Open Directory PDC w/ profiles stored on another server

Hello,
I am working on a new Open Directory (OD) setup to consolidate our O/S authentication directories. I desire to have our OD act as our Windows PDC. However, I want the profiles to be stored on another Samba server. I tried setting 'logon path = \\myserver\%U\profile', but when a OD Windows client logs in the system does not create a new profile.
Can an Open Directory Samba PDC store profiles on another server? If so, how do you do it?
Thank you,
Joe Kotran
Mac Pro   Mac OS X (10.4.8)  

SUMMARY
Q: Can an Open Directory (OD) Samba Primary Domain Controller (PDC) store user profiles on a third party Samba / storage server?
A: Yes! To do so set `logon path = \\$server\$user\$folder` in smb.conf on the OD server. This value will work for all accounts. You may also set individual profile paths in the Workgroup Manager GUI administration tool.
If you experience a "cannot find profile" error when you first set this up, try setting `profile acls = yes` in the [homes] share of your Samba storage server.
Mac Pro Mac OS X (10.4.8)

Similar Messages

  • How can I add links to open xml and csv files stored in another location? Please advice how to place links in my frame maker document?

    Hi,
    I would like to know as to how can I add links to open xml and csv files stored in another location? Please advice how to place links in my frame maker document?
    Kindly advice.
    Thanks
    Priya

    Special > Hypertext > Command "open document" will do its best to open the target document inside FrameMaker, which may not be much help; Special > Hypertext > Command "message …" will use the application you specify. The user guide for 7.0 says this about absolute links, and I don't think anything has changed since:
    For example, to start PaintBrush and open the Ship.pcx file on drive C you would use the command message system pbrush.exe C:/Ship.pcx
    I've not often used a relative link, and not recently: the same source says
    folder levels are separated by a slash / even in Windows and Mac
    [relative links] FrameMaker searches for a relative pathname beginning in the folder that contains the current document
    [absolute links] FrameMaker searches for an absolute pathname beginning at the top of the file system. In Windows, the absolute pathname begins with the drive specifier, a colon and a slash.

  • Using open hub to create a file on another server

    Hello everyone,
    I am wanting open hub to create a file, but create it on a different server (a file sharing server not associated with SAP).  Both BW and this file share server run Windows.
    Can this be done using logical files  (FILE transaction) or other configuration?
    I am aware of some other people posting here that send the file from open hub to DIR_HOME and then have created an OS command (SM49) to copy to the other file share server.  Also I know one could also write an ABAP to FTP the file from this location out to the file share server as well.
    I was hoping that FILE transaction would allow this but so far I have not had any luck with it.
    Many Thanks,
    Kevin

    All,
    Found out that this can be done, you can send a flat file from BW to a completely different server in one step, no need for SM49 or AL11 or FTP or ABAP program in the middle.  The trick lies in the configuration in transaction FILE.
    FILE transaction configuration steps:
    Step 1 - Define Logical File Path - just a place holder here
    Step 2 - Assignment of Physical Paths to Logical Path, here is where you enter the server & path but not a filename, for example
    \\server_swvs01\SAPFILE\<SYSID>\BPC\Cust_R3_sales\<FILENAME>
    Step 3 - Define Cross-client Logical File Name, here is where you specify the actual file name to be written to the file share on the other server in field "Physical file", just make sure and link this to the Local path you created in Step 1 above.  You can also use system variables in the physical file name or hard code it all.
    your_file_name.csv
    Hope this helps someone
    Cheers,
    Kevin

  • Why do website links to documents stored on another server work in IE but not firefox?

    here is the line of code that works fine in IE:
    <td><div align="left"><b><a ref="file://sndpdps.ess.ad.addp.com/opssupport/FLOWCHARTS/Batch_Processing/PDF format/BKUP_FACKS_PROD_Daily.pdf" target="_Top">FACKS_PROD Backup</a></b></div></td>

    Does it work with 3 "/" after "file:" (i.e., file:///)
    '''If this reply solves your problem, please click "Solved It" next to this reply when <u>signed-in</u> to the forum.'''
    Not related to your question.
    You have multiple old Java Console '''''extensions''''' installed that Java did not clean up when updating. The versions are 6.0.13, 6.0.14, 6.0.15, 6.0.17, 6.0.19, 6.0.20, 6.0.21, 6.0.22, 6.0.23. (You also have version 6.0.24 which is your currently installed version of Java --- see below).
    You can remove the old versions by following these instructions: http://kb.mozillazine.org/Java#Multiple_Java_Console_extensions
    Not related to your question, but...
    You need to update some plug-ins:
    *Plug-in check: https://www-trunk.stage.mozilla.com/en-US/plugincheck/
    *Shockwave Flash (Adobe Flash or Flash): [https://support.mozilla.com/en-US/kb/Managing%20the%20Flash%20plugin#w_updating-flash Updating Flash in Firefox]
    *Next Generation Java Plug-in for Mozilla browsers: [https://support.mozilla.com/en-US/kb/Using%20the%20Java%20plugin%20with%20Firefox#w_installing-or-updating-java Installing or Updating Java in Firefox]

