Multiple simutaneously logged in users accessing AFP home directories?

Hi,
Many of our problems are described in this guy's blog:
http://alblue.blogspot.com/2006/08/rantmac-migrating-from-afp-to-nfs.html
The basic capability we want is to have multiple simultaneously logged in users to have access to their AFP mounted home directory, which is configured in a sane, out-of-the box setup using WGM and Server Admin.
Multiple user access could take the form of FUS (fast user switching), or simply allowing a user to SSH into a machine that another user is already logged into and expect to be able to manipulate the contents of her home directory.
From my extensive searches, I have no reason to believe this is currently possible with 10.4 Server and AFP.
(here's the official word from apple: http://docs.info.apple.com/article.html?artnum=25581)
I've read that using NFS home directories will work, though.
I want to believe that Apple has a solution for this by now (it's been almost a year since we first had difficulty), or at least a sanctioned workaround. If Apple doesn't have one, maybe someone else has come up with something clever. I find it hard to believe that more people haven't wanted this capability! (not being able to easily search the discussion boards doesn't help, though...)
Thanks for your help!
Adam

Parallels Issue. Track at http://forum.parallels.com/showthread.php?p=135585

Similar Messages

  • Key-based SSH Authentication and AFP Home Directories

    I'm setting up some users with AFP home directories (hosted on an Xserve, with a couple of G5 towers as Open Directory clients). When logging in on the console on a G5 tower, the home directories work fine. The users can SSH into the Xserve using SSH key authentication. However, the users can not SSH into the G5 towers using SSH key authentication, and are instead asked for passwords - presumably because the AFP home directory is mounted with guest access (and thus the keys are unreadable) before the password is entered.
    Is there a known workaround for this? A different way of setting up the home directory mounting? I don't particularly want to go the mobile home directory route, because (among other things), as far as I know, mobile home directories only sync when a user logs into the GUI. If that's not the case (that is, if they will sync when a user logs into the machine with SSH), then I guess that would be a reasonable solution.
    Thanks in advance for any suggestions!

    That was just speculation on my part; I'm not sure exactly what's happening. I do know that until the user authenticates, the entire automount is mounted with guest access... and that the user can't authenticate until the key file can be read. It may be the case that I was just encountering some transient failure or the like, however.

  • Users on network home directories hang after sleep

    Hi,
    I have the following problem: I have a 10.5 server with network home directories. I can login from Snow Leopard (10.6.1) however whenever the machine goes to sleep and comes back from sleep, the user hangs then if you wait a bit then it will come with the message that the share has been disconnected and it asks you to manually unmount. It will stay there forever. When you click disconnect, the system will unmount and remount the home directory but in the mean time, Mail will have reported disk i/o errors in the logs and throw errors (ranging from type in your password to 'rebuild index').
    Going through the log files (and verbosity high) it seems that when going to sleep, the system doesn't unmount the network home directory. After it wakes up from sleep it attempts to unmount the home directory share which off course fails because it's in use and then it locks up, after you click disconnect, it says "spins reported" in the logs and goes on with remounting the shares.
    The issue doesn't happen if the user is local. If anybody has an idea as to how this works or if they have it working, please let me know. I have tried just about anything. AFP shares, NFS shares, I have tried with or without the intr, nolocks, locallocks mount options - they all have the same issue. I have even tried another Mac Mini with a fresh install of Snow Leopard.

