Server.app 3.2.1 Failure/Issue summary

Hello everybody,
since my Server broken down with the current update I read about so many problems with Server 3.2.1.
I like to give everybody a list of discussed Problems. I hope Apple will fix all this issues soon as possible:
1. ProfileManager migration failed, 2. cant login to ProfileManager web interface (solved)
Solution: Reset history of enrollment profile and drop AppleTV's from database
Details:Server 3.2.1 update fail
Server 3.2.1 (10.9.5) – Postgres won't start (solved)
All Device to User Associations gone (NOT solved)
Calendar and address book service not working (helpful advice)Re: Cannot connect to calendar or addressbook server HTTPChannel unhandled error
UTF-8 information in Profiles scrambled (NOT solved)
Check second post on:Re: Software update says 3.2.1 installed but server info still says 3.1.2?
Re: Re: Re: Server 3.2.1 update fail
1. OpenDirectory not working, 2. Profiles not signed (NOT solved)
Re: Re: Server 3.2.1 update fail
Open Directory Service not working since Server 3.2.1
Just the issues I found ... is any body out there who has updated his server without any problems?

Thank you.
You are completely right and my test lab included only iOS 8 devices.
What I missed - the "rename" functionality presents only for supervised devices.
When my iPhone was supervised and enrolled to Profile Manager with Apple Configurator I found rename option under the gear/action menu.

Similar Messages

  • Server.app: Users button ( + / -) are disabled of a replica server

    Hi everybody,
    After upgrade the server to 10.9.5 and server app 3.2.1 version, it has been crashing during the importation of users into server app using a text file. At the beginning everything was ok with a text file where there were only one user, but when I tried to do the same thing with all users file, the progress bar was freeze and just after reopen server app the buttons + and - were disabled. We have 1 master than 5 replicas servers working with the same OS X and server app version and this particular issue is only here. There is a similar postBug: Manage +/- buttons "Users" and "Users' Groups" disabled in server.app  but this issue coming back again after the first importation (It doesn't matter if you are using a text file with 5, 20 o 100 users).
    Moreover, if I set it up as a master, everything is right so I was wondering if this new server app version cause this issue or if it is related to mavericks itself because we upgraded all servers two month ago.
    I'll appreciate every clue,
    Thanks

