Restricting allowed network logins

I'm hoping to find a way to restrict newtork logins.
I have an environment with both openldap on linux, and Active Directory directories available to authenticate against. These directories are synced, so it doesn't matter which directory service is used.
I have successfully authenticated using network logins with both of these directories.
My problem is that I have a group of semi-public computers, and I would like to limit the allowed network logins to a small list of users, rather than the whole directory.
On linux, I was able to do this with a hodgepodge of pam_ldap configurations, allowing login only if there was a local home directory. So I could manually add a user locally with their netowrk uid, but they would use thier network password.
Is there a method to do this with OS X? To restrict allowed network logins to a list of uids?

I tried the osascript line and killall -HUP loginwindow in a loginHook script without success.
If I run the loginHook script from the terminal..
"sudo /Library/Management/get-user-info.sh nghani"
it works fine but when I login as nghani..
no osascript and
no restricted login
From the debug file I know my script is running from the LoginHook and the logic is correct.
Am I missing something?
Please help!!!!
/Library/Management/debug:
nghani is not ics or root
nghani user is not in group
button returned:OK
kill -HUP 600
nghani is not ics or root
nghani user is not in group
root is ics or root
/Library/Management/get-user-info.sh:
#!/bin/sh
shortname=$1
if [ "${shortname}" = "ics" -o "${shortname}" = "root" ]
then
# local admin accounts do nothing
echo "${shortname} is ics or root" >> /Library/Management/debug
exit
else
echo "${shortname} is not ics or root" >> /Library/Management/debug
# do ldap search to get email addresses + fullname + groups
ldapsearch -H ldaps://ldapnw1.instruct.langara.bc.ca -D "cn=MacProxy,ou=ProxyUsers,o=Aves" -w `cat MacProxyPassword` -b "ou=Users,o=Aves" -s sub -x cn=${shortname} cn mail fullname groupMembership > /Library/Management/Thunderbird/user-info
# UGLabsAll
if [ -n "`cat /Library/Management/Thunderbird/user-info | grep groupMembership: | grep -e 'UGLabsMac'`" ]
then
# user is a member of the required group.
echo "${shortname} user is in group" >> /Library/Management/debug
else
# user is not in the right group LOGOUT!
echo "${shortname} user is not in group" >> /Library/Management/debug
# tell user
osascript -e 'tell application "SystemUIServer"' -e 'display dialog "You are not permitted to use this computer. You will now be logged out." buttons {"OK"} default button "OK"' -e 'end tell' >> /Library/Management/debug
# logout
/usr/bin/killall -v -HUP loginwindow 1>> /Library/Management/debug 2>> /Library/Management/debug
fi
fi
G5 Tower 1.8GHz Mac OS X (10.4.4)

Similar Messages

  • Macbook bound to AD won't allow network login or new local account creation

    As the title states I am having an issue related to a macbook pro that is bound to active directory. The only option we tweak when binding the macs to AD is that we opt to "create mobile account" option under directory utility.
    It also seems that while we can login through the local admin account, new local accounts cannot be created (the account creation window hangs when you create account).
    Any help would be appreciated

    Hi
    To successfully bind a mac workstation to Active Directory certain things need to be in place:
    DNS has to be fully resolving on both pointers. This is done on the PDC or whatever server is the designated DNS Server.
    Date and Time settings need to be adjusted to reflect whatever is designated as the NTP Server in the AD environment. Adjust the Date & Time Preferences Pane and find out from the Windows Network Administrator what the NTP Server IP address is.
    You must use account credentials that has authority for the AD Domain. If you're trying to use your own account it may be restricted in what it can do? A domain account has special privileges not usually accorded to ordinary user accounts.
    This assumes you're (a) not the Active Directory Network Administrator and (b) you're using the Active Directory plug-in the login options section of the Accounts Preferences Pane. It's a good idea to click the "Open Directory Utility" button when binding to Active Directory. It's also a good idea to access the Advanced Section once the Utility has opened.
    If this is failing at the bind stage then perhaps you should review the details you've been given when binding to AD? It may be worthwhile to clear the workstation from the Computer OU before you try again?
    The above is not an exhaustive list but should help?
    Tony

  • Login Options: Where is "Allow network users" stored?

