Network Account Cannot Log On

New, fresh install of 10.8.2 OS X Server. DHCP, DNS, Open Directory, File Sharing all working. Server hostname is set to myserver.private. Two users are created:
test1 (and other accounts) has a network home, on AFP-shared Users, enabled for Home Directories
test2 home is set to Local Only
On an MBP 10.8.2, successfully joined to myserver.private, I try to log-in with those two network accounts. One works, the other does not:
test2 is able to log-on without a problem, log-out, and log-on, and so on,
test1 seems to authenticate, but cannot log on, displays message "You are unable to log in to the user account "test1" at this time. Logging in to the account failed because an error occurred."
After failing with test1, test2 will also produce the same error, until I log-in and log-out successfully with a local MBP account, or it has been rebooted.
The only error related to test1 that I can see in the Console logs is:
authorizationhost[1197]: ERROR | -[HomeDirMounter mountNetworkHomeWithURL:attributes:dirPath:username:] | PremountHomeDirectoryWithAuthentication( url=afp://myserver.private/Users, homedir=/Network/Servers/myserver.private/Users/test1, name=test1 ) returned 64
Now, if I change test1 home directory setting (using Server.app) to "Local Only", I will be able to log-in on the MBP, however no home directory is provided (it serves the root of the local file system). If I log-out, and then use the Server.app to change it back to the previously set network home, I will be able to log-in with this account on the MBP with test1, but not with any other accounts that have a network home directory.
Any ideas why I am getting the "You are unable to log in" error in the first place? Many thanks for any hints...

It seems that the problem is that LS cannot prompt you for connection requests during the very early login stage, ie. when you are still at the login window, so the connection gets rejected and the login fails.
If you disable the LS then upon first login you will get a dialog from LS saying that there were connection attempts during login, and allow you to verfiy them, I tried it now on the second mac, and it seems that all that matters is the NetAuthSysAgent - allow outgoing connections to domain yourdomainname, but this is a rule of the user you are logging into!

Similar Messages

  • Network users cannot log in to account on server

    Here's the situation.
    1) X-Server running 10.6
    2) Workstation running 10.5 or 10.4
    3) Created user accounts using WGM (from a machine other than the server)
    4) Bound workstation to server ('green-light' and message Network Accounts Available - shows up on workstation.
    5) When test account user name and password are entered, password shakes - we get the message 'Cannot log in due to an error'.
    What gives???!!!???

    If the error you're getting is 'You are unable to log in to the user account "suchandso" at this time. Logging in to the account failed because an error occurred', that usually indicates that there was a problem mounting the user's home folder. My standard approach to narrowing down where errors like this are coming from is to test the critical parts of a network login (user info lookup, authentication, and home directory mount) by hand and watch for informative errors:
    Log in as a local user on a client computer, and open the Terminal utility.
    Run the command "id suchandso" (where "suchandso" is the short name of a network user). It should reply with something like "uid=1025(suchandso), gid=20(staff)," etc. If it instead replies with "id: suchandso: no such user", you either have the wrong username or the client is having trouble looking up user info on the server over LDAP. (Note: if this isn't working, you generally don't get as far as the error message, just a shake of the login window.)
    Get a network authentication ticket with the command "kinit suchandso" (enter the user's password when prompted). If this works, it'll just come back with another shell prompt. If something goes wrong, you'll generally get an informative error message about what the problem is (e.g. if it says "Kerberos Login Failed: Clock skew too big", that means the client's clock is too far out of sync with the server's and one or both of them needs to be corrected).
    Now, use the Finder's Connect to Server (Command-K) feature to try to connect to the server; enter the server's full domain name in the Server Address field. You should not be prompted for a name and password (Kerberos authentication should be automatic after the "kinit" command; if not, something's wrong with the file service's Kerberos setup). You should get a "Select the volumes to mount" dialog including the Users folder (or whatever folder your user homes are under). Note that the user's actual home folder will also be listed, but that's not what you want; select the Users volume instead. If the Users folder isn't listed, or you get an error trying to mount it, troubleshoot that.
    If none of that shows any problem, you've got something more obscure going wrong. A couple of random things to try:
    Enable guest access to the Users folder (shouldn't be necessary, but I've seen reports that it sometimes avoids trouble).
    Make sure the user's home folder settings are configured correctly: use WGM to switch the user's home folder to "(None)", save, then set it back and save again.

