Network user log in problem

Can not create a network user, with home on the server.
I;m sure I am missing something, but can't seem to find it.
Any suggestions/pointers greatly appreciated.
The layout:
Server = Mini, 10.6.2, Open directory master, private network
Client1 = G4, 10.4.11, hardwired
Client2 = MacBook, 10.5.8, wireless
Airport extreme, handling dhcp
On the server a share point "Homes" created, with enable automount, use for home folders.
On the server user "zxc" is created, home folder set to afp://xyz.private/Homes.
Preferences for login managed, with "add network home share point" checked.
Client1 attempts to login and gets: "...account login failed....the home folder is located on AFP or SMB server...."
Client2 attempts to login and after delay, gets shaken off with no error.
Changing the home folder in workgroup manager to none, results in Client1 logging in but with error "...folder 99 can not be accessed .... premissions..." which would seem to confirm that Client1 is connecting to the server but having issues with home folder.
Don't know why Client1 can not log in, or why Client2 is not acting the same as Client1 ?
Did I miss something in setting up the network home folder? It shows up in the Home panel for the user and shows the correct home url and full path. Logging in on Client1 as a local user, I can connect to the server and mount the home folder using the "zxc" user and password.
I'm lost where to look next.
Thanks.

I encountered this issue when we did a clean install of 10.6 server to replace 10.4 server on our Mac Pro. The 10.4 clients cannot correctly distinguish the CNAME records of the 10.6 server. This VERY IMPORTANT piece of information is missing from the 10.6 administration guides.
Open Directory, like Active Directory, heavily relies on correct DNS setting. Your DNS settings are the first thing to look at.
The fix is simple. On the Mac client machines make sure the following is done:
1: Login with a local admin account. In the Network system preference make sure the primary DNS server IP address is the IP address of the OSX server.
On the OSX Server in the DNS manager you need to specify the external or "relay" IP address of your ISP's DNS server(s) if it is not already there. This way if the internal Mac DNS server cannot resolve the name they will push the request to the external DNS server. 10.6 server's wizard automatically assigns the external DNS entry to Server Admin when you set up the server.
2: Go into the utilities folder on the 10.4 client and open Directory Access. You should have the LDAP entry of the Mac OS X server. to the right of that is LDAP settings come from pull down menu. Choose Open Directory; it probably was set on automatic. 10.4 clients do not understand the automatic open directory server CNAME entries, you have to specifically tell then to use Open Directory as the LDAP source.
If you do not have a LDAP entry then you need to add it. type in the IP address or the DNS name of your mac server. Choose Open Directory as the LDAP entry type.
The "Cannot login to the user account because the home directory is located on an AFP/SMB server" error message is a constant headache to OSX admins because the error message doesn't tell you anything.
You should now be able to click on "other" and login to you AFP mounted home directory.
Message was edited by: lakorai

Similar Messages

  • No network user log in at login window when over WiFi??

    I can only log in as a network user (home directory on server instead of local) from computers that are connected via wired Ethernet, but not on computers connected via WiFi. From any computer a local logged in user can access server resources -- they just can't from the login window. It is as though WiFi is only enabled once logged in (however it still doesn't work even if I use Fast User Switching to get a login window.)
    Anyone experiencing this problem and found a solution?
    As a secondary issue, I haven't been able to figure out how to automount shares via any technique nor have I found an explanation of how to do it in the manuals. Enable Automount in Server Admin doesn't seem to do it for "Shared Library Folder" however at least something appears in /Network/Servers for "User Home Folders and Group Folders, although it isn't mounted. I've also tried Workgroup Manager, Perferences, Login Items, adding shares there, also to no avail. All the shares will mount via client system command so the sharing does seem to be working.