    Hi all
    If I enable "Allow network users to login to this computer" in SystemPreferences / Accounts / Login Options - anyone knows where that gets stored?
    I searched in the /Local/Default/ directory and in /Library/Preferences, but couldn't find anything. I'd like to write a script to modify access for network users; no problems in adding and deleting users from the list, but I can't turn on and off general access...
    Thanks, Tina

    I have set up a Mac OS X Server for Open Directory but I do not seet the additional option to allow network users to log in on a Mac OS X 10.4 client.
    This may be one of the reasons I cannot login with networks accounts.
    Unfortunately, I also cannot login using network accounts to the server which does have the network users option checked.
    I have the Mac OS X Server set up to be a LAN DNS server, which worked fine before I connected the second ethernet interface to the Internet. Now changeip -checkhostname insists that the Web address of the server should be the address of the hostname when it MUST be the LAN IP address to work properly. I can find no one to login to either of these machines as a network users, even though I can find the users through the Address Book, indicating that the Open Directory connection is properly configured and even though I can ping by name through the LAN which indicated DNS is set up properly.

  • Allow network users to login at login window option missing

    I hope someone can shed some light on this.
    I have bound a 10.6.2 machine to a Windows 2003 domain successfully. However, the checkbox to "allow network users to login at login window" is missing completely. There's a blank space. I've looked at a few other machines that haven't been joined to the domain and the option is missing from there as well.
    Am I missing something simple? Did I miss something during the OS install? This is a fresh 10.6.2 install.
    Any help would be greatly appreciated as this is keeping us from allowing domain users to log on. Thanks in advance.

    I installed ADmitMac and the option shows up. I removed it and the option goes away. There's obviously a flag being set somewhere. Any thoughts?

  • Lion Server Setup (Network Login/Mobile Account and more...)

    Hardware:
         Mac mini Intel Core i7, 2 GHz, 8 GB memory (Server)     x 1
         iMac 21.5" 2.8GHz Intel Core i7, 12 GB memory (Workstation)     x 6
    Operating System:
        Mac OS X Server Lion 10.7.4 (11E53)
         Mac OS X Lion 10.7.4 (11E53)
    Relevant Software:
         Server.app Version 10.7.4 (1.4.3)
         Workgroup Manager Version 10.7 (400.3)
         Server Admin Version 10.7 (355)
    So my head's swimming with "I dunno's" and I've been perusing probably all the wrong threads trying not to sound like a noob and find the literature that will finally lead me to a solution.  This is my first rodeo so make no assumptions about my experience (maybe).
    Short Version
    I can't login network users.  I get an error "You are unable to log in to the user account "<%short_name%>" at this time.  Logging in using >console tells me this No home directory: <path to home directory>    i.e. /Network/Servers/department.domain.com/Department/Accounts/bbunny
    If anyone can point me where to read, I will do so.
    Perhaps a longer discussion on how to verify that the proper permissions exist on the share/home directory in question and what those would be.
    More detail...
    I want to setup a Mac Mini server to have network login accounts stored on the 2nd data volume in a directory we shall call Accounts*.  Here all the "network users/logins" have their home directories, so that when they login at the workstation the idea is the workstation will sync their account and allow them to login, if the server is not available, the hope is I can configure it to allow them to login if they've logged in before and the files will sync when they are able. That being the ideal, I get the impression that for best practices, Apple is discouraging the use of mobile accounts that use Home Sync perhaps because it's reliability has been iffy, please advise.  A windows user might think of this as "roaming profiles" but, if I understand it, its a little more than that.
    Note, I do not want to login to the server and actively work on that network share, I want the account to be local and sync'd as needed.  But I want the user to be able to sit at any of the 6 other workstations and see the same documents, emails etc.  Obviously if the server is down, it won't be possible to authenticate, but I think it should have cached credentials that should allow the user to login if the server is down and still go about their work.
    This is the small picture...there is a larger picture that involves, parallel virtual machines of Windows Server 2008 R2 on server and and Windows 7 on the client, ical, ichat and perhaps wiki's.
    I apologize for the roughness of this question, in the interest of brevity, I have plenty of problems that led me here that I can expound upon if asked.
    Also a silly question someone might know the answer too, Why does the login payload settings that I have pushed to a workstation device, sometimes vanish inconsistently upon logout? 