  • One network account cannot access BPC 7

    We are using BPC 7 on Microsoft. We have one user that is having trouble accessing BPC, we'll call her J. Everything used to work fine for her. Recently it stopped working. She is still in the appropriate network security groups. Here is what happens now.
    Whenever J is logged in to a computer, you cannot connect to BPC in the wizard using any account. The error is "The system cannot connect to the (HTTP://Server) Application server. Verify that you have specified a valid Application server name, or see if the Application server is unavailable at this time." However, when you log in to the same computer as a different user, you can then connect to BPC in the wizard using J's account or anyone else's. We have replicated this on multiple computers.
    I don't think it's a server issue because everyone else works. I don't think it's a computer issue because you can log on as someone else and it works. I don't think it's a desktop profile issue, because it happens on multiple computers. I don't think it's a BPC account issue, because if you log on to the computer as someone else, you can then connect to BPC using her account. That just leaves the network account, but I am not sure what to check.
    Any ideas?
    Thanks.

    Hello,
    This has been a common issue for customers, and we are working diligently to resolve this issue. It usually occurs when a user attempts to acces an appset while offline or in the process of modifying an application or processing a dimension.
    Regards,
    Jason

  • Network users cannot log in to server

    I have set up a new server from scratch on a new Macmini.  In the main, it works absolutely fine.  Users can log into the sever from client device as registered user and can share the screen with no problem.
    The users are set up as local network users and are in a local group and a network group. I set them up using Workgroup manager after setting up Open directory.  All users cn be seen from OD and WM.  However, they cannot log in to the server directly - only the server adminstrator can do that.  Home drives etc are all set up fine.
    Any help will be greatly appreciated.
    F

    Administrators always have access, you may have blocked Network Users from having access using Workgroup Manager 10.8.
    Open Workgroup Manager 10.8
    Authenticate to the local directory as an administrator.
    Go to the machines section and select the server where users cannot log in.
    Click the preferences icon to see the preferences for that computer set through WM 10.8
    From the overview choose Login.
    Choose the Access tab and set Manage: to Never.
    Message was edited by: Mark23

  • Can log in with Skype account, cannot log in with ...

    Windows XP SP3
    Skype Desktop Client 6.14.0.104
    Problem: l can successfully log into Skype with an old (~1 year) Skype name, but if I try to switch over to sign in with a new (as of 2 hours ago) Microsoft Account, I get this error:
    Sorry, something went wrong. Please try again.
    What I have done/tried:
    Created a new MS Account with a gmail address
    Verified the email address by clicking the link sent to that account
    Successfully signed in to MS Account profile page with that email address
    Tried to sign in to Skype desktop client with that account, got the error above
    Switched to Skype login, successfully connected
    Switched back to new MS account, login failed with error above
    Verified the email address username was correct by copy/pasting after a successfully Live account profile login
    Reset password following the instructions on the FAQ page
    Successfully logged into Live account page with new password
    New password fails with same error
    Uninstalled client and downloaded the latest verision
    Same thing: MS account login fails, Skype name works
    Came here
    Does anyone have any ideas?  I assume the system is up in general and I can reach it across the internet, or my old name would not work. Is this a problem of an account that's too new?
    Why not just use my Skype name?  Well, I'll be interviewing some candidates for a position on my team later this afternoon, and don't want my normal username getting out to a lot of people.
    Solved!
    Go to Solution.

    One extra piece of info: if I enter an incorrect password, I immediate get
    That password is incorrect. Be sure you're using the password for your Microsoft account.
    If I enter a bogus MS Account name, I get "account doesn't exist".
    If I enter my correct MS Account detail, I get the blue Skype login screen with the spinning "wait" logo before being bumped back to the login page with the original message from my first post.

