input/output error
    So, on the server looking for folder ~user does not work. It wants to  go to afp://domain.com/Users/user but that is unreachable.
    Any tips on what I can do except do a clean rebuild of the server (again)?
    (One of the obvious problems is that the Realm of OD is still called foo.domain.com, the origin of my problems has been that the first name change from foo.domain.com to domain.com (ill-advised, I know) failed — partly).
    What I'd like to know is:
    - where is it determined which servers end up in /Network/Servers?

    Som additional info:
    Other machines can mount afp://foo.domain.com/, afp://domain.com/ and afp://bar.domain.com/, but the server itself cannot mount them via Finder.

  • Mac OSX Lion 10.7.3 finder issue

    When I used file>place, the files are greyed out in my finder, until I select "enable all readable files" in the bottom of finder window. In PS5, this does not occur. How to I make enable the default setting in PS6?

    Do you have the latest add-in? It can be found here: http://www.connectusers.com/downloads/

  • I am running Mac OSx Lion 10.7.2. My problem is I can't search on an external network server for a file with the finder toolbar anymore. Nothing shows up and it will not search. I was able to in snow-leopard and am no longer able to w. Lion. Suggestions?

    I am running Mac OSx Lion 10.7.2.
    My issue is that I am not able to run a search in the finder toolabar on a network server. No files show up nor does it search on the server anymore. I was able to run the search in snow-leopard and am no longer able to do so with Lion. Is there a preference I can change or some kind of app or program I can download that will help me with this issue? This is extremely problematic for me as I am searching for files all day everyday. Thank you!

    Hello,
    It isn't the fw in Network you want o use or look at, that's for something completely different.
    My first suspect is the Power Adapter on the LaCie has gone.
    At the Apple Icon at top left>About this Mac, then click on More Info, then click on Hardware>Firewire, what is listed there?
    Reset the Firewire bus
    If your Firewire or USB isn't recognizing any device.  A solution which has worked for some whose hard drive became invisible in 10.4 was simply to follow these four steps to reset the Firewire/USB bus:
    1. Shut the machine down.
    2. UNPLUG the power lead to the computer and any firewire/USB drive or devices.
    3. leave it for 10 minutes.
    4. Connect back up and reboot.
    http://www.macmaps.com/firewirebug2.html

  • ICloud for pages app not working on network users having home folder on Mac Mini Lion server

    Does anyone know how to make iCloud for pages work on network users having home folder on server, having home folder on local Client iCloud for Pages works fine but when home folder is on Server iCloud for Pages app does not work. My Clients are Running Mountain Lion 10.8.2, my Server is a Mac Mini Lion Server.

    Hi Tim,
    No fix yet, my home folders reside on a thunderbolt external hard drive, I also tested having home folders on default server HD and no changes, I called Apple Support a while ago, they replicated the issue, it just does not work on network users, they did not say when will it be fix.
    The version of Pages I am using is from the Apple Store.
    Hector

  • LDAP and NFS mounts/setup OSX Lion iMac with Mac Mini Lion Server

    Hello all,
    I have a local account on my iMac (Lion), and I also have a Mac Mini (Lion Server) and I want to use LDAP and NFS to mount the /Users directory, but am having trouble.
    We have a comination of Linux (Ubuntu), Windows 7 and Macs on this network using LDAP and NFS, except the windows computers.
    We have created users in workgroup management on the server, and we have it working on a few Macs already, but I wasnt there to see that process. 
    Is there a way to keep my local account separate, and still have NFS access to /Users on the server and LDAP for authentification?
    Thanks,
    -Matt

    It would make a great server. Bonus over Apple TV for example is that you have access via both wired ethernet and wireless. Plus if you load tools from XBMC, Firecore and others you have a significant media server. Cost is right too.
    Many people are doing this - google mac mini media server or other for more info.
    Total downside to any windows based system - dealing with constant anti-virus, major security hassels, lack of true media integration and PITA to update, etc.
    You should be aware that Lion Server is not ready for prime time - it stil has significant issues if you are migrating from SNL 10.6.8. If you buy an apple fresh Lion Server mac mini you should have no problems.
    You'll probably be pleased.