    I found a possible cause and solution.
    This has been on 10.6.1 with Mac Mini's. Then we got a new Mac Pro with 10.6 out of the (Apple) factory which I updated to 10.6.1, same issue. What I didn't think about is that by default I install a heap of software (including XCode, Adobe CS4 and Office 2008) with customized packages and workgroup manager preferences.
    So I was mucking around with Cocktail (the tool to clean up caches etc.) and I noticed Snow Leopard hung every time after cleaning & recreating some caches. Now that I had a reliable way to hang Snow Leopard I investigated what could cause it.
    I noticed during a PackageMaker session that Adobe CS4 installs a Version Cue startup script in /etc/machinit_peruser.d. I deleted it, rebooted, used Cocktail again and it went all the way through without hanging. Rebooted again, according to the logs it pre-linked & cached the kernel and several kernel extensions and that was it, no more hangs, no more issues logging in after sleep or screensaver.
    So possible causes:
    - VersionCue installs itself as a kernel module or something (the location says "mach" which is the kernel after all) which is not compatible with Snow Leopard.
    - The caches and kernel extensions were 'dirty' out of the box but VersionCue (or something else that interacts with it) blocked my or Snow Leopard's automated attempts to clean them.
    - VersionCue reinitializes (it sits on the network after all) after a sleep or screen saver timeout in a way that gives issues with Snow Leopard

  • Update from 10.5.6 to 10.5.8 and lost all users and their home directories

    My server has been working flawlessly for many months. I did the upgrade to 10.5.6 and everything has been fine. I decided to do the software update to 10.5.8. When it was finished I could not log in as admin or anyone else. I finally got in as root...then it gave me an error in Workgroup Manager. Said I was not logged in and there was an error of -14008.
    All my users are gone and so is their home directories....I hate to say it but this is ridiculous...doing a simple update and losing all the users? I expect this from Windows but not my xSERVER.
    Does anyone have a fix to correct this? I really hate having to tell all the users tomorrow morning a simple update wiped all their data.
    Carl

    Hi
    I saw your issue and I feel your pain. I did the same upgrade path to 10.6 and found that I had no users!. This is not your typical apple upgrade, the same as all other 10-X from day one. I cheated and used a new drive as I feel that upgrades may cause issues and I also used that as an opportunity to upgrade to a larger hard drive. After booting up on the new system with the upgraded drive I found the same issue to be true. I used the original drive, modified all my users to allow my new admin account to have rights to a user that I called 'move' on the old system. I booted up the old system modified all the users to allow user 'move' then I copied them to the new directory I set up that I called 'move' on the old drive, The next step I set up a new user 'move' on the new system drive and copied all the data from the old system drive 'move' to the new system drive 'move' I created all of my users on the new system drive. I set up all of my user accounts with a simple password 123456 on the new system I copied the users to there new directory. You could restore your backup on spare drive or an external drive with the old OS loaded. Postits on all the users monitors for Monday morning and... grumbling users with all of the data from Friday, get KrispyCreams and leave by the coffee pot [this step i forgot]. The users will talk about how nice it was that you brought doughnuts and not how there login is messed up [ha ha....}
    I know that this is not an elegant or a quick solution but it worked for me and my 36 user accounts. If you know Unix script or Python or Apple script the procedures would be faster as you could batch the whole mess.
    Hope this helps and good luck.

  • Why can't files be locked in AFP home directories?