    This is a copy from Slapconfig.log. This start creating a replica and finish when it is destroyed. Between 21:39:39 ans 22:20:49 the server app crashed and nothing is reported with this service, after that, I destroyed the replica. The only problem that I see, is in times of each register, the real time was already 16:00 aprox. but It show 21:33 aprox, I don't now why and the others files are correct in time.
    2014-09-24 21:33:29 +0000 slapconfig -createreplica
    2014-09-24 21:33:30 +0000 1 Creating computer record for replica
    2014-09-24 21:38:38 +0000 command: /usr/sbin/slapconfig -delkeychain /LDAPv3/127.0.0.1 server_replica.domain.ca$
    2014-09-24 21:38:38 +0000 slapconfig -delkeychain
    2014-09-24 21:38:39 +0000 Added computer password to keychain
    2014-09-24 21:38:39 +0000 Adding ldap and host service principals
    2014-09-24 21:38:41 +0000 2 Creating ldap replicator user
    2014-09-24 21:38:41 +0000 _ldap_replicator exists from previous replica - migrating
    2014-09-24 21:38:41 +0000 ServerID for this replica 37
    2014-09-24 21:38:43 +0000 command: /usr/bin/sntp -s time.apple.com.
    2014-09-24 21:38:44 +0000 3 Updating local replica configuration
    2014-09-24 21:38:44 +0000 4 Gathering replication data from the master
    2014-09-24 21:38:44 +0000 5 Copying master database to new replica
    2014-09-24 21:38:44 +0000 Removed directory at path /var/db/openldap/openldap-data.
    2014-09-24 21:38:55 +0000 Starting LDAP server (slapd)
    2014-09-24 21:38:58 +0000 slapd started
    2014-09-24 21:38:58 +0000 Stopping LDAP server (slapd)
    2014-09-24 21:39:02 +0000 command: /usr/sbin/slaptest -f /etc/openldap/slapd.conf -F /etc/openldap/slapd.d
    2014-09-24 21:39:02 +0000 command: /usr/sbin/slapadd -c -w -l /var/db/openldap/openldap-data/backup.ldif
    2014-09-24 21:39:08 +0000 command: /usr/sbin/slapadd -c -w -b cn=authdata -l /var/db/openldap/authdata/authdata.ldif
    2014-09-24 21:39:09 +0000
    2014-09-24 21:39:09 +0000 542339fc slapd is running in import mode - only use if importing large data
      542339fd bdb_monitor_db_open: monitoring disabled; configure monitor database to enable
    2014-09-24 21:39:09 +0000 6 Starting new replica
    2014-09-24 21:39:09 +0000 Starting LDAP server (slapd)
    2014-09-24 21:39:09 +0000 slapd started
    2014-09-24 21:39:09 +0000 command: /usr/bin/ldapmodify -c -x -H ldapi://%2Fvar%2Frun%2Fldapi
    2014-09-24 21:39:09 +0000 command: /usr/bin/ldapsearch -x -LLL -H ldapi://%2Fvar%2Frun%2Fldapi -b cn=config -s base olcServerID
    2014-09-24 21:39:09 +0000 command: /usr/bin/ldapmodify -c -x -H ldapi://%2Fvar%2Frun%2Fldapi
    2014-09-24 21:39:09 +0000 Starting password server
    2014-09-24 21:39:15 +0000 7 Enabling local Kerberos server
    2014-09-24 21:39:15 +0000 Configuring Kerberos server, realm is servermaster.domain.CA
    2014-09-24 21:39:15 +0000 command: /usr/sbin/sso_util configure -x -k -r servermaster.domain.CA -f /LDAPv3/ldapi://%2Fvar%2Frun%2Fldapi -a diradmin -p **** -v 1 all
    2014-09-24 21:39:17 +0000 command: /usr/bin/ldapmodify -c -x -H ldapi://%2Fvar%2Frun%2Fldapi
    2014-09-24 21:39:17 +0000 Stopping LDAP server (slapd)
    2014-09-24 21:39:18 +0000 Starting LDAP server (slapd)
    2014-09-24 21:39:18 +0000 slapd started
    2014-09-24 21:39:19 +0000 8 Enabling syncprov overlay on the replica
    2014-09-24 21:39:19 +0000 command: /usr/bin/ldapsearch -x -LLL -H ldapi://%2Fvar%2Frun%2Fldapi -b cn=config objectClass=olcSyncProvConfig dn
    2014-09-24 21:39:19 +0000 command: /usr/bin/ldapmodify -c -x -H ldapi://%2Fvar%2Frun%2Fldapi
    2014-09-24 21:39:19 +0000 adding new entry "olcOverlay=syncprov,olcDatabase={1}bdb,cn=config"
    2014-09-24 21:39:19 +0000 command: /usr/bin/ldapmodify -c -x -H ldapi://%2Fvar%2Frun%2Fldapi
    2014-09-24 21:39:19 +0000 adding new entry "olcOverlay=syncprov,olcDatabase={2}bdb,cn=config"
    2014-09-24 21:39:19 +0000 9 Adding replica to master
    2014-09-24 21:39:19 +0000 Configuring multimaster for (server_replica.domain.ca) with ServerID (37)
    2014-09-24 21:39:19 +0000 Remote server (servermaster.domain.ca) ID: 1
    2014-09-24 21:39:19 +0000 command: /usr/bin/ldapsearch -x -LLL -H ldapi://%2Fvar%2Frun%2Fldapi -b dc=servermaster,dc=domain,dc=ca uid=_ldap_replicator dn
    2014-09-24 21:39:19 +0000 command: /usr/bin/ldapsearch -x -LLL -H ldapi://%2Fvar%2Frun%2Fldapi -b cn=config -s base olcServerID
    2014-09-24 21:39:19 +0000 command: /usr/bin/ldapsearch -x -LLL -H ldapi://%2Fvar%2Frun%2Fldapi -b cn=config objectClass=olcSyncProvConfig dn
    2014-09-24 21:39:20 +0000 default realm: servermaster.domain.CA
    2014-09-24 21:39:20 +0000 Configuring multimaster
    2014-09-24 21:39:20 +0000 command: /usr/bin/ldapsearch -x -LLL -H ldapi://%2Fvar%2Frun%2Fldapi -b cn=config -s base olcServerID
    2014-09-24 21:39:20 +0000 command: /usr/bin/ldapmodify -c -x -H ldapi://%2Fvar%2Frun%2Fldapi
    2014-09-24 21:39:20 +0000 modifying entry "cn=config"
      modifying entry "olcDatabase={1}bdb,cn=config"
      modifying entry "olcDatabase={1}bdb,cn=config"
      modifying entry "olcDatabase={2}bdb,cn=config"
      modifying entry "olcDatabase={2}bdb,cn=config"
    2014-09-24 21:39:20 +0000 Stopping LDAP server (slapd)
    2014-09-24 21:39:21 +0000 Starting LDAP server (slapd)
    2014-09-24 21:39:21 +0000 slapd started
    2014-09-24 21:39:21 +0000 Updating ldapreplicas on servermaster.domain.ca as diradmin
    2014-09-24 21:39:21 +0000 Updating ldapreplicas record
    2014-09-24 21:39:22 +0000 Updating ldapreplicas plist.
    2014-09-24 21:39:22 +0000 Binding to 127.0.0.1
    2014-09-24 21:39:27 +0000 command: /usr/bin/ldapadd -c -x -H ldapi://%2Fvar%2Frun%2Fldapi
    2014-09-24 21:39:33 +0000 Could not find root CA certificate in system keychain
    2014-09-24 21:39:39 +0000 IntermediateCA not configured as CA admin email not found.
    2014-09-24 21:39:39 +0000 Replica Creation successfully completed
    2014-09-24 22:20:49 +0000 slapconfig -destroyldapserver
    2014-09-24 22:20:49 +0000 Deleting Cert Authority related data
    2014-09-24 22:20:49 +0000 No intCAIdentity, not removing int CA from keychain
    2014-09-24 22:20:49 +0000 command: /bin/launchctl unload -w /System/Library/LaunchDaemons/com.apple.xscertd.plist
    2014-09-24 22:20:49 +0000 command: /bin/launchctl unload -w /System/Library/LaunchDaemons/com.apple.xscertd-helper.plist
    2014-09-24 22:20:49 +0000 command: /bin/launchctl unload -w /System/Library/LaunchDaemons/com.apple.xscertadmin.plist
    2014-09-24 22:20:49 +0000 Updating ldapreplicas on primary master
    2014-09-24 22:20:52 +0000 Removing self from the database
    2014-09-24 22:20:54 +0000 Stopping LDAP server (slapd)
    2014-09-24 22:21:24 +0000 Stopping password server
    2014-09-24 22:21:29 +0000 Removed all service principals from keytab for realm servermaster.domain.CA
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/__db.001.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/__db.002.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/__db.003.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/__db.004.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/__db.005.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/__db.006.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/altSecurityIdentities.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-computers.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-config-realname.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-generateduid.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-group-memberguid.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-group-nestedgroup.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-group-realname.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-hwuuid.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-locale-subnets.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-realname.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/apple-serviceslocator.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/c.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/cn.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/DB_CONFIG.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/dn2id.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/entryCSN.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/entryUUID.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/gidNumber.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/givenName.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/id2entry.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/ipHostNumber.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/l.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/log.0000000001.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/log.0000000002.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/log.0000000003.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/log.0000000004.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/log.0000000005.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/log.0000000006.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/log.0000000007.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/log.0000000008.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/macAddress.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/mail.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/memberUid.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/objectClass.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/ou.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/postalCode.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/sn.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/st.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/street.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/telephoneNumber.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/uid.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/openldap-data/uidNumber.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/__db.001.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/__db.002.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/__db.003.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/__db.004.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/__db.005.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/__db.006.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/alock.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/authdata.ldif.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/authGUID.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/DB_CONFIG.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/dn2id.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/draft-krbPrincipalAliases.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/draft-krbPrincipalName.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/entryCSN.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/entryUUID.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/id2entry.bdb.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/log.0000000001.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/openldap/authdata/objectClass.bdb.
    2014-09-24 22:21:29 +0000 Removed directory at path /var/db/openldap/authdata.
    2014-09-24 22:21:29 +0000 Removed file at path /etc/openldap/slapd_macosxserver.conf.
    2014-09-24 22:21:29 +0000 Removed file at path /etc/openldap/slapd.conf.
    2014-09-24 22:21:29 +0000 Removed file at path /etc/openldap/rootDSE.ldif.
    2014-09-24 22:21:29 +0000 Removed file at path /var/db/dslocal/nodes/Default/groups/com.apple.access_dsproxy.plist.
    2014-09-24 22:21:29 +0000 Removed directory at path /etc/openldap/slapd.d/cn=config.
    2014-09-24 22:21:29 +0000 Removed file at path /etc/openldap/slapd.d/cn=config.ldif.
    2014-09-24 22:21:29 +0000 Removed directory at path /etc/openldap/slapd.d.
    2014-09-24 22:21:29 +0000 Removed directory at path /etc/openldap/slapd.d.backup/cn=config.
    2014-09-24 22:21:29 +0000 Removed file at path /etc/openldap/slapd.d.backup/cn=config.ldif.
    2014-09-24 22:21:29 +0000 Removed directory at path /etc/openldap/slapd.d.backup.
    2014-09-24 22:21:29 +0000 Stopping password server
    2014-09-24 22:21:29 +0000 Removed file at path /etc/ntp_opendirectory.conf.
    2014-09-24 22:21:29 +0000 Removed file at path /Library/Preferences/com.apple.openldap.plist.
    2014-09-24 22:21:29 +0000 Attempting to remove principal [email protected]
    2014-09-24 22:21:29 +0000 command: /usr/bin/kdestroy [email protected]
    2014-09-24 22:21:29 +0000 Notifying peer servermaster.domain.ca we have been destroyed

