OD SSL Connection from 10.7 Client to 10.6.8 Server Not Working

We have an existing Open Directory running on a 10.6.8 Xserve in which we have all our client OS X computers using as their authentication/authorization server. Clients are a mix of 10.5 and 10.6. We have the clients configured to connect to the server via an SSL LDAP connection. The SSL LDAP connection is a policy requirement so we can’t use a non-SSL connection. We have tried 3 different 10.7 client computers and none of them have been able to connect to the OD server via SSL. A non-SSL connection works. When we check off the box to enable an SSL OD connection in the 10.7 Directory Utility app the OD connection stops working. We get a red status indicator for the OD server connection like you get when the client can’t communicate to the OD server. Any OD lookup I try in the terminal against the OD server fails, confirming the computer’s inability to “talk” to our OD server. I ran a packet sniffer and I can see that a 10.7 client computer configured to use SSL never attempts to connect to the OD server using the LDAP SSL port of 636. I only see the client attempting to connect to the non-SSL LDAP port 389 on the server. I have already tried the usual of repair permissions, rebooting, reinstalling. We have been able to follow this Apple support doc in the past to get this to work with 10.5 and10.6 clients but the instructions don’t appear to work with 10.7 clients:
http://support.apple.com/kb/HT4183
Can anyone else confirm an SSL LDAP connection between a 10.7 client computer to a 10.6.8 OD server does not work? Has anyone even gotten this setup to work?

Martin,
That was the link the OP used that didn't work for him.
I haven't heard from James, but I solved my problem using both this support article:
http://support.apple.com/kb/TS3861
and my own black magic:
http://groups.google.com/group/macenterprise/msg/0a5f8c0725e9bfdd
--Francis

Similar Messages

Maybe you are looking for

  • JSF or Struts

    Hi, We have a web application designed using MVC framework. Besides a web view, we now need to support mobile users using WML. We are considering JSF and struts (customising struts to handle WML client). I have read that JSF supports disparate client

  • How to sync iTunes to iPhone

    Hi there, I'm having trouble syncing my iPhone 3G onto my iTunes. How do I copy ringtones, music and podcasts which are on my iPhone into iTunes??? I download podcasts directly onto my iPhone so there's always new podcasts on my iPhone which aren't o

  • Require  help in my ABAP code

    Hi All, My design wont allow Delta loads because the transformation source is an InfoSet.  To limit the data in these loads, I require a  filter in the DTPs on fiscal year/period then only load I can load the current month and 2 prior months.  Now we

  • Purchase requisition release strategy - projects person responsible

    Hello, I want to create a characteristic in CT04 that contains the person responsible of a project (CJ20n). What would be the table and the field for that? Thanks Anne

  • Skin tone brush

    Why i can't use skin tone brush (only on skin) and than correct white balance on oll photo. i wont do that at the same time.