    Hello!
    Our setup: Lion Server on Mac Pro with 30 Lion clients.
    Several applications, notable Eclipse and R Studio, are crashing on start and complaining about not being able to lock files in their working directories. This only happens on network accounts whose home directories are on the server, not local accounts on the clients.
    These apps worked fine under Snow Leopard.
    I have three questions:
    1. I assume this is a more low-level type of locking than the "Locked" checkbox in Get Info: am I right?
    2. Could apps running on clients (logged into network accounts) get locks in Snow Leopard?
    3. If so, what's changed in Lion, and how can I re-enable locking?
    Thanks
    Louise
    Example error from R Studio:
    12 Jun 2012 18:24:23 [rsession-fintannagle] ERROR system error 45 (Operation not supported) [lock-file=/Network/Servers/xgrid.complex.ucl.ac.uk/Volumes/Users/fintannagle/. rstudio-desktop/sdb/s-333EABAB/lock_file]; OCCURRED AT: core::Error core::FileLock::acquire(const core::FilePath&) /Users/rstudio/rstudio/src/cpp/core/FileLock.cpp:117; LOGGED FROM: bool session::source_database::supervisor::<unnamed>::reclaimOrphanedSession(const std::vector<core::FilePath, std::allocator<core::FilePath> >&, core::FilePath*) /Users/rstudio/rstudio/src/cpp/session/SessionSourceDatabaseSupervisor.cpp:249
    12 Jun 2012 18:24:23 [rsession-fintannagle] ERROR system error 45 (Operation not supported) [lock-file=/Network/Servers/xgrid.complex.ucl.ac.uk/Volumes/Users/fintannagle/. rstudio-desktop/sdb/s-505698E8/lock_file]; OCCURRED AT: static bool core::FileLock::isLocked(const core::FilePath&) /Users/rstudio/rstudio/src/cpp/core/FileLock.cpp:61; LOGGED FROM: static bool core::FileLock::isLocked(const core::FilePath&) /Users/rstudio/rstudio/src/cpp/core/FileLock.cpp:63
    12 Jun 2012 18:24:23 [rsession-fintannagle] ERROR system error 45 (Operation not supported) [lock-file=/Network/Servers/xgrid.complex.ucl.ac.uk/Volumes/Users/fintannagle/. rstudio-desktop/sdb/s-505698E8/lock_file]; OCCURRED AT: core::Error core::FileLock::acquire(const core::FilePath&) /Users/rstudio/rstudio/src/cpp/core/FileLock.cpp:117; LOGGED FROM: bool session::source_database::supervisor::<unnamed>::reclaimOrphanedSession(const std::vector<core::FilePath, std::allocator<core::FilePath> >&, core::FilePath*) /Users/rstudio/rstudio/src/cpp/session/SessionSourceDatabaseSupervisor.cpp:249

    User presets and templates will only be placed within the catalog folder after the 'Store presets with catalog' is activated. Existing user presets and templates will remain in their original location. I appreciate that this is a tad confusing, but it's the way Lr works. To get all of your existing presets and templates into the catalog folder it's probably quicker and easier to just copy the entire 'Lightroom Settings' folder from the default location to the Lightroom catalog folder.

  • How do I grant non-logged in user access to application component?

    I want to make the customization page for a report available on
    our portal available to users without them having to log on to
    our portal. I thought I set up the access rights to the
    application component correctly, but the link takes them to the
    login screen instead of the customization page. Can anyone give
    me an idea of what I may have set wrong?

    Hi Greggor,
    You say they are still logged in after a restart?? if you open task manager and look under users are the session aside yours listed?
    Thanks,
    Adam

  • Log the user Access to a Channel

    It's possible to log the access to a channel with the system log facility or a simple file when an user click in the desktop link... the link can be an external URL.
    The log must have the user id and the name of the URL for tracking user action in the desktop.
    It's possible using the Rewriter Rules and Rulesets to perfome this?
    If it's impossible we're the better solution?
    Obsiously it's possible to redirect all the channel link of the desktop in a new servelets o jsp page that provides this functionality and log the access but I think there is not the better solution...
    Thank for the help
    Best Regards
    Fausto

    Hi Fausto,
    Of course there are several cool tricks ;-)
    - Your "JS trick with post " will refresh the page - no good...
    (Also what if you log several channels etc.... )
    - For reporting I actually used "JS hidden image" trick.
    Note: You will loose the browser handle from logging jsp
    - "One Pixel Frame" is good only if you need to have a browser handle.
    For example on click e.g. TabSwitch you can show immediate statistics
    (e.g. how many time user spend with this channel and how much he has to pay!)
    PS: I am actually done with the reporting tool.
    Send me a mail if you wanna see it.
    Cheers,
    Alex :-)

  • Users accessing admin home folder

    I have two drives in my MBP. A solid state boot drive and the internal drive for all other files including the home folders. There are three users and all of their home folders reside on the internal drive, not the boot drive. My problem is that the non-admin users somehow have access to the admin home folder and all its files, while the admin cannot access the others users' home folders. In other words, the permissions are all wrong. However, I have checked the permissions and my (the admin) home folder has the same permissions as the users' home folder. Hopefully that makes sense.
    I have searched for a fix and repairing the home folder permissions through the recovery partition reset password utility seemed like it could be the solution but when I tried that, it did not allow me to access the true home folders on the non-boot drive, it only allowed me to repair the permissions on the boot drive home folders, which is not where the true home folders are located.
    I'm on OSX 10.9.2.
    Thanks for any and all your help. Hopefully my issue is clear and someone out there knows a fix!