  • Users cannot connect over SMB 10.10.1 server.app 4.0 and 4.0.3

    Hello,
    I have an issue where users cannot connect to a server for files sharing over SMB.
    Info:
    All users on 10.10.1
    2 Servers on 10.10.1
    Server.app 4.0.3 but issue was also present using 4.0
    SMB connection works when connecting to the OD Master
    SMB does not work when connecting to the OD Replica ServerBut AFP works fine when connecting to the OD Replica Server.
    I have destroyed and re-added the OD replica but that did not seem to help
    This is what I see in the logs each time I try to connect(logs have been cleaned to remove client details:
    Jan  9 14:37:12 server.pretendco.com digest-service[9961]: label: default
    Jan  9 14:37:12 server.pretendco.com digest-service[9961]: dbname: od:/Local/Default
    Jan  9 14:37:12 server.pretendco.com digest-service[9961]: mkey_file: /var/db/krb5kdc/m-key
    Jan  9 14:37:12 server.pretendco.com digest-service[9961]: acl_file: /var/db/krb5kdc/kadmind.acl
    Jan  9 14:37:12 server.pretendco.com digest-service[9961]: digest-request: uid=0
    Jan  9 14:37:12 server.pretendco.com digest-service[9961]: digest-request: netr probe 0
    Jan  9 14:37:12 server.pretendco.com digest-service[9961]: digest-request: init request
    Jan  9 14:37:12 server.pretendco.com digest-service[9961]: digest-request: init return domain: SERVER2 server: SERVER2 indomain was: <NULL>
    Jan  9 14:37:13 server.pretendco.com digest-service[9961]: digest-request: uid=0
    Jan  9 14:37:13 server.pretendco.com digest-service[9961]: digest-request: init request
    Jan  9 14:37:13 server.pretendco.com digest-service[9961]: digest-request: init return domain: SERVER2 server: SERVER2 indomain was: <NULL>
    Jan  9 14:37:13 server.pretendco.com kdc[4802]: Got a canonicalize request for a LKDC realm from local-ipc
    Jan  9 14:37:13 server.pretendco.com kdc[4802]: Asked for LKDC, but there is none
    Jan  9 14:37:13 server.pretendco.com sandboxd[395] ([4802]): kdc(4802) deny file-read-data /private/etc/krb5.conf
    Jan  9 14:37:22 server.pretendco.com kdc[4802]: Got a canonicalize request for a LKDC realm from local-ipc
    Jan  9 14:37:22 server.pretendco.com kdc[4802]: Asked for LKDC, but there is none
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: uid=0
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: init request
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: init return domain: SERVER2 server: SERVER2 indomain was: <NULL>
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: uid=0
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: init request
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: init return domain: SERVER2 server: SERVER2 indomain was: <NULL>
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: uid=0
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: od failed with 2 proto=ntlmv2
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: user=SERVER2\\username
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: kdc failed with 36150275 proto=unknown
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: guest failed with -1561745590 proto=ntlmv2
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: uid=0
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: init request
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: init return domain: SERVER2 server: SERVER2 indomain was: <NULL>
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: uid=0
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: init request
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: init return domain: SERVER2 server: SERVER2 indomain was: <NULL>
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: uid=0
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: od failed with 2 proto=ntlmv2
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: user=SERVER2\\codywood
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: kdc failed with 36150275 proto=unknown
    Jan  9 14:37:23 server.pretendco.com digest-service[9961]: digest-request: guest failed with -1561745590 proto=ntlmv2
    I suspect the problem is to do with Kerberos and in relation to this server being an OD Replica.
    I would really appreciate anyone's insight into this.
    Thanks
    Morgs