    I don't have my wireless entwork set up yet (no one really needs it), so can't help with that issue. Although, I seem to recall Fast User Switching has issues with network accounts anyway, so that issue may be unrelated to your original WiFi issue.
    As for automounting, you should have it set up in Server Admin first (as you seem to already). Then you need to also set it up in WGM much like it seems you tried, but make sure you're doing it from a client machine and not from the server so it populates with the proper path info (or you could correct it in the Details section if you know what you need, but that's unnecessarily cumbersome). Also, make sure the "Authenticate selected share point with..." is checked for the share as well. Of course, if you're already doing this from the client, then I've no clue as it seems everything should be fine. That's how mine are set up with no issues, although I also have them set up on the dock, but that should be irrelevant just for mounting purposes.
    Message was edited by: Rikakiah

  • Networked user logs in and only gets dock and spotlight icon

    Here's the deal: I have a networked user (PHD) that logs in the only gets her dock and spotlight icon to come up. The rest of the menu bar at the top is missing. If you click on an icon in the dock it bounces and trys to open but never does and quits. Any ideas? This has happened before to two other users of mine using the same type of computer (2.0ghz 20in iMac G5) With the other two I was very busy so I just dropped our editorial image/clone on there and that fixed it. What is weird about this is that the user can log in on another computer fine and different users can log in on that computer fine. The computer is running 10.4.4 and the xserve is running 10.3.9
    Thanks!

    well its created by using bad fonts at one time in your system - or fonts that do not exist on a local volume. when you load a font that is bad and may conflict with a current font etc the system encounters problems - upon reboot the "font cache" remembers this font and doesnt initialize the window server properly. the other case i mentioned is when i loads up and tries to load the font that was cached but was loaded into suitcase or some font management from a cd or network volume. the volume is not available and then the user login fails to finish... been a problem ever since 10.4 came out. 10.3 had its own way of showing the same issue.

  • Multiple Users/Logging In Problem

    Using Multiple Users I added a second user to our iMac DV400 (blueberry, slot loading) running OS9.2.1. The problem: now we can only log on to the second user's desktop and can't access the primary user's desktop. Since the second user is set up with limited user privileges, we can't access the system programs; most importantly, the Multiple Users program so that we can revert this problem by deleting the second user from the system. Can anyone offer some help?
    Thanks

    Welcome to Apple Discussions pd,
    Start from your Mac OS installer CD (insert it and hold the c key, release the key when you see the "Welome To Macintosh" message)
    Open your hard drive and locate the System folder. Open that and locate the Preferences folder. From that folder, delete the three preference files and one folder with "Multi User" in their names.
    Restart as normal and empty the trash. You will have to re-create the user accounts.

  • User log on problems

    user account cannot  be loaded
    cannot  logon 

    1.  Use the Windows 7 DVD to start the computer in Windows Recovery (WinRE).
    2.  In WinRE, open a command prompt. To do this, follow these steps:
            On the Install Windows screen, select the appropriate Language to install, Time and
         currency format, and Keyboard or input method options, and then click Next.
    3. Click Repair your computer.
    4. Click the 7 installation that you want to repair, and then click Next.
    5. Click Command Prompt.
         At the command prompt, type the following command, and then press ENTER:
    lusrmgr.msc in the search line and press Enter
    NOTE: This file is located at C:\Windows\System32\lusrmgr.msc
    1. Open the Local Users and Groups manager.
    2. In the left pane, click on the Users folder.
    3. In the middle pane, right click on Administrator and click on Properties.
    4. To Enable the Buit-in Administrator Account > Uncheck the Account is disabled box > Click on OK.
    5. Close the Local Users and Groups window.
    6. Log off, and you will now see the built-in Administrator account log on icon at login screen.
    Click on the Administrator icon to log on to the built-in Administrator account.
    Create new user account with administrator privilege.
    Start > Control Panel > User Accounts and Family Safety > User Accounts > Manage another user account > Create a new user > type USERNAME and Select Account type as administrator > Click Create Account.
    Open lusrmgr.msc > Users > right click on ADMINISTRATOR and click on Properties > Check the Account is disabled box > Click on OK.
    Login into the new user account.
    Go to C:\Users > Open the previous user account folder which is not loaded > Take backup of your files from Desktop, Documents, Pictures, Music, Videos and Downloads.
    Delete the user account which is not loaded.

  • Network user switching from log in screen in Mavericks

    I have an iMac set up for network users, but I can't seem to figure out how to switch users from the login screen after a time out screen lock. That is, if I'm logged on to the machine, and walk away from it and it autmatically locks the screen, how can another network user log on at that point? This seems like it should be a pretty basic feature, like it is in (stupid) Windows.
    I'm running:
    OS X Mavericks 10.9.1
    iMac (2013) 2.7 GHz

    Hi,
    i am experiencing smiliar problem:
    Sep 21 23:09:40 Xserve slapd[40]: SASL [conn=143] Failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (No principal in keytab matches desired name)
    Sep 21 23:15:41 Xserve slapd[40]: <= bdbsubstringcandidates: (authAuthority) index_param failed (18)
    several times - every time a user from a Mac (iMac with Intel processor and 10.5.8 OS X) tries to log in.
    Remark: There are some windows-Workstations that login on Active Directory and work fine!
    Does anyone have some ideas how to solve that problem?
    Thanks!