  • How do I create a network account to log in on multiple clients?

    I am using Lion Server, and will have Lion clients shortly (waiting for 10.6 to arrive to update from Leopard).

    When you have Open Directory working you just need to make the account once and with a bound computer you can log in on all client computers to the same account.
    Look here for more info: Set up Open Directory

  • Network users cannot log in to Wiki

    I am managing an OS X Server 10.6 at work. As far as I can tell only local users on the server (i.e, those created through the server's Accounts preference pane) can log in to the Wiki (e.g., to "My Page"). Our user accounts are managed through the server's Open Directory LDAP. We don't have an Active Directory server (though we do have a mix of PCs and Macs). All SSL checkboxes are off, if that makes a difference. How do I enable Wiki login for Open Directory accounts?
    Message was edited by: MLModel

    Thanks for your reply. My concern is with users who don't have local accounts on the server machine. It seems to me that local accounts on the server machine are generally inappropriate, as well as imposing a maintenance burden that duplicates the maintenance of the Open Directory user entries.
    Am I correct that for users with no local server account I need to have "WebDAV-Digest" turned on in Server Admin > Open Directory > Settings > Policies > Authentication? Is it a bad idea to have that policy on? (I don't remember whether it is on by default when the server is installed, but it was off when I was having the Wiki problems and turning it on seemed to enable login by anyone in Open Directory.)

  • Visual Studio Test Controller recovery locks out the user domain account, cannot log into PC

    On the recovery tab of the Visual studio Test controller Services properties dialog, there are three recovery settings:
    First Failure, Second failure and Subsequent failures. The default settings for these options is to "Restart the Service". I changed my domain password this morning, restared the PC and could not log in because the Visual Studio Test Controller
    service tried to restart with the wrong credentials in an infinite loop. This resulted in my account with the domain controller getting locked out. The delay between service restarts was very quick and I could not login and stop the service. The kind admin
    fellow logged in  to the PC and changed the service settings.
    Is there a place where the recovery service restart interval can be changed to prevent this situation?

    Hi bcautest1,
    >>I changed my domain password this morning, restared the PC and could not log in because the Visual Studio Test Controller service tried to restart with the wrong credentials in an infinite loop. This resulted in my account with the domain controller
    getting locked out.
    You said that you couldn't log in, do you mean that you couldn't log in your machine or others?
    If you change the domain password, generally we could open the Test Controller configuration and change the logon account for this service.
    But if you mean that you couldn't log in your windows now, I'm afraid that it is not the test controller and Agent issue, it would be the windows issue, because it still has this issue even if you use other servers.
    Reference:
    https://technet.microsoft.com/en-us/library/cc773155(v=ws.10).aspx
    Like the following documents here:
    http://stackoverflow.com/questions/4468677/domain-account-keeping-locking-out-with-correct-password-every-few-minutes
    Maybe the Window support forum would be better for you:
    https://social.technet.microsoft.com/Forums/windows/en-US/home?forum=w7itprosecurity
    If I misunderstood this issue, please feel free to let me know.
    Best Regards,
    Jack 
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • HT201320 My personal email account cannot log on.

    I've even tried changing the password. Works fine my MacBook Pro but not the new iPad?

    This is how you setup the mail on your iPad; http://www.names.co.uk/support/email/imap_client_configuration/1182-how_to_setup _an_imap_account_on_iphone_ipad.html
    Tell what it say when it go wrong and where?