  • Open Directory authentication question

    I have 2 Apple servers.  One is running 10.6 (server), the other is running 10.5 (server).  I have my Open Directory on the 10.6 server, and I have the 10.5 server use it via LDAP for user authentication.  What I'd like to do is to assign a home directory on the 10.5 server for users in the 10.6 Open Directory.  Any ideas?

    mickey13 wrote:
    I have 2 Apple servers.  One is running 10.6 (server), the other is running 10.5 (server).  I have my Open Directory on the 10.6 server, and I have the 10.5 server use it via LDAP for user authentication.  What I'd like to do is to assign a home directory on the 10.5 server for users in the 10.6 Open Directory.  Any ideas?
    This should work the same way as normal.
    Define the user accounts in Open Directory as normal via Workgroup Manager
    On the 10.5 Server, set up a share point, usually AFP is used as the protocol, this is done in Server Admin
    On the 10.5 Server, set up that share point to be an Automounted share for user home directories, this will register that share in Open Directory assuming you have already successfully connected the 10.5 Server to Open Directory system, this is also done in Server Admin
    Go back to Workgroup Manager select a user account you want to store on the 10.5 server, click on the Home tab, you should now see the 10.5 share point listed as an available choice for storing home directories.
    Click on the 10.5 share point and save the user account.
    I normally now click on create Home directory, although this happens automatically when a user logs in for the first time.
    It is perfectly ok to mix 10.5 and 10.6 servers in this manner. The client machines can also be a different version e.g. 10.4
    What you are doing above even though you are mixing 10.5 and 10.6 servers, is the same as you would do to spread the workload of user home directories across multiple servers. While handling user home directories does not cause a massive amount of CPU activity (or memory use) it does cause a significant amount of disk activity and therefore at a certain level spreading user accounts across multiple servers is recommended.

  • Open Directory Keychain Question

    I have set up open directory on my domain but I am having trouble with Keychain access over the network when users logging into network accounts. Whenever I log in using open directory, I can open all of my applications, however each time I log in to my user account all of my keychain passwords are reset. I can look into the user preferences file and see the keychain file, but for some reason whenever a user logs out the changes to it are lost.
    Is Keychain access supported when network mounting user folders? If so, what is the proper way to implement keychain access?

    mickey13 wrote:
    I have 2 Apple servers.  One is running 10.6 (server), the other is running 10.5 (server).  I have my Open Directory on the 10.6 server, and I have the 10.5 server use it via LDAP for user authentication.  What I'd like to do is to assign a home directory on the 10.5 server for users in the 10.6 Open Directory.  Any ideas?
    This should work the same way as normal.
    Define the user accounts in Open Directory as normal via Workgroup Manager
    On the 10.5 Server, set up a share point, usually AFP is used as the protocol, this is done in Server Admin
    On the 10.5 Server, set up that share point to be an Automounted share for user home directories, this will register that share in Open Directory assuming you have already successfully connected the 10.5 Server to Open Directory system, this is also done in Server Admin
    Go back to Workgroup Manager select a user account you want to store on the 10.5 server, click on the Home tab, you should now see the 10.5 share point listed as an available choice for storing home directories.
    Click on the 10.5 share point and save the user account.
    I normally now click on create Home directory, although this happens automatically when a user logs in for the first time.
    It is perfectly ok to mix 10.5 and 10.6 servers in this manner. The client machines can also be a different version e.g. 10.4
    What you are doing above even though you are mixing 10.5 and 10.6 servers, is the same as you would do to spread the workload of user home directories across multiple servers. While handling user home directories does not cause a massive amount of CPU activity (or memory use) it does cause a significant amount of disk activity and therefore at a certain level spreading user accounts across multiple servers is recommended.

  • Open directory 'read only' after restore

    Hi
    I have restored open directory using sudo slapconfig -restoredb after our server hangs on a restart and subsequently loses the master record, users etc.
    All appears OK except that I am unable to add or remove users via the Server.app. It appears as though the restore process has given the OD read only permissions?
    Any ideas
    Thanks
    Andrew

    Please update Mountain Lion and OS X Server to the latest versions (App Store) and use Workgroup Manager 10.8 to manage your users.