    Ok, Some Good news and clearer understanding to disseminate in this post I hope it helps
    "the Universe" so I am posting it here in my "ever-the-noob" blog on apple forums.
    Problem
    What do you do when you get an error when logging into a mobile account setup?
    One symptom would be the error message below...
         "You are unable to log in to the user account "<%short_name%>" at this time.
    Logging in using >console  You get the message…
         "No home directory: <path to home directory>"
         or
         "You are unable to log in to the user account "<%short_name%>" at this time. 
         Logging in using >console tells me this No home directory: <path to home directory>
    Solution
    Do the check list…
    Short Version
    Sever Admin.app > Access (Key Component)
    Check Permissions on directories for your file shares. 
    (The reason stuff doesn't work especially when you're rebuilding/recovering a server)
    File sharing setup (Turned ON, Home sharing Enabled)
    Directory Utility > Directory Editor or dscl 
    ( Do not underestimate the importance of this part!!!!
    Use white-gloves when you're handling it though!!! )
    Workgroup Manager
    (You're poopy "main" interface that really is a "window", not a "door", but maybe Apple likes to do things "Dukes of Hazard" style?)
    Long Version
    Check Sever Admin.app > Access
    Make sure that your user has the "Proper" access.  For me I created a test user from Server.app and saw what access he had as a way to "check myself for a properly created users" and because I think one is kind of on his/her own using WGM and duplicated the same access. (I was a little neater, though and did it with a group, not individual users, that would have been a mess!)
    Server Admin.app > Access
    Click the "+" sign, sort by UID and Add the imported users  to the following Services…
    ( You can use a group, but understand when Server.app creates users they get added
    individually to each of these groups. )
    Address Book
    AFP
    iCal
    iChat
    Mail
    Profile Manager
    SMB
    VPN
    Check Permissions on directories for your file shares. 
              (That's an understatement) I could go in depth about all the crap I had to read about, I still
              know I am missing a chunk of tech brain when it comes to the particulars. Basically, I boil
              it down to this…
              Permissions require thinking about things first with regards to POSIX permissions... good
              ole ls, chmod, chgrp, chown to the rescue with ugo permissions or the old 755, 600 etc
              stuff.
              Apple's file-sharing access uses this as a starting point to see what the user is allowed to
              access.
              I also needed to use chflags once to unhide a file that I mucked around with using xattr. 
              I still haven't figured out why folders can lose their triangles, but I didn't find out if you cp or
              move them from terminal, the triangles come back in the moved or copied directory.  For a
              minute I thought it was because cp alone doesn't preserve flag attributes, but mv actually
              works by doing a cp that preserves the flags, unless it's a bug.  I dunno.
              This helped me get my file visible again...
              chflags hidden path_to_file
              chflags nohidden path_to_file
              Read up on those manuals, if you're not a terminal type go to apples website
              http://developer.apple.com/library/mac/#documentation/Darwin/Reference/ManPages/
              or download...
              http://www.bruji.com/bwana/ I thought that was cool.
              or if you prefer to read the manual in pdf try…
      man -t sharing | pstopdf -i -o ./Desktop/Sharing\ Manual.pdf
              man -t chown | pstopdf -i -o ./Desktop/CHOWN\ Manual.pdf
              man -t chmod | pstopdf -i -o ./Desktop/CHMOD\ Manual.pdf
              man -t chgrp | pstopdf -i -o ./Desktop/CHGRP\ Manual.pdf
              My basic guideline was avoid using ACLs if at all possible, if you try to use them, things
              can get crazy complicated, take notes and plan, baby. If you read above, opening up
              permissions wide is wrong though.  You would restrict permissions tightly to begin with and
              then place ACE (Access Control Entries) to specifically target the rights you want to enable.
              Here's one that's obviously a novice attempt to do this, but since the novice is the only one
              speaking…. here it is, Universe… >:P
              sudo chmod -R +ai "admin allow read,write,delete,file_inherit,directory_inherit,search,list" Department/
              That allowed my admin to do all the things a normal user could do so far… It fixed things for
              my admin, which made me happy.  I really hate having to authenticate or sudo just to see
              the contents of a nested directory.  I could explain it, and even give a few notes on why its
              probably overkill, but I will attempt to look less stupid till "poked".
              There's another command line utility I STILL haven't read, which may bear mentioning
              because…well I haven't read it.  umask (see wikipedia or unix.com)…I worked past my
              problems without going into it so far, but obviously it's there, and it serves a purpose.
              I also found this article helpful…and educational.  :O
              http://www.bresink.de/osx/300321023/Docs-en/pgs/ACL.html