  • Finder window opens when user logs in

    I apologize if this has been answered previously - I can't find anything on this topic.
    Every time a user logs in to one of my eMacs - OS 10.4.10 (whether it be a local or network user) a new finder window opens that displays the users home. I would like this window to stop opening. I've read some responses that say to close the window then log out and the window should be gone when you log back in. That is not the case. I thought this solution my work on my local users but it doesn't work for either type of user.
    I'm trying to avoid writing a script to close the window. I'd like the window to just stop opening in the first place. I tried editing the finder.plist file and I can change what the window opens to, but I can't "turn off" the actual opening of the window.
    Any suggestions are greatly appreciated!
    Thanks!

    I do not have anything checked in the login items. This is happening for both local and network accounts. I'm more concerned about this issue for my network users.
    I've discovered that the problem seems to have something to do with a script I had running via a login hook. Is there any way to run a script when a network user logs in without adding it to a login hook?
    We have a program on our eMacs that resets the computer back t o its original state every time the computer is restarted. For this reason network user profiles are never stored on the eMac they are recreated from the default user template every time a user logs in.
    Maybe this extra information will help!
    Thanks!

  • How can a network account log on via ssh to run jobs?

    We have a small setup with a tiger server and snow leopard clients. Each user has their own machine, but we have some communal mac pro machines. A lot of the software we run uses xwindows and I would like to have a method that allowed the users to ssh to these number crunching machines and run their parallel code at the same time, without having to log on using the apple log in window.
    The problem: The home directory is mounted at log in and is only readable for the person who physically logs in at that computer, so if a network user logis in via ssh they cannot see their home directory, and the authentication for xwindows screws up and there is no display.
    How can I make my client machines mount the home directory properly, and in a readable way, so that my network users can ssh to various client machines and have all their data available?
    I look forward to being illuminated.
    Will Handler

    rdoss
    Welcome to the Apple Discussions.
    If you want others to be able to see the pics, but not add to, change or alter your library, then enable Sharing in your iPhoto (Preferences -> Sharing), leave iPhoto running and use Fast User Switching to open the other account(s). In the other account(s), enable 'Look For Shared Libraries'. Your Library will appear in their source pane.
    Remember iPhoto must be running in both accounts for this to work.
    Regards
    TD

  • Add Network Users to Fast User Switching Menu

    Local users appear in the *Fast User Switching menu* on our Macs. How can we add users with *Network accounts* on our bound Mac OS X Servers so they appear in the Fast User Switching menu w/out already being logged into the client machine?

    Demetrios wrote:
    Local users appear in the *Fast User Switching menu* on our Macs. How can we add users with *Network accounts* on our bound Mac OS X Servers so they appear in the Fast User Switching menu w/out already being logged into the client machine?
    It did not use to be possible to have two (or more) network users logged in on a machine (via fast switching) as the normal method of accessing network home directories, i.e. via AFP had limitations that prevented this.
    If you want to try this, I suggest you first need to setup your home directories so they are shared via NFS rather than AFP. I found I had to actually turn AFP off for that share rather than merely setting the autoshare to be NFS as if it was shared by both AFP and NFS the clients seemed to prefer using AFP and would use that instead.
    I am not using fast user switching myself for this, but I have a Terminal Server running on a Mac Server which allows multiple clients to be logged in at the same time and accessing their home directories via NFS.