    I have the same problem although I upgraded from Lion Server to Mountain Lion Server. The error appears to go hand in hand with this error.
    userInit: CFPreferences: user home directory for user kCFPreferencesCurrentUser at /Network/Servers/fullyqualifieddomainname/Users/user is unavailable. User domains will be volatile.
    I've read a number of things to try. A lot of people point to DNS being a problem, but I'm confident this is correct in my environment.

  • Issues with Server.app

    hello together,
    I have some issues with Server.app.
    I connect to a server in our local network.
    In the Users tab I see only local users of the server, not the network accounts
    When I choose "Manage Network Accounts" from the "Manage" Menu, it tells me to configure the server as a network directory, but it is already configured as such.
    When I hit "next" and enter account information for the directory admin it tells me that this server is already configured to manage network accounts.
    How can I view and mange the network accounts again?
    Thanks in advance
    macmartin  

    Just fyi, I was not able to resolve this on my migrated server. Every time when I imported the OD backup from 10.5.8 Server.app couldn't load the user or group list and issues an error message with "error 5000" or something. Check if you have that in your logs, too. If so, Server.app is no longer able to authenticate against the OD. There are several threads regarding this 5000-error, none of them worked for me. Usually this happens when the hostname, IP or something in the OD setup changes and the agreed keys no longer work for authentication. As mentioned, I never managed to get that to work again and had to use a fresh OD and create the users from a list (without pwd). Not very charming.

  • Remote management via Server app authentication issues

    I am having issues with server app.  I can login to my home server if I choose the "other computer" option and input the IP address of the server and respective authentication information, but if I acutally choose server that appears in the "manage" screen, server.xxxxxx.private, the authentication fails.  Go figure.  I also had this issue when I when to bind our other computers to the server.
    What could cause this issue?

    I figured it out!  I had to add the IP of the server as a DNS Server in Network preferences Advanced Tab.  Also binding worked as well when I did this.

  • Mountain Lion Server App - Issue with Time Machine Volume Selection

    Besides my gripes that 10.7 Server or the 10.8 Server app are radically dumbed down versions of what 10.6 Server was capable of, the upgrade to 10.8 from 10.7 unexpectably broke my home time machine backup.
    Am quite familiar with the prior server versions as we are still using 10.6 Server on a dozen or so Xserve's, plugging along nicely
    This is for our house setup using a Mac Mini with an attached 8TB RAID managing media serving and time machine backups. For simplicity, the array is partitioned as a single volume and simply configuring a file sharing sharepoint as a Time Machine Volume. Simple and easy!
    When upgrading to 10.8 and then installing the server app, the upgrade conveniently didn't migrate any file sharing settings, forcing me to set them up again. Easy enough, just took a couple of minutes, except that the share point I used for time machine backups has no more setting to turn it into a Time Machine volume.
    As such, under the Time Machine tab, which shows only logical volumes, I simply can't back up to our existing backups.
    I suppose I can re-partition the array to create a logical volume for TM backups, but I can't believe that there is no provision to change a sharepoint into a TM volume anymore.
    Am trying to stay away from CLI settings as well as that defeats the purpose of the app.
    Any thoughts or suggestions?
    Wolfman

    I have asked the hosts to move your post to the OS X Server forum.

  • Hosting an ecommerce website with iMac and Mac server app

    Would it be possible to run an effective small business website which includes an online store using my iMac (or Mac mini), a WYSIWYG editor, my current ISP, plus, do effective SEO, configure and employ other revenue streams in addition to my own website shopping cart feature such as google shopping and implement other revenue streams on my website like ad-sense?
    I need to set-up an ecommerce site for my small business which I just bought a domain for.  What I'm trying to find out is if it is better to use a web host, or, if I could use my iMac with the Apple server app (or buy the mini server) and host it myself.  I don't have any programming language skills, but, I believe I am capable of doing this myself once I begin to comprehend and practice the neccasary processes to make all of this happen.