              (          Its enlightening to hear the air whistling between a developer/coder's ears, still it's
                        apparent he has a clear idea what's going on.
                        Ever wonder why when you use get info to check or assign permissions it kind of
                        flakes out and doesn't take?  Read this article!          )
              Second, if you can't obtain the "specific" permissions you need with POSIX, chmod also
              can set the 2nd category of permissions, which windows users may be familiar with
              Access Control Lists (ACLs) and here you get some really fine granularity...messy stuff. 
              All in all, if I felt I could guide you through these murky waters, I would, but I think I'll let
              the professionals weigh in on that one and cut my wall-of-text to ribbons.
              To heuristically check I would connect from a client as one or two of my users and see what
              folders I could mount as a share, armored with an understanding of what ls -le@O * showed
              me in Terminal.
    3.)           File sharing setup (Turned ON, Home sharing Enabled)
              Here is an example of using command line sharing utility where each share is properly
              labeled (that took a bit for me to figure out) still this share only enables the AFP share as
              you can see from my flags.
      sudo sharing -a /Volumes/Hard\ Drive/Department/Database -A Database-afp -F Database-ftp -S Database-smb -n Database -s 100 -g 000 -i 10
              Then you do a sudo sharing -l and get back what you just did…
                                              List of Share Points
              name:                    Database
              path:                    /Volumes/Hard Drive/Department/Database
                        afp:          {
                        name:          Database-afp
                        shared:          1
                        guest access:          0
                        inherit perms:          1
                        ftp:          {
                        name:          Database-ftp
                        shared:          0
                        guest access:          0
                        smb:          {
                        name:          Database-smb
                        shared:          0
                        guest access:          0
              If you mess up the sharing command, you may not be paying attention (I wasn't) but there
              are a lot of defaults that Apple will just assume you meant to do anyway and it won't read
              any of your flags, you have to get it right or the flags will be defaulted. 
              (          Basically I could tell I was bombing it for one, I explicitly only wanted afp working, but
                        the default was afp and smb.  So each time I ran sudo sharing -l after I shot my sharing
                        command…back would come smb shared: 1 and I knew that wasn't right.  Also my
                        custom names were defaulting to the name of the directory not the name I had
                        specified.           )
              I like to know what protocol my share is over so when it doesn't work, I know which protocol's
              are connecting. It's not full-proof, but it's a bookmark.  I wish the network browser would
              identify the protocol that its available listed shares are using, because small visual queues
              like that help when you're trying to see what works.  Maybe that's something I should
              investigate via the command line?
              As a note about reading forums, I discovered using command line that "\" is kind of like a
              way of going to next line neatly with long commands…."\ " is a way to insert a space. As you
              can see above where I have a volume with a space in it. 
              Removing shares was a little trickier though, sharing -r Share\ With-space didn't work….I
              had to enclose it in quotes and do "Share With-space" instead. So nooby beware!
              (          *nix users are now rolling their eyes at this tip.          )
              I wasn't sure how you enabled a share for home directories from the command line, maybe its
              in the manual, but I was up to my eyeballs in manuals already so I haven't gone back to
              revisit this question since my work around was to go to Server.app and verify that what I set
              up in the sharing in terminal was being reflected in the gui…sort of my own MVC
              (model-view-controller) check.
    4.)           Directory Utility > Directory Editor or dscl 
      Make sure what you see in WGM and Server.app are reflected here….to that question let's
              take a journey where I did some exploring about that.
      Ever really wonder "WHY CAN"T I REMOVE AN OLD HOME DIRECTORY SHARE?!!!"
              Ah, then you will  - LOVE -  this tip…
              (          Provided my testing or yours, later, doesn't prove that in my ignorance I've broken
                        Open Directory. Remember, WHITEGLOVES!!!! but here we get a little dirty.  I think of
                        OD as Apple's Registry, but that's not what it is at all. However, you as the user do have
                        to "****" around in it from time to time.          )
              I scoured the forums and everyone was saying things like "You have to change your server
              role" etc. which seemed a little bit dumb to me (dumb because you're pushing views around