  • Open directory on lion server

    I've got problem with my open directory with A red dot not responding

    Download Server Admin tools for 10.7.2 from Apple's support downloads page, I have found Workgroup Manager more stable for managing network users and groups. Plus you need Server Admin to set up your Open Directory Master well. The only thing you will need Server.app for is setting the network users home share location.
    You can do it all from Server.app but I have found it to be slow and cumbersum

  • Cant Edit Ldap Search Base in Open Directory

    Greetings ,
    My ldap search base wrong in my open directory . I have tried converting the server to standalone and back to a directory master and it still retains the old search base. How do i get rid of this, as it is causing problems.
    Thanks In Advance

    Any resolution to this? I am trying to configure OD and it's NOT using our FQDN for the server as the search base... instead of server.domain.NET it is putting in server.domain.COM - pretty sure that will cause problems.
    I ran host <ip address> and checked our DNS settings on the server and everything is configured as .NET - cannot find this .COM anywhere. Am NOT in a position to do an uninstall and re-install as many folks have seemed to have done.
    Mike

  • Local Admin Doesn't Authenticate on Open Directory 10.9

    Running 10.9.4.  I exported my open directory database from my old 10.6 server and imported into my new 10.9.4 server.  Everything worked without a hitch, except that the local admin can't administer the database, only the old directory admin (which works, but after every action, it tells me I'm not authenticated... even though it still works).
    I double checked, and sure enough, all the admins are in the directory administer group:
    GroupMembership: root diradmin rfinn
    Member: root diradmin rfinn
    NestedGroups: 9B953861-B2D1-43A2-BC57-F53C0C33F236
    PrimaryGroupID: 80
    RealName:
    Open Directory Administrators
    RecordName: admin
    RecordType: dsRecTypeStandard:Groups
    But... it still doesn't authenticate in Workgroup Manager.  Just to be sure, I re-added the LDAP admin GUID to the local admin's nested group list, but that didn't fix the issue either.  Suggestions?
    Thanks,
    -Rob

    Running 10.9.4.  I exported my open directory database from my old 10.6 server and imported into my new 10.9.4 server.  Everything worked without a hitch, except that the local admin can't administer the database, only the old directory admin (which works, but after every action, it tells me I'm not authenticated... even though it still works).
    I double checked, and sure enough, all the admins are in the directory administer group:
    GroupMembership: root diradmin rfinn
    Member: root diradmin rfinn
    NestedGroups: 9B953861-B2D1-43A2-BC57-F53C0C33F236
    PrimaryGroupID: 80
    RealName:
    Open Directory Administrators
    RecordName: admin
    RecordType: dsRecTypeStandard:Groups
    But... it still doesn't authenticate in Workgroup Manager.  Just to be sure, I re-added the LDAP admin GUID to the local admin's nested group list, but that didn't fix the issue either.  Suggestions?
    Thanks,
    -Rob

  • Dot in Open Directory username prohibits Illustrator CS3 from starting up

    Hi
    We have a large Open Directory on a MacOS X 10.4 Server. The clients uses OD and Network Home on their Computers.
    We used CS2 whit out any problems. But now we have upgraded to CS3. The problem is that Illustrator won´t start up. I have isolated the problem to the dot we use in the shortname on the OD-users. Testusers whit out the dot works fine, and local users whit a dot works!..
    So, OD users whit dot is the problem...
    Anyone got a workaround for this?
    It´s to many users to change the shortname. And the OD is used by our mailserver to, so changing shortname is not an option.. :(

    Sounds like a question that might do better being explored in a forum that focuses on O.D., rather than one which is about Illustrator.
    Just a thought...

  • Configuring DNS for Open Directory

    I'm reading Mac OS X Server Essentials, A Guide to Using and Supporting Mac OS X Server 10.4 and in the Open Directory section it says Make sure your server is resolving DNS correctly. If not, you may need to stop and start DNS.
    I don't have DNS set up on our Xserve so I started reading the section about DNS.
    We don't serve any web or mail services from this Xserve and I don't want to screw up the Custom DNS service provided by our web host/nic provider. If I enter my domain in the DNS admin area will that affect anything outside our LAN?

    It says: "Make sure it is resolving DNS correclty. ...". It ain't saying: "DNS has to be running on the OD server itself. ...".
    So if your network provides does handle dns for you that perfectly fine. Just check that they have forward and reverse records in place.
    -Ralph

  • Some Open Directory accounts will not log in

    At the school where I work, the Open Directory master is running 10.6.8 Server and the clients are running 10.7.4. I am preparing images to update all the clients to 10.8.3, and I've run into a curious issue.
    In our setup, we have a single Open Directory account for each classroom. They are set up for simultaneous login, and their home folders are created in /Users rather than on a network share. We have 20 or so unique room accounts, and the text boxes I'm working with now can log into almost all of them. However, there are a few that simply refuse.
    When I attempt to log into one of those accounts, the login window immediately shakes as if I've put in the wrong password. However, I've confirmed that the password is correct. I've also checked through the settings of those accounts to make sure they're in line with all the rest of them. I know that they work because our lab Macs, which are currently running 10.7.4 are able to log into them just fine.
    I've tried unbinding and rebinding the clients to the OD server, as well as manually creating a home folder in /Users, neither of which works. I have found a little bit of voodoo that seems to work sometimes. I have to bind to the OD server, then check "Allow Network Users at Login Window", then select "Only These Users", then add all of the available network users to the list. Then, I delete them all, restart the computer, and sometimes that works. Not always though.
    Has anybody run into this before?