  • After binding my MAC with Lion OS I cannot log on to any network accounts

    I bound my Mac with OSX 7 to a Windows domain.
    When I restarted the unit I cannot log onto any domain accounts.
    I looked for the option to allow network users to log in via Login Ooptions but it is not there.

    cor=el,
    First link. https://support.mozilla.com/en-US/kb/Web%20sites%20or%20add-ons%20incorrectly%20report%20incompatible%20browser
    Did not work.
    ◦general.useragent.override was the only one that had a "reset" option that wasn't greyed out.
    After following as much of the proceedure as I could the problem was still there.
    Of course, I never got an "incompatible browser" report. I got a missing USER AGENT report.
    However the second link: http://kb.mozillazine.org/Resetting_your_useragent_string_to_its_compiled-in_default
    was more interesting. I reset the about:config file.
    I then deleted my history and watched the useragent files in config RESET themselves to where they were before I reset them. I connected to a website successfully, then checked WHAT'S MY USER AGENT and it showed no User Agent again. I tried again to connect to the website and got the error.
    I returned to About:Config and again reset the general.useragent files. After a while they went back to their pre-reset state on their own. Something is resetting them.
    I disabled USERAGENTSWITCHER in FF (which had been installed in an attempt to deal with this problem) I rebooted FF and returned to About:Config where I realized any click after resetting the general.useragent list undid the reset exactly.
    I reset the About:Config and immediately closed FF. I then rebooted FF. It was as if I had never reset the general.useragent list.
    Something unknown is resetting the general.useragent to pre-reset conditions on my next action. I think the links SHOULD have worked except they are not, so the problem lies elsewhere
    The "default" user agent is correct....it just keeps disappearing.

  • I am setting up a lab of imacs in a school.  I have successfully bound the imacs to our network and can log in using the windows account.  However, I cannot access my files.  Is there another step?

    I am setting up a lab of imacs in a school.  Our network is windows based using active directoy.  I have successfully bound the imacs to our network and can log in using the windows account.  However, I cannot access my files.  Is there another step?

    If the modem is also a router, either use the modem in bridge and run pppoe client on the TC.. that is assuming ADSL or similar eg vdsl. If it is cable service.. and the modem is a router, then bridge the TC.. go to internet page and select connect by ethernet and below that set connection sharing to bridge.
    Please tell us more about the modem if the above gives you issues.

  • Cannot login with Network account.

    Hi,
    I am an experimented Mac user, but quite new with Snow Leopard Server.
    I've just purchased the brand new MacMini Server.
    I have configured my server with the name server.local and installed OpenDirectory as Master.
    I wanted to try the network login, so I created a Test1 account in Open Directory. Then from my iMac I joined my server.local through System Preferences/Accounts/Options/... then I log off and try to use the newly created account test1.... I asked the system to change the password from first loggin... which works, but then I receive a message saying that I cannot log in for the moment... I tried everything but I just can't use the network account.
    Any hints?
    Cheers.

    You should avoid .local at all costs when configuring an OS X Server.
    .local is reserved for zeroconfig/Bonjour, and will cause conflicts.
    There's an excellent tutorial for new users here
    http://www.wazmac.com/serversnetwork/fileservers/osxserver_setup/osxserver106setup.htm
    Jeff

  • Cannot login to network account (leopard client and server)

    Up until now, I have used local accounts on my leopard server. I want to start experimenting with OD prior to implementing. I created a new user account in the /LDAPv3/127.0.0.1 domain, and have bound my leopard client to the server using directory utility. On the login screen, "Network Accounts Available" has a green button to the left of it. When I try and login to the server account, the login window just shakes. At first, I could enter the password and then it would prompt me for a new password. Trying to enter a new password would not allow me to login. I went back to server admin and disabled the "require new password" setting, (as well as the other good security policies)...
    I have also reset the password in WGM, and made sure to disable all the security stuff there too...
    Lastly, I have deleted the server in directory utility, rebooted, then added it back in, and rebooted again...
    I still cannot login to the server account, the login screen just shakes
    Does anyone have an idea of what settings and or logs I can check to try and narrow down what is going on?
    Thanks in advance....

    to close out the thread, I have working dns on my network, but I did not have dns enabled on my server. I enabled the dns service and entered just the info for my server, then assigned my server and client to use the server's ip addy as the primary dns server. Next, I created the home directory.
    Once both steps were done, I was able to log in from my client to my server based account...
    FYI-I found a document on afp548.com called "leopard server: advanced setup, rsync backup and automated reporting" that walks you right thru the process...Here is the link, it's a very useful doc....
    http://www.afp548.com/filemgmt_data/files/Leopard%20Server%20Quickstart%20Guide. pdf
    thanks again boomboom_uk and woVi, your suggestions were spot on....