              not "controlling"), and well, yea, that share that I couldn't modify or delete was REALLY
              bugging me.
              Now hmm… Before you do ANYTHING, how do you try to not hurt yourself…in Windows you
              can make a Registry Backup….(yea bad analogy)  In Server Admin.app you can go to your Open
              Directory Service > Archive and Choose a place to Archive your information. (Figure this out by
              yourself, this is getting long…sheesh! It's easy. Restoring is just as easy and painless.)
      Before we can remove the entry we "SEE" in WGM we should make sure no
              one has it selected so as not to "corrupt" the OD db, so in WGM first before going to Directory
              Utility set the Home directory to "None".  (We need to remember to set this to a correct share
              later….Mental Note!!!)
              Now Open Directory Utility
              Method 1
              System Preferences > Users & Groups > Login Options
              Click the Lock to make changes…
              Authenticate -> click "OK"          (do I REALLY have to step-by-step this?)
              Network Account Sever: • Local Server - click "Edit" button here.
              Open Directory Utility > Directory Editor
              (          Wow, did Apple hire someone from Microsoft?  You'ld think with all their research in to
                        Human Interface Design that's WAY too many clicks to get to something you need.          )
              or
              Method 2 (It's good to know about this directory, neat-o speed-o app's hidden here.)
              Use "Go to Folder" Under Finder > Go > Go to Folder...
      ⇧⌘G /System/Library/CoreServices/ 
              Click "OK"
              and Double click Directory Utility.app
              or
              Method 3
              Terminal
              open /System/Library/CoreServices/Directory\ Utility.app/
              Now From the Directory Editor Pane you will see a Pop-up menu Labeled "Viewing"
              You should glance through this and get to know it.  You should use it to see what
              information is really being stored about your Users, Groups, Mounts…
              We are interested in Mounts, which is where we want to go…and there is the pesky
              mount that you will see reflected in WGM.
              Authenticate, and delete the bugger.
              Quit WGM and restart it.  Voila, bad share is GONE!!!!!
              a.)          First select all my users
              b.)           Then I clicked on the "+" and added the correct share
                        (          Remember, I only showed you the first one we created, this is another and
                                  for THIS one you HAVE to go into Server.app and verify that it is set to be
                                  available for Home Directories in this case for AFP.          )
                        For the home directory entry you do this...
                        afp://computer.domain.com/Accounts-afp
                        %short_name%
                        /Network/Servers/computer.domain.com/Volumes/Hard\ Drive/Department/Accounts/%short_name%
      %short_name% is a wild card for the short name there are other wild cards check out Apple's
                        Documentation on them.  I lost the link   sorry \<shrug\>
              Interesting dscl commands…(check it out in command line form and compare side by side with
              what you see in the GUI Directory Utility)
              dscl . list /users
              dscl . list /groups
              If you want to output information about each user, though, use readall:
              dscl . readall /users
              dscl . readall /groups
              And if you need to programatically parse said information, use -plist to make your life easier:
              dscl -plist . readall /users
              dscl -plist . readall /groups
              This made a little more direct sense to me, language wise…but fyi "." is kind of a wild card I think so the first
              commands I think look in ALL directories local, Search, LDAP whatever you have.  The command here
              corresponds to the Entry from the Pop-up menu "…in node > Blah…" see GUI of Directory Utility to confirm.
              dscl /LDAPv3/127.0.0.1 -list /Users
              dscl /Local/Default -list /Users
    5.)          Workgroup Manager
              Remember this is a utility that is not long for this world.  Apple's Mountain Lion is rumored to fully
              replace it, why? Yea, Apple's making a go at MDM (Mobile Device Management) and somehow
              desktop computers are being pulled/dragged along for the ride.  I have plenty of issues with
              Profile Manager, but I'll likely revisit it in a couple of months and see where we stand.
              Anyway, treat this baby like the bottom rung, because, well it is built like you start your
              foundation here, but it's just a viewer with controlling "tweaks".  Use the other areas to get a solid
              grasp of what is actually going on.  Server.app is where you should create accounts you can
              feel are safe.  When you create accounts in WGM, you are responsible for making sure they
              have the appropriate EVERYTHING.
    This list is by no means complete, but these are the areas this noob is or was prepared to talk about.
    Good night for now.  Enjoy climbing my wall of text, and yea sorry about that.  :O Run for you lives!!!!
      - Signed Shadowwraith