    Getting the easy question out of the way: yes, an iMac running Server.app and add-on eCommerce software can do this.
    Now for the tougher question: should you?  You're signing on for maintaining and updating and troubleshooting and potentially site remediation and decontamination after issues or security attacks.  You are also signing up for PCI compliance, if you're not working with another entity for credit-card processing.  (Anything with credit card data is a target for attacks; there's money involved.)  
    There're the more germane aspects, too: ensuring your (static IP) network links have bandwidth, availability and latency (eg: ISP bandwidth, pingdom or other uptime checks, et al), and maintaining your servers against crashes and corruptions and hardware failures (eg: RAID, possibly redundant systems); maintaining site access against the usual sorts of outages.  Software updates for OS X and for the ecommerce software and whatever other dependencies are involved, too.  Regular backups are most definitely required.
    Or alternatively: getting somebody to maintain this stuff for you, either hosted, or dedicated to and on your server(s) and your network links, or on your own co-lo servers.
    All this in addition to running your business, and writing (good, frequently updated) content that'll draw in the search engine ranking and/or buying search keywords or whatever you're doing for advertising that'll draw in potential customers, and dealing with the finances and the rest.
    Servers are somewhat different from clients, in terms of system management, too.  Servers involve more than one user when they're out, and so you're not rebooting or reconfiguring them nearly as often as client systems can be modified.  Servers can also tend to chew up bandwidth, if you're successful.
    Key to running a business is figuring out what you don't need to do (either at all, or that you can outsource or host or whatever, or hire out for, etc), so that you can focus on what you do need to do to make the business successful...  If you're just getting going and not into system administration and programming payment gateways and the rest of running a server, I'd suggest hosting the ecommerce stuff, at least to start with.  Unless you want to learn how to run an ecommerce site, that is...

  • Presentation Server 4.5 - Warning Balloon Display Issue

    Hi all,
    We're experiencing an issue within one of our apps being hosted via Presentation Server/XenApp 4.5. This issue is only happening to a select users, regardless of which server the app is hosted on. For this app, it's being hosted on 2 servers. Other users using this app on either server are being displayed properly.
    Has anyone seen this issue before?
    This topic first appeared in the Spiceworks Community

    Good evening to every one, I have the next question,I gota DellPower EdgeT710 Server, in this server I have 2 HDwithRaid Level1(00:00 and 00:01) but one of those (00:01) is damage, my concern is about a failure in the main one (Main 00:00-HD 2TB Dell Win ad sv2012R2 and it hassome programs anddatabases).So the question is if I buy a new hard drive with the same specs for replace my damage HD:- Can I Install it to initialize and virtualize for the Raid Level 1 ? is this possible ?-If the above question is possible after this what I have to do for synchronize or obtain an exact copy of my OS andall the information of the main drive to the new one? I have to clone it?OrThis is not possible and I have to replace the hard drive, format, initialize, virtualize, Fix RIAD1,install my OS, programs and restore mydatabases fromback up, copyfiles...