  • User settings to access network when logged on as service/batch

    Hi.
    We have been running Oracle Remote Agent (running external jobs on other host) on some linux-distros and have now started to do it on Windows as well.
    But when we have setup everything properly, we get an 'Access denied' when trying to access the network from the Remote Host.
    The way it works, in the database, you set up a credential with a user name and password. This information is then sent to the ETL (Remote Agent) which then starts the process as the user supplied in credentials.
    So the service it self is running as Local Service and then starts a process as another user. Technically, how this is done on Windows I don't know...
    Anyhow, the process starts fine and if we are not trying to access the network, it works fine.
    But as soon as we are trying to access a network share using UNC path (\\192.168.1.10\share\directory), we get an 'Acces is denied'
    The user we are using is an administrator. When doing a desktop login, this user can access the share without any problem.
    Is there any other settings/policy/property the user must have to be able to access the network when logged on but not from the desktop?
    Cheers
    Richard

    Have you checked the security logs on 192.168.1.10?
    You should see the entries showing what account is attempting to log on through a network connect.  You may need to grant the User Right for "Allow Access from Network" and you may be having basic folder permission errors.
    I'm curious if the process is using the machine account to hit the share or if it's the user account you're starting the process with.
    Chris Ream

  • How can I get Firefox to run on a network with multiple users logging on with the same user name and password?

    I am trying to get Firefox running on a large network where I have multiple users that log on with the same user name and password. The problem is that when another user logs on to another computer the message comes up that their is already an instance of firefox running on that computer even though there really isn't. Only one instance can be run on the network at one time. I believe it is because firefox stores a shared profile as it thinks it is actually the same user even though it is being run on another computer. I repeat that each user that logs on uses the same user name and password but on different computers.

    I am trying to get Firefox running on a large network where I have multiple users that log on with the same user name and password. The problem is that when another user logs on to another computer the message comes up that their is already an instance of firefox running on that computer even though there really isn't. Only one instance can be run on the network at one time. I believe it is because firefox stores a shared profile as it thinks it is actually the same user even though it is being run on another computer. I repeat that each user that logs on uses the same user name and password but on different computers.

  • Problem setting up Network User

    I am running Mac OS X 10.5 Server with clients running 10.5 also. Currently, there are several users on the server, but in Workgroup Manager, their home directory is set to null. The users have local accounts on certain 10.5 clients which are linked to their accounts on the server. So when they log in to the client, they are authenticated against their account on the server, and various settings (Mail, iCal) are picked up from the server.
    I now need to allow users to log in to any client machine without setting up a local account (and linking it to the server account) first. So I have gone through the procedures specified in the 'User Management v10.5' documentation, specifically the 'Administering Share Points' and 'Administering Home Folders -> Creating a Network Home Folder' sections. I have used the second set of procedures to create a network home folder for a single test user. I assume that this makes the test user a 'Network User', though how to create a 'Network User' is not explicitly specified anywhere.
    The problem is that on a client machine (that does not have a local account for the test user), the test user's network account is not listed on the login screen (though the login settings indicate it should be), and I also cannot log in as the test user by clicking on 'Other...' and supplying the requisite credentials. I should note that the client Mac is 'attached' to the server (eg. through Directory Utility).
    Can anyone provide advice as to what's going wrong? Is there some other (secret?!) step that is needed to create a Network User so that clients see the user and allow the user to login?
    Many, many thanks,
    Jolin

    Hi Leif,
    Many thanks for your reply.
    Leif Carlsson wrote:
    The only way of "linking" a "local" account on a computer to a OpenDirectory account that I know of is to create the "network" account homefolder on the local/client machine HD when the user is logging in to the OD server for the first time.
    Actually, it is possible to not have a network account or home folder, and link a local user to a user account on the server. When a client computer is bound to the OpenDirectory server, in the 'Accounts' preference pane of the client computer, there is a field called 'Server Account:' with a 'Set…' button. Clicking the 'Set…' button allows one to link the local account to the server account. Even though there is no home directory on the server, when the user logs in to the client Mac, the password and any managed preferences for that account are taken from the server account.
    The client machine has to be bound to OD first and the account should preferably be setup as a mobile account (so the account can be used even if the computer isn't connected to the network - logins are cached locally).
    I have bound the client machine to the OD server, but I have not yet set up the account as a mobile account. I plan to do this eventually, but wanted to get the 'basic' network user account working first.
    For a "true network home" folder residing only on a server volume/share, the OD account should use a share(point) setup in Server Admin for an automount AFP (or NFS) "User home folders" share.
    I have done this. The server has a sharepoint called 'Homes' which is set to automount over AFP, with the setting 'Use for: User home folders and group folders'. This seems to be working, because on the client Mac, the 'Homes' sharepoint automatically appears when browsing the available network volumes.
    Then in the OD the user should be setup to use the automatically created path (afp://<server FQDN>/<shared folder>) as it's homefolder path.
    I believe I've done this as well, using Workgroup Manager. When viewing the 'Basic' tab of the user, the 'Home:' is given as 'afp://<server FQDN>/Homes/jwarren'. That looks right to me, but I cannot login as the user 'jwarren' from the client Mac's login screen (Network Users are enabled on the client Mac). When I log in as a different user on the client Mac, I can browse the network, and the above afp path is automatically mounted.
    Is there some other setting needed so that the client Mac will 'see' the network user I have set up? As I say, the autmount sharepoint is set up, and the user is set up in OpenDirectory (on the server) to have a home folder on the automount. But when I'm at the login screen on the client Mac, the network user does not appear in the list, and if I try to login by typing the username and password manually, the login window just shakes as it does when one enters the incorrect password.
    Any further help much appreciated!