  • Not allow simultaneous login on managed computers using profile mangaer

    Does any one knows how to not allow simultaneous login on managed computers using Profile Manager instead of Workgroup Manager?
    Thanks in advanced

    Hi Folks
    First - thanks for your help.
    Closing this out - here is what I learned:
    1) Needed to ensure my server was Kerberised and that Kerebos was running correctly
    2) Local users have precedence over network so I need to ensure I don't use the same short name. While using the "id" command you may be able to see the network user ID, the local of the same name appears to take precedence.
    3) Using the "kinit" command useful for confirming Kerebos is working correctly
    4) Home directories created - had already done this but what finally got this working was stopping and restarting AFP Service.
    So was able to successfully login to Mac Client using OD username and password - it mounted the network home share just fine on the client, loaded preferences etc.
    Now on to create network users with Mobile Accounts for my laptop users - wish me luck

  • Restricting number of login made to Enterprise portal

    Hai,
    Is there any way to restrict the number of logins made by a user using a single user to portal. That is a should not be allowed to login using five browser at a same time. Please let me know how to do it.
    Thanks & Regards,
    H.K.Hayath Basha.

    Hi.
    You should validate user only after his successful authentication.
    Once the credentials are valid thenafter have to check whether the user has logged in already or not?
    So i think .jsp page is not the correct place, u can modify masthead.par file, do check there if the user logged in already and then redirect him to the logon page by invalidating his session object.
    process should looks like :
    enter username / password --> valid --> goes to masthead.par file --> check for duplicate login --> if yes, logout else continue.
    pls : Award points for helpful answers.
    Thanks
    MMK

  • How to get Network logins shown as a list with photos!

    A long time ago, some one posted a tip here on how to set this up for Panther Server (that is to be able to view the list of network login accounts as a scrolling list with different pictures [photos] for each user).
    I myself was able to follow the instructions and get it working in Panther.
    Later someone else said it no longer worked using Tiger Server.
    A while I go I did set this up (again) using Tiger Server and therefore I can confirm it does still work. (Although I am only now getting round to letting anyone else know.)
    If anyone is interested I can help you through the process.
    In theory the same pictures can be used in other places as well, for example in Apple AddressBook (works for me as well). Its a shame Apple broke MailPictures in Tiger though. See http://www.nikwest.de/Software/
    Despite what the above website implies, it DOES NOT work properly in Mail in Tiger (although the Panther version does work in Panther Client).
    PS. I did get an equivalent to work in Mozilla Thunderbird 1.5 in Tiger.