    You are correct, it is not supported though a program or user can do it with root access. That is very strange, I would take it to an Apple Authorized Service Provider or get somebody who can actually look at it.

  • AFP Home Directories Working - Except for...

    Hello. I have a test model for a network environment I am preparing to deploy. AFP is working - for the most part - properly and as expected in providing a network home for open directory users.
    However I have three issues I have run into and still can't find the reasoning.
    1) When creating a new home folder in the workgroup manager I get the error below. However it still creates the home and functions - for the most part - properly. This could be connected to any of the below two issues.
    +Error of type Not a known DirStatus (-1) on line 2112 of /SourceCache/WorkgroupManager/WorkgroupManager-319.2.2/Plugins/UserAccounts/Use rAdvancedPluginView.mm+
    2) When viewing the home folder in the finder it doesn't appear that home folder disc quotas are applying correctly. In the guest machine home folder it shows "9 items 26GB Available" at the bottom while the quota is set for 5GB per user.
    3) Write and read (saving files) is working for all applications except for iWeb. About half way through a publish to a folder in iWeb it fails the publish very with a this disk is unwritable error. However it gets many of the files published before it finally fails. Sometimes, but not all times the AFP connection will drop completely and it will come up with an OS "server disconnected" dialogue box.
    Looking at the AFP access log it shows the following hundreds and hundreds of time - probably about 700 or so times repeated. The error log shows no errors. It seems like it is just overloading the server somehow?
    +IP fe80::21c:42ff:fe7d:1638 - - [22/Nov/2008:20:02:52 -0500] "Reconnected User: testuser7" 501 0 0+
    +<Connection> - - [22/Nov/2008:20:02:52 -0500] "Saved for Reconnect User: testuser7" 1227390615 503 0+
    +IP fe80::21c:42ff:fe7d:1638 - - [22/Nov/2008:20:02:52 -0500] "Login testuser7" 0 0 0+
    +** - - [22/Nov/2008:20:02:52 -0500] "<D> testuser7" 89 503 0+
    +IP fe80::21c:42ff:fe7d:1638 - - [22/Nov/2008:20:02:52 -0500] "Reconnected User: testuser7" 503 0 0+
    +<Connection> - - [22/Nov/2008:20:02:53 -0500] "Saved for Reconnect User: testuser7" 1227390615 505 0+
    +IP fe80::21c:42ff:fe7d:1638 - - [22/Nov/2008:20:02:53 -0500] "Login testuser7" 0 0 0+
    +** - - [22/Nov/2008:20:02:53 -0500] "<D> testuser7" 89 505 0+
    +IP fe80::21c:42ff:fe7d:1638 - - [22/Nov/2008:20:02:53 -0500] "Reconnected User: testuser7" 505 0 0+
    +<Connection> - - [22/Nov/2008:20:02:53 -0500] "Saved for Reconnect User: testuser7" 1227390615 507 0+
    +IP fe80::21c:42ff:fe7d:1638 - - [22/Nov/2008:20:02:53 -0500] "Login testuser7" 0 0 0+
    +** - - [22/Nov/2008:20:02:53 -0500] "<D> testuser7" 89 507 0+
    +IP fe80::21c:42ff:fe7d:1638 - - [22/Nov/2008:20:02:53 -0500] "Reconnected User: testuser7" 507 0 0+
    +<Connection> - - [22/Nov/2008:20:02:53 -0500] "Saved for Reconnect User: testuser7" 1227390615 509 0+
    Thanks so incredibly much for any suggestions or ideas.
    ~ Ben