  • Not able to log in as an AD Network User

    Hey guys,
    I am sure this has been beaten to death but I can't seem to be able to authenticate as an AD network user to my os x 10.5.7 system.
    I see that my domain controller is responding normally inside of the Directory Utility but when I try to log in as a network user, I get the login shake telling me that access is denied.
    Is there an additional step that I missed? Or something that the readings have not let on? Is there a specific way I need to specify that I am a network user when I try to login?
    Any help is greatly appreciated

    Hi,
    I am having the same problem
    Did you manage to solve the issue?
    TIA
    Giorgio

  • Permissions problems with networked users

    Hi,
    We use 11 intel imacs with networked users from an xserve and run Logic Pro. I have told all students to run their projects from a temporary folder on the local hard drive and then copy the final work to their desktop to secure it for next time if they use a different machine, this seems to work OKish.
    However there are a few features that refuse to work in Logic for a managed user, time stretching is one and various others so what I need to know is anyone have a comprehensive list of ALL the folders that logic would use so I can make them all read/write to everyone and see if the problems go away. A local account with admin privileges seems to work fine but I am keen to solve the problem at the root level and this seems like a good place to start.
    Anyone have any tips on networked LDAP users and Logic Pro?

    I don't know about the network stuff as such, but there are various utilities that hook into OSX to display all file activity - you can turn on logging, run the application, then look through the log to see what files that Logic was trying to access while it was running.
    It might give you some clues, beyond all the obvious stuff (application, preferences files, app support files, garageband libraries, plugin settings, plugins, sampler instruments, audio files, project manager database files and so on)

  • Network users cannot log in to server

    I have set up a new server from scratch on a new Macmini.  In the main, it works absolutely fine.  Users can log into the sever from client device as registered user and can share the screen with no problem.
    The users are set up as local network users and are in a local group and a network group. I set them up using Workgroup manager after setting up Open directory.  All users cn be seen from OD and WM.  However, they cannot log in to the server directly - only the server adminstrator can do that.  Home drives etc are all set up fine.
    Any help will be greatly appreciated.
    F

    Administrators always have access, you may have blocked Network Users from having access using Workgroup Manager 10.8.
    Open Workgroup Manager 10.8
    Authenticate to the local directory as an administrator.
    Go to the machines section and select the server where users cannot log in.
    Click the preferences icon to see the preferences for that computer set through WM 10.8
    From the overview choose Login.
    Choose the Access tab and set Manage: to Never.
    Message was edited by: Mark23

Maybe you are looking for

  • Search more than one location at a time?

    Hello, I spend a lot of my time searching for files in our studio (I maintain the archives, backups, file systems, etc.) and I have to search across a number of locations (a number of local drives, specific locations/folders on various servers, etc.)

  • Complex type in web service request

    Hello everybody... Maybe not the best place, but have to start from somewhere. Recently, I've started playing with utl_dbws package. I succeeded to call webservice with simple parameter. Now, I'd like to send (and receive) a parameter which is array

  • Node problems

    Hi! I have a problem with the org.w3c.dom.Node (implementation) object... or more specificly its method getNodeValue. My problem: I have a Node object and im trying to get its value like this: node.getNodeValue() returns: null one line later.... node

  • Finding Your Custom Color Swatch by Name

    I have created a large custom swatch set and I need an easy way to find one by its name. I know you can search for Pantone colors but is there way to search through your named swatches?

  • I can't open iMessage, app store on my macbook pro

    i recently installed mavericks, everything was ok until I used clean my mac, since i cant open may apps, I dont have any backup on time machine, i have already tried with starting up in safe mode and it didnt work please help !!