    Unfortunately it doesn't work. @List requires members names so I can't provide a member set as an argument :(^^^Are you sure? Take a look at the below example from the Tech Ref. That sure looks like @LANCESTORS and @LIST is accepting more than just member names.
    FIX(@LANCESTORS(@LIST(@ATTRIBUTE(Caffeinated_True),@ATTRIBUTE(Ounces_12),"200-40")))Also note this:
    If the @LANCESTORS function is used alone (not within a FIX statement), you must use the @LIST function and specify member names. So you DO have to use @LIST if @LANCESTORS is to be used to do an aggregation. Or so it appears.
    Regards,
    Cameron Lackpour

  • Network logins not working with 10.7 and 10.8 clients

    Hi
    I have Snow Leopard Server (10.6.8)  running on a Mac Mini for the past 3 years. The client Macs were all running Snow Leopard and could happily do network logins. I recently upgraded my client Macs to 10.7 and 10.8.Now they cannot login via Network logins. Only via the Other selection. Network logins produces the Error occured dialog box. Once users do a local login, they have access to all server services (file sharing, calendar, messaging, contacts, etc.)
    The server is setup as a OD Master with Kerberos. The changeip check is all good. The DNS is working. I have made no changes to the server. Only the clients were upgraded from Snow Leopard.
    I have read a lot about similar problems but still haven't solved this problem.
    I hope someone can help.
    Kind regards
    Michael

    Hi all
    I solved this annoying issue
    It was an Open Directory issue. If you have upgraded clients to 10.7 or 10.8 from 10.6, the OD Master passwords are incompatible with 10.7 or 10.8.
    The fix is simple.
    1. Stop AFP file shares
    2. Export Users, Groups and Computers from Workgroup Manager then quit the the Workgroup Manager
    3. Demote the OD Master to Standalone
    4. Promote the Standalone OD to a Master OD,
    5. Reimport the Users, Groups and Computers back into Workgroup Manager
    6. Reset all passwords and home folders
    7. Rebind all clients computers
    That's it.
    I hope this helps someone.
    Cheers
    Michael

  • How do I allow network volumes with the latest iMovie 10.0?

    How do I allow network volumes with the latest iMovie 10.0? The old "defaults write -app iMovie allowNV -bool true" doesn't work anymore.

    So, apparently, while iMovie is open, I have to EJECT the Net Drive.  When I remount it, iMovie immediately picks it up.
    That said... the update leaves much to be desired.  Many of the Projects have unlinked video (even though the same update using a Firewire HD shows the video linked).
    Message was edited by: BradNet

  • Allow anonymous login

    Is it possible to allow anonymous login but disallow anonymous searching.
    If its possible some direction how to achieve it.
    Appreciate any input.
    Thank you

    Rather than adding a Deny ACI, you should search for the ACI that is granting Compare, Search rights to anonymous users, and remove the operation that you do not want to grant (compare in the example mentioned).
    Example : Transform
    aci: (target ="ldap:///dc=example,dc=com")(targetattr !="userPassword")(version 3.0;acl "Anonymous read-search access";allow (read, search, compare)(userdn = "ldap:///anyone");)
    Into:
    aci: (target ="ldap:///dc=example,dc=com")(targetattr !="userPassword")(version 3.0;acl "Anonymous read-search access, but no compare";allow (read, search)(userdn = "ldap:///anyone");)
    Ludo

  • Sudden problems with network logins

    Hello,
    I've suddenly started experiencing an issue preventing normal network logins. Logging in on client machines gives "The home folder for user "xxxxxx" is not located in the usual place or cannot be accessed" This occurs on every client machine - all are running Tiger. The server is running Leopard. This occurs with user home accounts located on the OD master, as well as the OD replica. The automount record appears to be correct, "sudo sharing -l" reports correct information, AFP logs show normal logins, as does all open directory logs. I can mount home folders manually (apple + K method), and permissions appear to be correct on home folders.
    I've discovered that attempting to change directories to /Network/Servers gives an authentication failure, and, for extra fun, I opened a terminal window on the ODM, su'd to an open directory user (who had a home directory on the ODR)and poked around a bit only to discover that ls -l showed this user as owning everything, and everything had no permissions whatsoever.
    Has anyone seen this behavior? Does anyone have any ideas?
    Thank you!
    Colin

    Hello,
    I just upgraded a complete company from 10.4.11 to 10.5.6, about 25 machines and exactly 2 of them show that behaviour. The network accoutns are all ok, you con use them on other machines. I can confirm that /Network/Servers is not a correct path on both of the bad machines.
    Ther is NO issue with time synchronization, access rights or whatever.
    Funny, the REAL interesting questions seem to go unanswered all the time...
    Can anybody give me a hint (other than "archive and install")?
    Regards, Lucian

  • 2630. java applications. Allow network access?

    when entering some java application on nokia 2630 ,for example google maps, it asks:
    "Allow network access? the application is not from a trusted supplier" for three times. On the fourth time: "try again later or try to install new version".
    Some other applications are working allmost properly... but they use to ask every 5-10 seconds the same question: "Allow network access? The application is not..."
    And some applications are working correctly. miniopera and jimm.
    So, the problem is not in gprs settings.
    What can i do with this problem?