    Parallels Issue. Track at http://forum.parallels.com/showthread.php?p=135585

  • Augmented Users with OSX Home Directories 10.8

    Hi All.
    I currently have an AD/OD setup with 10.6 Server where the users authenticate via Active Directory but the home folder is pulled down from Open Directory. To configure this we setup Augmented users and edited the inspector to map the correct Home Directory and NFSHomeDirectory paths. Thsi all works perfect and has for many years.
    Ive now been tasked with replicating this setup on a new 10.8.2 Mac Mini Server and am having issues getting the home directory to map.
    This is what i have done so far.
    Configure DNS on AD including pointer records. Setup host name on the Mac Server to follow AD structure i.e. macserver.ad1.internal
    Bound Mac Server to AD (default user shell is the only box ticked on the user experience settings).
    Created open directory master.
    Installed workgroup manager 10.8 and impoted Augmented user from AD.
    Switched to Preferences view in WGM and imported Managed Client pref from Macintosh HD:System:Library:CoreServices:ManagedClient. Setup Syncronised URL path.
    Back to Accounts in WGM and configured the mobility settings to auto mount home directory etc etc
    Created a homes folder and ticked 'make available for homes"
    Opened Directory Editor which is now a tab in Directory Utility. Selected Augments from the drop down list then selected my AD (Augmented User). Set the correct path for NFSHomeDirectory and also clicked + and added a string for HomeDIrectory.
    When i then bind a client machine it allows me to log in with the AD user credentials but displays a blank desktop with a bouncing finder Icon. Basically it is not referencing the Home Path i have configured.
    Heres an example of the paths i am using. Although i think there is something more fundimental missing from me configuration rather than the incorrcect path.
    Synconistation URL          - afp://macserver.ad1.internal/Homes/%@
    HomeDirectory                    - <home_dir><url>afp://macserver.ad1.internal/Homes/</url><path>michaelt</path><h ome_dir>
    NFSHomeDirectory          - /Network/Servers/macserver.ad1.internal/Homes/michaelt
    Any ideas of what i have missed? Or if this is possible on 10.8 as i havent read any success stories on this so far.
    Many thanks and a Merry Xmas everyone
    Michael

    I've just upgraded my Mac operating system from OSX 10.6.8 to Mountain Lion 10.8.2 and think i've hit a bug in CS5 Bridge.
    It is indeed a bug and already active in OSX 10.7
    Good news is, this bug is fixed, the bad news, the fix only was added in Bridge CS6...

  • Users and Remote Home Directories

    I have a lab of brand new 24" iMacs running 10.5.4 set up to authenticate to our 10.5.4 Server which is running Open Directory. When I log in as myself, the iMac logs in fine, I get my Home Directory from the server. Everything is happy. If I log in as a Student, the computer hangs on the login screen. I either have to use ARD to Restart the computer or I have to pull the plug. Here's where it gets weird. If I log in as myself, then log off and log in as a student, it works. The student gets their Home Directory from the Server and everything is happy again. It only seems to hang if the Student is the first one to log into the computer.
    The only difference I've been able to find is that my Home Directory lives under /Users on the server, where a Student's home directory would be under the folder for their class. For example a Senior would have a Home Directory in /Users/2009. Each class folder is set to share out with the same permissions as Users, and they all show up in Workgroup Manager as being options on the Home tab. Is there something I need to know about enabling Automount on multiple shares? Or can anyone else out there think of something else to explain this behavior.
    Thanks in advance.

    As far as I know, its buggy software. If your school has an Apple tech support contract, you might try calling or emailing Apple to ask about this problem.