  • New, Single Server - DNS, Web, Wiki, Mail Setup Issues

    I'm having some issues properly setting up 10.7.3 to host internal DNS and external Web, Wiki and Mail.  I'm having issues with the web and wiki hosting.  Since those are the most important right now, I haven't really had a chance to fully test the other features.  I was able to do some testing of the mail and iCal but it was limited.
    Long read below but I thought the specifics would be helpful...
    My goals and configuration are:
    ***GOALS***
    Primary:
    1) Host a public website: example.org and www.example.org
    2) Host a public wiki: main.example.org and www.main.example.org
    3) Host a public mail server: [email protected]
    4) Host a public, group calendar
    4a) Read only to majority - Read/Write to a group
    5) Host a global address book for authenticated users
    Secondary:
    6) Allow anonymous public access to a file share (read only)
    7) Allow authenticated access to the same file share (read/write)
    8) Do as much of this via GUIs as possible.
    ***SETUP AND CONFIGURATION***
    Physical:
    1) Business class Internet (no blocked ports)
    2) A single, public and static IP address
    3) Domain name and public DNS via GoDaddy
    4) Wildcard Cert: *.example.org from GoDaddy
    5) Late 2011 (bought in Jan 2012) MacMini Lion Server (the $1,000 one).
    5a) Upgraded the RAM to 16GB (need for VMware Windows clients)
    5b) Added two USB to Ethernet adapters.
    6) Using a new model AirPort Extreme Base Station (bought w/ the MM) as the main router.
    Initial Configuration:
    7) Setup a Mac Address reservation for the main and two USB Ethernet ports along with the wireless too.
    7a) Main port = 10.0.1.5 / Others are .6, .7 and .10
    8) During the setup, I chose the Host on the Internet (third) option and named my server: main.example.org
    9) After the setup completed, I upgraded the OS & Admin Tool to 10.7.3 from a clean install (on #5 now)
    DNS Config
    10) I used the admin tool to open DNS and change:
    11) "Primary Zone Name" from main.example.org to example.org.
    12) In the "Nameservers:" block, I changed the zone name there but left the nameserver name alone (zone: example.org /// Nameserver Hostname: main.example.org).
    13) The Machine Name and Reverse Zone was left alone.  RZ resolves to main.example.org.  sudo changeip -checkhostname is good.  dig on the example.org and main.example.org are good to go (NOERROR).
    OD Config
    14) From the server app, I clicked Manage/Network Accounts and setup the OD - No issues.
    SSL
    15) From the server app, I created self signed cert, generated a CSR, got a public Cert, then replaced the self-signed with the public one - No issues.
    16) Changed any service using the self-signed cert to the public one - No issues.
    17) Changed the cert in the OD to the public cert from server admin - No issues.
    In order: File Sharing, Mail, AB, iCal, Web, Wiki, Profile Manager, Network Groups, Network Users
    18) File Sharing was setup using the server app
    19) Setup mail using the server app to start it and the server admin app to configure it - No issues there (I think...)
    20) AB - Flipped the switch to on
    21) iCal - Flipped the switch to on - I setup the e-mail address to use after I added the network accounts.
    22) Web - Flipped the switch to on - Default site worked (main.example.org)
    23) Wiki - Flipped the switch to on - Default wiki worked. (main.example.org)
    24) PM - Checked the sign config profiles and enabled the device mgt.  I then flipped the switch to on - Default settings and pages worked.
    ***MY PROBLEMS***
    Website:
    Adding a website for example.org gave me the red dot in the server app.  To fix that, I added a Machine Name record to my primary zone (PZ = example.org Machine Name = example.org).  I first tried using the same 10.0.1.5 IP as the main.example.org and left the reverse mapping alone (still resolved to the NS of main.example.org).
    That gave me the green light in the server app when trying to add the website again.  From there, I changed the "Store Site Files In" to the location of my website files (and confirmed "Everyone" has Read Access in the folder's security settings).  I left the other info alone (all defaults accepted) and clicked done.
    Access to the website works on the server but external access doesn't (Network Error/timed out tcp_error).  Checked the AirPort settings using the AirPort utility (version 5.5.3) and the Port Mapping (under the "Advanced" icon) show serveral services all pointing to 10.0.1.5.  Thinking it could be DNS I tried main.example.org externally and it failed the same way.
    I ran the changeip command (good to go) and dig on example.org and main.example.org and they both resolved to 10.0.1.5 correctly.
    I removed the example.org Machine Record from the zone and it now looks like:
    PZ=example.org / ZONE=example.org / NS=main.example.org
    Machine Record=main.example.org / IP=10.0.1.5
    RM=10.0.1.5 / Resolves=main.example.org
    PLEASE HELP!

    The amount of users (if relevant):
    On site - 1 (Me)
    Off site - 16 (Windows clients - some have iOS devices too)
    Web site traffic - less than 50 regular visits per day (avg of 15) with a peek of ~125 once a month.
    This is for a 501c3 public nonprofit made of all unpaid volunteers (including the officers and directors).  All of us have paying day jobs and I just so happen to be the guy that knows just enough to get myself in trouble here.

  • No permission to access the server app and Timemachine Backup failed

    Problem:
    Mac Mini Server late 2009 running OSX Server 10.6xx for years without any problem,
    upgrading to Mavericks Server in Dec. 2013, running perfectly for 6 month.
    No Hardware issues.
    Last week i inadvertently deleted some (or most?) accounts (user and others), using the gui of the server app (and too much wine for myself).
    After that i couldn’t login the app anymore, because it needs administrator rights (which were deleted).
    This all caused problems by accessing some of the running services (e.g. Calendar, Adressbook, Wiki, Mail)
    No matter - TimeMachine always did a fine backup job, i thought.
    I restarted the machine using „command - r“, selected Recovery from TM-Backup and so on.
    But after recovering and restarting the OS always hangs on reboot.
    Ok - now i can do a clean install etc.
    But has anyone any idea how to get back all the data of the services and the user accounts etc., using the corresponding parts of the Time Machine backup only? (Only local accounts, no network accounts/no open directory)

    After reading one similar post, I've solve the problem.
    It seems that I have to enable 'read and write' permission on
    my site root folder.