    You can either try to get hold of a trusted build of the application you want to run or you can change the Application access setting. When you have an application selected, click Option then Application Access and set the Network access Ask first time only.
    Knowledge should be your Advisor when you need help.
    1610»2110»8110»5110»3310»6210»7250i»6220»6230»6230i»6233
    Love me or hate me, its still an obsession. Love me or hate me, that is the question. If you love me then Thank you! If you hate me then ...

  • When starting up a Mountain Lion iMac, it takes along time before network logins are available.

    When starting up a Mountain Lion iMac, it takes along time before network logins are available. There seems to be a huge delay getting the network up and running, and I'm not sure why. This isn't an issue for identical iMacs running Snow Leopard.
    If I login with a local account, I see the ethernet registered as disconnected for at least a minute, then it pops up. If I switch to Snow Leopard, using the exact same hardware, network cable, jack, etc, it's instant.
    Has anybody encountered anything similar?

    Fulcrum Media wrote:
    Has anybody encountered anything similar?
    No. I have a rMBP and a Mac Mini on a home LAN. The Mac Mini is connected via ethernet and the rMBP is WiFi. Both connect instantly to my network. Both are running OS X Mountain Lion 10.8.2.

  • Unwanted Network Login Popup

    After default Companion installation (and upgrade to 1.6, all on Windows 2000), I've got an unwanted popup Network Login screen even before I can get to the:
    http://machine_name:7777/pls/htmldb
    I can satisfy this additional login popup by providing a valid database credentials (e.g. system/manager), however it's annoying to have unwanted login popup that does not serve any purpose. Thanks. VR

    hi vr--
    there's more on mod_plsql DAD configuration in section/chapter 4 of the htmldb 1.6 installation guide, but the install you describe places your dad named "htmldb" in the file $ORACLE_COMP_CD_HOME/Apache/modplsql/conf/marvel.conf. as scott suggested, it sounds as if you don't have a valid username/password in that DAD. you'd want to put htmldb_public_user in for that user and his valid password, as well. check the install guide if then you need to obfuscate that password.
    hope this helps,
    raj

Maybe you are looking for

  • Sign HTTP request in interactive PDF form

    I know that is possible to send HTTP request from PDF form. I know that is possible to sign whole PDF and submit it. But I want to sign some XML and send it from PDF as HTTP request. Is it possible? Thanks in advance Denis

  • Some valuable inputs required on SAP Netweaver connection in xcelsius

    Hi Gurus, i am going to create the dashboard on top of SAP Query in xcelsius. can someone share some best practices on that. I have a requirement where the user should be prompted for the date and year variable.i need the help on variables as well. i

  • Brushes Still Cause Freeze Up

    I posted last week about this same problem. I have 11k images in library, the image I'm working on is RAW and 11mb in size. Before making any other changes to the image I make a curves adjustment via curves brick and then click the gear symbol to bru

  • Flash on mac os 10.3.9 flash player being prohibited by browser security settings how do i fix this

    this is the message i get "This content requires the Adobe Flash Player. It either has not been installed yet or is prohibited by your browser security settings. Either click here to get Flash or loosen your browser security restrictions." how do i l

  • Generating repeating XML aggregate using OSB

    Hi all, Following is my scenario:- I get an XML request as: <Request> <aaa>1234</aaa> <bbb>asdf</bbb> <ccc>as123</ccc> <ddd></ddd> </Request> I want to transform it into: <NewRequest> <test data="aaa" flag="true"> <detail>1234</detail> <test data="bb