    As far as I can tell, the server isn't logging much with regard to the passwords being refused. I have tried attempting to log in to the accounts that don't work and then checking the Open Directory logs within Server Admin, but I don't see anything either relating to that user or with a timestamp that's close to the time to log in.
    On the client side, the log entry I see that relates to that user trying to log in is:
    5/30/13 10:03:28.001 AM SecurityAgent[147]: User info context values set for r364epson
    Which log in the Server Admin app would errors like this be likely to be logged in?

  • Images/PDFs in another server

    Can I specify a URL (http://someserver.com/image.gif) as a place holder for the location of a PDF or image file?  I believe that MDM stores a local copy of the file in the server.  This is not desirable in my project because the latest version of the files will be stored in another server.  The desired behavior is that MDM will grab the most up-to-date version from the image server and display it on the screen, even the thumbnails.
    I tested the "Link to original", as opposed to "store in repository", option when added the image/PDF file.  When I deleted the original file that was on my PC, MDM still was able to display the image that I originally loaded.  Hence, my suspicion that MDM stores a local copy in the server.
    Regards,
    Simon

    Hi Simon,
    Currently MDM supports one of two approaches:
    1.  Loading images into the repository (preferred)
    2.  Linking to images stored on a file system (no http-driven access).
    Your requirement is noted and others have requested it but no current plans for this functionality for a variety of reasons (many of them related to image management/manipulation capabilities built into MDM's Image Manager application)
    Glen

  • Application launches fail after wake up from sleep when switching from one open directory to another

    I take my MacBook Pro back and forth from home to work.  Open Directory is set up at both locations running on Snow Leopard server.  These two locations are entirely separate domains and IP networks.  The only thing that is the same is my username and password, which is the same in both locations.
    If I put my machine to sleep in one location and move to the other location and wake it up, I can usually launch one application, then no other applications launch and the machine is pretty much frozen up except for mouse cursor movement.  Using command-shift-escape and relaunching the finder doesn't help.
    It is as if the launch daemon has been made inoperative.  Apps just sit and bounce.
    Should one be able to log in one one network with open directory. Close all applications, move to an entirely different network, and wake up from sleep and continue working?  The login/password is identical on both open directory setups.
    Both home and work are set up so the users can "travel" and the machines are not "bound" to the open directory server.
    I've started using the "other" login box to login in which I think keeps the machine more independent of open directory and that seems to work better for moving between networks.
    Any ideas and/or comment welcome.
    (my DNS seems fine in both environments.  running changeip gets "success" in both places)

    After reading another post that popped up under "More Like This" after I posted this I may have found at least a temporary fix.  Unplugging and reseating the MDP adapter in the MacPro didn't accomplish anything but unplugging/reseating the HDMI plug in the Viewsonic brought it back to life.
    I guess I can live with this but it would be nice knowing that there's a more permanent fix for this.

Maybe you are looking for

  • Applet does not run in Browser

    Iam using Windows XP and IE 6.0. Applets do not run in my browser. Hovering the cursor where the applet should be in the browser, I get a Class not found message. Setting the CLASSPATH variable did not help. Any suggestions?

  • Personal File Sharing failure between Leopard MBP and Tiger iMac

    Hi, I am attempting to give the iMac access to files on the Leopard using Personal File Sharing. Personal File Sharing is turned on on the MBP. The firewall on the MBP has been variously set for Essential Services Only and turned off. The firewall on

  • Enter a period   error key: RFC_ERROR_SYSTEM

    Hi Experts, Please help with this issue. while trying to save travel request, the next screen appears is settlement of Trip data with the Other Period Radio button active. Is it possible to default the current period radio button or not to go to the

  • If I purchase photoshop download do I need an internet connection to use photoshop or just for download?

    I am thinking of purchasing photoshop and since it is only available now by download I would like to know if I just need an internet connection for download or would I need it for download and when I decide to use it?

  • Creating I-Doc from F110

    I want to create check information as an I-doc from F110. I have run F110, successfully, it gave me that 1 document is generated and 1 is completed. Now I want to create an I-doc which contains all the check information and send it to an external sys