  • Server name change leads to Server.app not being able to add users/groups

    I changed the name of my server from vanroodewierda.rna.nl to rna.nl. I recreated my DNS setup (only used on the LAN) and everything works. I do have one problem, though: in Server.app, it is impossible to add/delete users and groups. (Yes, I can use Workgroup Manager, but this situation makes the system less robust, certainly, so it should not persist)
    changeip -checkhostname says all is well:
    $ sudo changeip -checkhostname
    Password:
    Primary address     = 192.168.2.66
    Current HostName    = rna.nl
    DNS HostName        = rna.nl
    The names match. There is nothing to change.
    dirserv:success = "success"
    system log says
    Apr  7 12:36:47 rna.nl servermgrd[5046]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:36:48 rna.nl servermgrd[5046]: flushing dns cache
    Apr  7 12:36:54 rna.nl servermgrd[5046]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:36:55 rna.nl servermgrd[5046]: --Module servermgr_devicemgr's response has retain count of 3.
    Apr  7 12:36:55 rna.nl servermgrd[5046]: --request was {
    Apr  7 12:36:55 rna.nl servermgrd[5046]: --response was {
    Apr  7 12:36:55 rna.nl servermgrd[5046]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:37:01 rna.nl servermgrd[5046]: nsc_smb XPC: handle_event error : < Connection invalid >
    Apr  7 12:37:01 rna.nl servermgrd[5046]: nsc_smb XPC: handle_event error : < Connection invalid >
    Apr  7 12:37:27 rna.nl servermgrd[5046]: nsc_smb XPC: handle_event error : < Connection invalid >
    Apr  7 12:37:48 rna.nl servermgrd[5046]: -[AccountsRequestHandler(AccountsSystemConfigurationObservation) registerForKeychainEventNotifications]: SecKeychainAddCallback() status: -25297
    Apr  7 12:37:48 rna.nl servermgrd[5046]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:38:48 rna.nl servermgrd[5046]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:41:24 rna.nl servermgrd[5046]: getting service list
    Apr  7 12:46:25 rna.nl servermgrd[5046]: No requests in 300 seconds, shutting down
    Apr  7 12:48:38 rna.nl servermgrd[148]: -[AccountsRequestHandler(AccountsOpenDirectoryHelpers) openLocalLDAPNodeIfNeeded]: dsLocalLDAP = (null), error = Error Domain=com.apple.OpenDirectory Code=2100 "Connection failed to node '/LDAPv3/127.0.0.1'" UserInfo=0x7f9fc501c950 {NSLocalizedDescription=Connection failed to node '/LDAPv3/127.0.0.1', NSLocalizedFailureReason=Connection failed to the directory server.}
    Apr  7 12:48:49 rna.nl servermgrd[148]: servermgr_accounts: noteDirectorySearchPolicyChanged (reopening nodes)
    Apr  7 12:48:50 rna.nl serveradmin[156]: --Module servermgr_devicemgr's response has retain count of 3.
    Apr  7 12:48:52 rna.nl servermgrd[148]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:48:52 rna.nl serveradmin[156]: servermgr_accounts: noteDirectorySearchPolicyChanged (reopening nodes)
    Apr  7 12:48:53 rna.nl serveradmin[156]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:49:44 rna.nl servermgrd[148]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:49:44 rna.nl servermgrd[148]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:49:44 rna.nl servermgrd[148]: getting service list
    Apr  7 12:50:44 rna.nl servermgrd[148]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:53:44 rna.nl servermgrd[148]: No requests in 300 seconds, shutting down
    Apr  7 12:56:59 rna.nl servermgrd[422]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:57:00 rna.nl servermgrd[422]: flushing dns cache
    Apr  7 12:57:03 rna.nl servermgrd[422]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:57:04 rna.nl servermgrd[422]: --Module servermgr_devicemgr's response has retain count of 3.
    Apr  7 12:57:04 rna.nl servermgrd[422]: --request was {
    Apr  7 12:57:04 rna.nl servermgrd[422]: --response was {
    Apr  7 12:57:04 rna.nl servermgrd[422]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:57:08 rna.nl servermgrd[422]: nsc_smb XPC: handle_event error : < Connection invalid >
    Apr  7 12:57:59 rna.nl servermgrd[422]: -[AccountsRequestHandler(AccountsSystemConfigurationObservation) registerForKeychainEventNotifications]: SecKeychainAddCallback() status: -25297
    Apr  7 12:58:00 rna.nl servermgrd[422]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Apr  7 12:58:59 rna.nl servermgrd[422]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    In All messages, I see that the name VANROODEWIERDA.RNA.NL is still used (note: vanroodewierda.rna.nl is an alias in DNS for rna.nl)
    4/7/13 1:07:55.037 PM kdc[73]: AS-REQ [email protected] from 192.168.2.86:56402 for krbtgt/[email protected]
    4/7/13 1:07:55.046 PM kdc[73]: AS-REQ [email protected] from 192.168.2.86:56402 for krbtgt/[email protected]
    4/7/13 1:07:55.048 PM kdc[73]: Client sent patypes: REQ-ENC-PA-REP
    4/7/13 1:07:55.048 PM kdc[73]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ
    4/7/13 1:07:55.072 PM kdc[73]: AS-REQ [email protected] from 192.168.2.86:56901 for krbtgt/[email protected]
    4/7/13 1:07:55.081 PM kdc[73]: AS-REQ [email protected] from 192.168.2.86:56901 for krbtgt/[email protected]
    4/7/13 1:07:55.082 PM kdc[73]: Client sent patypes: ENC-TS, REQ-ENC-PA-REP
    4/7/13 1:07:55.083 PM kdc[73]: ENC-TS pre-authentication succeeded -- [email protected]
    4/7/13 1:07:55.083 PM kdc[73]: Client supported enctypes: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96, des3-cbc-sha1, arcfour-hmac-md5, using aes256-cts-hmac-sha1-96/aes256-cts-hmac-sha1-96
    4/7/13 1:07:55.083 PM kdc[73]: Requested flags: forwardable
    There is one stupid thing I might have done myself that caused this. In WGM in my Machines directory there was a machine called vanroodewierda.rna.nl$, I removed that and replaced it with the same MAC address and the name rna.nl$. Might the following have to do with that?
    4/7/13 2:03:57.457 PM kdc[73]: Server not found in database: ldap/[email protected]: no such entry found in hdb
    4/7/13 2:03:57.457 PM kdc[73]: Failed building TGS-REP to 127.0.0.1:50170
    4/7/13 2:03:57.458 PM opendirectoryd[31]: GSSAPI Error:  Miscellaneous failure (see text (Server (ldap/[email protected]) unknown while looking up 'ldap/[email protected]' (cached result, timeout in 1200 sec))
    What must I do to correct this? It feels like something should change in the Keychain and/or in Kerberos, but what and how?
    Thanks,