  • I am a new mac user and I switch to mac due to the graphics that it brings. I do website in pc and I heard iweb is the best.NOW i heard that iweb will be discontinue. so what is the best application there for website using MAC OSX lion?

    I am a new mac user and I switch to mac due to the graphics that it brings. I do website in pc and I heard iweb is the best.NOW i heard that iweb will be discontinue. so what is the best application there for website using MAC OSX lion?

    It is now confirmed  that iWeb, and iDVD, has been discontinued by Apple. This is evidenced by the fact that new Macs are shipping with iLife 11 installed but without iWeb and iDVD.
    On June 30, 2012 MobileMe will be shutdown. However, iWeb will still continue to work but without the following:
    Features No Longer Available Once MobileMe is Discontinued:
    ◼ Password protection
    ◼ Blog and photo comments
    ◼ Blog search
    ◼ Hit counter
    ◼ MobileMe Gallery
    All of these features can be replaced with 3rd party options.
    I found that if I published my site to a folder on my hard drive and then uploaded with a 3rd party FTP client subscriptions to slideshows and the RSS feed were broken.  If I published directly from iWeb to the FPT server those two features continued to work correctly.
    There's another problem and that's with iWeb's popup slideshows.  Once the MMe servers are no longer online the popup slideshow buttons will not display their images.
    Click to view full size
    However, Roddy McKay and I have figured out a way to modify existing sites with those slideshows and iWeb itself so that those images will display as expected once MobileMe servers are gone.  How to is described in this tutorial: #26 - How to Modify iWeb So Popup Slideshows Will Work After MobileMe is Discontinued.
    It now appears that the iLife suite of applications offered on disc is now a discontinued product and the remaining supported iApps will only be available thru the App Store from now on. However, the iLife 11 boxed version that is still available at the online Apple Store (Store button at the top of the page) and those still on the shelves of retailers will include iWeb and iDVD. Those two apps were listed in small, gray text on the iLife 11 box that I bought.
    Personally, if I didn't already have a copy I would purchase one to have it for reinstallation purposes if ever needed.
    This might be of some interest to you at this time: Life After MobileMe.
    OT

  • Quicktime Plugin Issue in Safari on Mac OSX Lion.

    (Strange) Safari - Quicktime - issue on Mac OSX Lion (All Updates done - 20/11/2011)
    Strange issue with Safari - Quicktime video playing - on Mac OSX Lion (All updates done till 20th Nov 2011 night)
    Problem discovery: Tried to view the Apple iPhone 4S Keynote on Apple Website. Strange that Safari does not display any videos from Apple Website.
    Following works OK:- You Tube worked fine.
    - Google Chrome worked fine. (It shows the quick time player loading and then displays the video absolutely fine.)
    Conclusion: There is some problem with Safari Quicktime Plug-in.
    Strange Discovery:
    - There are two users on the MAC. Logged in with a general user (Non Admin)
    - When tried to view Apple Videos on Safary ... THEY WORKED FINE !!! 
    - The user where they donot work is an ADMIN User ... Strange !!!
    System:
    - Mac-Mini 2010 - 8 GB RAM - with OSX Lion fully software updated until 20th Nov 2011 night.
    - DIVX is installed and is also a paid version - registered with DIVX website.
    - VLC is installed.
    - Perian was installed - after problem discovery - uninstalled it - no use.
    Please help with a solution if anyone has faced and solved this problem. Sub question is : If DIVX / anyother plug-in causes problems with QuickTime plugin on Safari, why does it affect only one user on the system and not other users on that system ?
    Notes:
    1) There is a similar looking thread on MacRumors here but concluded that required to start a seperate one with clear problem statement.
    2) Apple Forums
    (a) One thread on topic that hints that some 3IVX plug-in can cause issues with Safari Quicktime Plugin: here
    (b) Another thread from Apple Forum, that hints that DIVX causes problems to Safari Quicktime Plug in, Link is Here