  • How to set NTFS and share permissions for Users share for home directories in Server 2012

    I have a new Server 2012 server, and I want to set up a Users share, that will contain subfolders of each user's username and contain their home directory.  But what do I set the share and NTFS permissions as on the root level, lets call the folder
    Users? Is the following older article the correct permissions I need?
    https://support.microsoft.com/kb/274443

    Hi RJO22,
    You can choose configure the Folder Redirection, Folder Redirection enables you to redirect the location of specific folders within user profiles to a new location, such as
    a shared network location. Folder redirection is used in the process of administering user profiles and roaming user profiles. You can configure Folder Redirection using the Group Policy Management Console to redirect specific user profile folders, as well
    as edit Folder Redirection policy settings.
    The related KB:
    Folder Redirection Overview
    http://technet.microsoft.com/en-us/library/cc732275.aspx
    Specify the Location of Folders in a User Profile
    http://technet.microsoft.com/en-us/library/cc771969.aspx
    I’m glad to be of help to you!
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • You are unable to log in...; Network Home directories; 10.4 & 10.5 Servers

    I have a solution!
    Note: this is a new post because all previous posts dealing with this topic have been archived, MANY without an answer.
    Problem:
    Users with Network Home directories can't log in. After entering their correct username and password, the following error message appears:
    "You are unable to login to the user account 'username' at this time. Logging in to the account failed because an error occurred."
    Problem occurs with v10.5 Leopard client attempting to login to a Network Home directory hosted on a v10.4 Tiger server.
    _Significant Troubleshooting Symptom:_
    Client mac Console log (all Messages) contains the following entry at the time the user attempted to login to their Network Home directory:
    authorizationhost[509] ERROR | -[HomeDirMounter
    mountNetworkHomeWithURL:attributes:dir:Path:username:] |
    PremountHomeDirectoryWith Authentication( url=afp://server.example.com/Homes, homedir=
    /Network/Servers/server.example.com/Volumes/ServerHardDisk/Homes/username,
    name=username )
    returned 2
    _Computing/Network Environment:_
    v10.5 Leopard server doing: DNS; Open Directory with Kerberos for Single Sign-On; AFP for half of all users' Network Home directories.
    v10.4 Tiger server doing: AFP for the other half of the Network Home directories. Also, note that Open Directory is not running on this server, BUT IT IS CONFIGURED (using Server Admin) as "Connected to a Directory System" and has joined the Kerberos realm on the v10.5 Leopard server.
    v10.5 Leopard clients.
    Solution:
    v10.5 User Management manual
    http://manuals.info.apple.com/enUS/User_Managementv10.5.pdf
    says share points for Network Home directories have to have Guest Access ENABLED. See step 5 on page 117 and step 12 on page 118. Note that these are two different settings, but seem consistent with each other.
    I had followed/complied/set Guest Access according to steps 5 (page 117) and 12 (page 118) on BOTH the v10.5 Leopard AND the v10.4 Tiger servers. The solution that allows users to log on normally is:
    Uncheck/disable Guest Access (as set in step 12 page 118) for the v10.4 Leopard server only. Leave "Share this item using AFP" checked. Uncheck "Allow AFP guest access."
    The above worked for me. Your milage may vary. If anyone knows how to report this to Apple for fixing in the server software and/or clarification in User Management manual, please do. If anyone knows that this solution "breaks" other stuff, please post back.

    Other posts that dealt with this same issue and other potential solutions:
    http://discussions.apple.com/thread.jspa?messageID=5700241&#5700241
    http://discussions.apple.com/thread.jspa?messageID=5784186&#5784186
    http://discussions.apple.com/thread.jspa?threadID=1215039&start=0&tstart=0
    http://discussions.apple.com/thread.jspa?messageID=9204496&#9204496
    http://discussions.apple.com/thread.jspa?threadID=1522353&start=0&tstart=0
    http://discussions.apple.com/thread.jspa?messageID=10226660&#10226660

  • Removing default folders in users home directories

    My users have their home directories at /Users/<username>. I also created some directories there for users' websites and other things.
    All users have only access by ftp (mail, webmail, web service, etc.), but it is never intended to use AFP or other things.
    So my question is... can I safely delete the pre-set directories like Desktop, Documents, Library, Public, etc. ?
    I was told that this is possible, but now have doubts as I closer looked at, for example, the Library folder. There are some .plist files and other stuff.
    Before deleting them I want to get the statements of some experts

    You can safely delete all of that stuff, and if they ever log in to the GUI again, Library, Desktop, and the necessary Library items will be recreated. Library and Desktop are the only ones the OS really cares about, and only then when a user is logged in to the GUI.