  • Cannot login into network accounts when there is no network connectivity

    Hey guys
    quick question here if anyone can help.
    What has been done: backuped user's home folder, binded the mac to AD, logged in as the user's AD name, copied everything from the backup into the new user's home folder, users can work flawlessly.
    What is wrong is when they leave the office, after a few hours they cannot login anymore to their AD username. Is there something i missed?
    The network accounts do not appear in system preferences.
    Thanks

    On your client machine login screen, type in ">console" (without quotes) in the username field and hit enter. Try and login with your network account username and password. What error messages do you get in console?
    Taylor

  • I cannot log in to my YouTube account?

    Since I installed Firefox on my PC more than a month ago, I cannot log in to my YouTube account, and cannot watch any videos there. I get an error message, telling me connection to this site (something like that) has failed, you can "retry" it again. Nothing come of it when I retry. This is very frustrating and I'm close to giving up on Firefox as a result. Please help.

    Clear the cache and the cookies from sites that cause problems.
    "Clear the Cache":
    *Tools > Options > Advanced > Network > Cached Web Content: "Clear Now"
    "Remove Cookies" from sites causing problems:
    *Tools > Options > Privacy > Cookies: "Show Cookies"
    Start Firefox in <u>[[Safe Mode|Safe Mode]]</u> to check if one of the extensions (Firefox/Tools > Add-ons > Extensions) or if hardware acceleration is causing the problem (switch to the DEFAULT theme: Firefox/Tools > Add-ons > Appearance).
    *Do not click the Reset button on the Safe mode start window or otherwise make changes.
    *https://support.mozilla.org/kb/Safe+Mode
    *https://support.mozilla.org/kb/Troubleshooting+extensions+and+themes
    This can be caused by corrupted cookies or cookies that aren't send or otherwise blocked.
    *https://support.mozilla.org/kb/fix-login-issues-on-websites-require-passwords
    If clearing cookies doesn't work then it is possible that the <i>cookies.sqlite</i> file that stores the cookies is corrupted.
    Rename (or delete) <b>cookies.sqlite</b> (cookies.sqlite.old) and delete other present cookie files like <b>cookies.sqlite-journal</b> in the Firefox Profile Folder in case the file cookies.sqlite got corrupted.
    *http://kb.mozillazine.org/Cookies
    *https://support.mozilla.org/kb/Deleting+cookies

Maybe you are looking for

  • Firefox won't open and gives me an error that it is already open when it isn't.

    Whenever Firefox crashes or I restart the computer, I get this message that I can't open a new browser because Firefox is already open. I am using a MacBook Pro OS 10.6.7 and I have Firefox 5.0

  • Hyperlink in DESKI report

    Hello Gurus, We are using BO 3.1 My requirement is to hyperlink 2 deski reports. For example: Report A has fields (Emp Name, Emp ID) Report B has fields (Emp Name, Emp Age, Emp Salary, Emp address) Report B should be hyperlinked to Report A on the fi

  • Weblogic Integration Sample is available for download from developer site

    Hi, All, The Weblogic Integration 2.0 Sample is available for download from the developer site: http://developer.bea.com/ftp_bin/download/code/wliSample_1.zip This sample shows how to develop a standard based integration solution within and across en

  • E-mail Reports Contents

    HI,     i searched in forum for this problem but i couldn't found relevant solution for this. I want to E-mail Report Contents as a body of Email. I am geting report result somehow and holding it in a Variable type "String". Now i need some way to pa

  • Can't access recovery mode in Creative

    I want to update my firmware for my Creative Zen. I press and hold the play/pause button while starting the player. I should release this at the moment I see the creative logo. The problem is that I never see this logo. The screen is blank while the