    Refer to a thread on Apple Discussions Forum itself, Link is HERE; refer to the posting by "Charles Cole",
    Charles Cole
    Re: Does anyone recommend OS X Lion?
    Aug 2, 2011 8:09 PM (in response to Landrix)
    Charles writes about DIVX and QuickTime Plugin conflict in Safari:
    One thing I've discovered that might help anyone having a Quicktime Plug-in issue. If you have DivX as a codec on your system (usually installed to play .avi files) you'll want to uninstall it so that Sarfari 5.1 will default to the Quicktime Plug-In and not the DivX plug-in. Otherwise, you can't see Quicktime movies in Safari.
    Note: this post is about and at the time of OSX Lions launch, i.e. 10.7.0.
    Now we have 10.7.2, still cannot believe Apple has not fixed this bug !!!

  • Migrate from Exchange Server 2011 to Mac OSX Lion Mail Server

    Hi all,
    I'm looking to migrate from Exchange Server 2011 to Mac OSX Lion Mail Server.  I work for a company with roughly 30 employees and they use exchange for mail, contacts and calendars.  We want to take full advantage of OSX Server and to completly get off of exchange.
    What are the best ways to do this?  Are there any tools available to help this process?

    I agree with the points made by Strontium90. If you have any PCs then Apple's mail/contacts/calendar software is a poor choice. Kerio Connect as a mail/contacts/calendar server would not only support Macs but would also do a good job supporting PCs running Outlook.
    If you are going to become a pure Apple site, then you could use just the Apple software and this would be cheaper than using Kerio. For 30 users this might be a suitable solution, however even in a pure Apple environment many people prefer Kerio. For example I find Kerio much more pleasent when dealing with email addresses across multiple domains, email aliases, email group addresses, and so on. Kerio also has built-in email archiving, that is keeping a record of all emails. Kerio also provides a web-browser client for accessing email, calendar and contacts. It is worth noting that as standard Mountain Lion Server no longer includes a webmail feature. While I personally find the Kerio webclient rather ugly it does work.
    There are some annoyances I have with Kerio, firstly they have always charged a 'maintenance' fee for their software. This provided access to software updates, and in the past also provided access to Kerio technical support. Unfortunately they now only let you make two (2) support cases per year for that cost, and you now have to pay extra for any more cases. Also while they added support for EWS (Exchange Web Service) to allow using Outlook 2011 for Mac as a supported email client, they did a poor job of this so that it does not work properly with any other EWS compatible client. This means it will not work in EWS mode with Apple Mail, nor with Outlook for Windows. While there are other ways to connect these other clients, this seems a foolish move and there have been plenty of requests to fix this.
    Apple's Mail client uses EWS to connect to a 'real' MS Exhange server.

Maybe you are looking for

  • I can't get iWeb to STOP working.

    I uploaded a published iWeb site to my existing web server, under a add-on domain. It was accessible through http://mydomain.com/Photos.html I noticed after doing this, though, that going to http://mydomain.com/ automatically loaded the iWeb page by

  • JFrame resizing

    Hi, I have a JFrame, it displays on the right upper corner the icons minimize, maximize and exit. Minimize and Exit icons are working fine. I have the problem with the maximize button. The application I am writing allows to resize the JFrame. Thats f

  • Movement Type 321/322 for Quality Inspection in warehouse

    Hi Experts, I have stock of 950 To in Leanwarehouse in plant. I wanted to move 50 TO material or Quality Inspection to same leanwarehouse 0001 by movement type 321 but it throw error Deficit of SL Stck.in qual.insp 11 TO : 1727 4040 0001 In MMBE I sa

  • Can't seem to eliminate top margin of page

    Page is here: http://www.innerkids.net/tgf-odg2/ The wrapper is an outer table Relevant CSS us: <style type="text/css"> <!-- body { margin-top: 0; .contentcell { font-family: Verdana, Arial, Helvetica, sans-serif; font-size: 12px; text-align: justify

  • To switch PCs, do I need the original install disk or can I just use the upgrade download and s/n?

    I need to download my Acrobat 9 Pro on a new PC, but I cannot find my original product installation disk for Acrobat 8.   I have my serial # and the download link for the Acrobat Pro 9 upgrade.   Do I need to install Acrobat 8 first, and then downloa