  • Network Users with network homes not really working for me

    I have with great pain setup a OS X Lion server on a Mac Mini that was supposed to be my central server to have 4 network users accounts and all the users data is stored on an external disk array with mounted network homes to the 2 iMacs and 2 Macbooks I have in my home.
    I have gotten it all working and all my Macs are joined to the Open Directory and each User can login as a network users on any of the Macs and get their files via mounted home directory from the server. The home directories on the server are backed up with Time Machine.
    I have found the following items that do not work proberly:
    1) Desktop backgrounds settings are just lost sometimes for whatever reason. Desktop background goes to default and you need to manually set back to the one you have selected. This happen mostly if users have their own desktop pictures.
    2) Keychain get's screwed up. The user often get the "Keychain doesn't exist to store ..." message and need to select to reset the keychain. Anything I have tried from "Keychain First Aid" to removing and have a new one created doesn't fix the problem. It keeps on coming back.
    3) iTunes Storage and AppStore are getting confused about authorized computers. This is because a user logs in from another computer and then iTunes store would tell the user this computer hasn't been authorized to play the purchase music. Same happens with iPhone apps from the AppStore. Apparently those two stores are not setup to hanlde network users proberly.
    4) Permission issues happen sometimes in Application like iPhoto where it would complain not being able to see photos or cannot add new photos to the library. Need to run a permission repair on the Iphoto Library to fix this.
    5) One critical one is that it's not really possible to restore files from Time Machine. The Time Machine backup is done on the server by an administrator account directly backing up the user directories. When you go into Time Machine on the server even the admin can drill down into the user directories so no restore possible. The individual users have no idea that there was ever a Time Machine backup done as Time Machine is not setup in their accounts on the individual Macs. This prevents any possible restore.
    I reckon that many of the problems are related to having only one location for ~/Library as the individual Macs are writing their user related settings into this directory in a central location. So what happens is when something on iMac 1 and then I log in on iMac 2 that might not exactly match this Macs config and it get's confused throwing one of the above erors.
    Trouble is witth central network home directory the way they mounted i can't exclude the ~/Library folder. The only option I can see is mobile account because I have seen in the preferences that when they sync the handle Library items differently.
    Does anybody have any experience out there with this sort of thing and can advise what's the best way forward?
    If i can't resolve this I'll go back to have network users with local home directories on each Mac and just setup for each user a network share to which they copy files if they want them available on other Macs. Not as nice but at least it works!
    As a said note I did this to make things easier but it has up to now cost me trouble then i had before!

    Haven't heard anything from anybody so probably to daunting a topic ...
    I have now moved on to try Portable Home Directories (PHD) and syncing ... what a disaster!
    First it took  me ages to get this right as the way the home directores are mounted on the clients from the server it's just weired which has to do with how AFP mounts are implemented. Since one AFP mount can't be mounted by several users on the same system they use a workaround of mounting it to a temp directory and then linking it back to where it should be. Of course this causes major problems.
    Okay it kind of worked so let's move on to syncing PHD. First of all on initial creation it only sync a small portion of the directory that should be okay but on some of my accounts it never went passed this stage. It said it's all synced but it only had synced the first 10% or so of the data. I wasn't able to make it sync anymore.
    On other accounts it correctly synced all the data down, or so I thought. Apparently a few sync session back and forth and 50-60% of the data was gone. On further investigation it turned out to be iTunes and iPhoto libraries. Turns out does don't sync probably via Home Sync!!!
    Apple product is not able to probably syncing Apple specific library files!!!!
    So here my warning to everybody: DO NOT USE PHD and HOME SYNC to sync your data as you will lose stuff if you have iTunes and/or iPhoto libraries with Lion OS X Server!!!
    The whole Lion Server experience has been a disaster for me. Now I have a server that does file sharing and time machine backup sharing. I can do the same thing with a standard Mac using those services. What's the point of Lion Sever for Home if nothing works proberly?

Maybe you are looking for