    @John & MrHoffMan,
    thanks for replying.
    - I know about the split-horizon DNS, it is by design so that, say, mail.rna.nl on the LAN resolves to the same machine as on the WAN and people can take their laptops anywhere and mail 'just works'.
    I tried this in Server.app (last night also). I now changed from rna.nl to rna.nl to vanroodewierda.rna.nl and back to rna.nl. (I did this because a change to the same might be ignored by some services and I wanted to force them). In the system log I notice (esp. the first 4 lines):
    Apr  7 18:28:21 rna.nl changeip_certs[5029]: found identity for vanroodewierda.rna.nl in keychain
    Apr  7 18:28:21 rna.nl changeip_certs[5029]: certificate for vanroodewierda.rna.nl is not self-signed
    Apr  7 18:28:21 rna.nl changeip_certs[5029]: no self-signed identity for the previous hostname 'vanroodewierda.rna.nl' found in keychain
    Apr  7 18:28:21 rna.nl changeip_certs[5029]: not generating a self-signed certificate for new hostname 'rna.nl'
    Apr  7 18:28:21 rna.nl serveradmin[5034]: servermgr_jabber[N]: Processing changeip request.
    Apr  7 18:28:22 rna.nl changeip_mail.py[5035]: Mail Service change IP: old hostname: "vanroodewierda.rna.nl (192.168.2.66)" to: new hostname: "rna.nl (192.168.2.66)"
    Apr  7 18:28:22 rna.nl changeip_mail.py[5035]: Mail Service new host/domain/IP settings:
                        mail:postfix:submit_cred:rna.nl:username = "submit"
                        mail:postfix:submit_cred:rna.nl:password = "8OOkDnAXKi8bHYHwft1mWs"
                        mail:postfix:mydomain = "rna.nl"
                        mail:imap:postmaster_address = "[email protected]"
                        mail:postfix:submit_cred:nl:username = "submit"
                        mail:postfix:submit_cred:nl:password = "8OOkDnAXKi8bHYHwft1mWs"
                        mail:postfix:add_whitelist_host = "rna.nl"
                        mail:postfix:add_whitelist_domain = "nl"
    Apr  7 18:28:22 rna.nl com.apple.SecurityServer[22]: Succeeded authorizing right 'system.privilege.admin' by client '/Applications/Server.app/Contents/ServerRoot/usr/libexec/ServerEventAgent' [147] for authorization created by '/Applications/Server.app/Contents/ServerRoot/usr/libexec/ServerEventAgent' [147] (2,0)
    Apr  7 18:28:22 rna.nl com.apple.SecurityServer[22]: Succeeded authorizing right 'system.privilege.admin' by client '/Library/PrivilegedHelperTools/com.apple.serverd' [89] for authorization created by '/Applications/Server.app/Contents/ServerRoot/usr/libexec/ServerEventAgent' [147] (100000,0)
    Apr  7 18:28:22 rna.nl serveradmin[5034]: servermgr_jabber[I]: Proxy65 config file successfully created.
    Apr  7 18:28:22 rna.nl kdc[73]: AS-REQ [email protected] from 127.0.0.1:64299 for krbtgt/[email protected]
    Apr  7 18:28:22 --- last message repeated 1 time ---
    Apr  7 18:28:22 rna.nl kdc[73]: Client sent patypes: REQ-ENC-PA-REP
    Apr  7 18:28:22 rna.nl kdc[73]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ
    Apr  7 18:28:22 rna.nl kdc[73]: AS-REQ [email protected] from 127.0.0.1:52730 for krbtgt/[email protected]
    Apr  7 18:28:22 --- last message repeated 1 time ---
    Apr  7 18:28:22 rna.nl kdc[73]: Client sent patypes: ENC-TS, REQ-ENC-PA-REP
    Apr  7 18:28:22 rna.nl kdc[73]: Need to use PA-ENC-TIMESTAMP/PA-PK-AS-REQ
    Apr  7 18:28:23 rna.nl servermgrd[1402]: servermgr_accounts: got error 5000 trying to auth to local LDAP node
    Problem remains, but I wonder: can I remove the identities in Keychain that may be messing things up? And if so, which ones? Some are even duplicated in System and login key chain.
    (never mind the weird whitelist domains Server creates, I'm managing that by hand anyway)

  • How to convert batch application to server app?

    I have an application that performs some processing task in batch mode: data in, processing, data out. The application can be accessed through a well-documented API but is not thread-safe -- one cannot run the processing function in two threads concurrently.
    In order to make that processing accessible to a program written in another language I would like to encapsulate it into some form of server.
    I would like to find some minimum overhead solution where the other program sends the data to the server app in some way, waits for the processing to complete and reads back the result. One option would be to use the HTTP protocol with a POST request, another to write the data to a database row and send some command over a socket.
    My main problem is: which solution is the easiest to implement and use and the one that allows to serialize the processing with the least effort. The solution should make it easy to prevent deadlocks or similar nuisances.
    Are there some standard patterns for doing this or what would you Wizards recommend?

    Thanks for the answers!
    I must admit that I am still rather clueless in general about the issues involved here.
    My immediate need is to send text files to the java application and get back processed text files. At the moment I have to do this from perl, but in the future, other languages (mostly scripting languages) might also need to do this.
    So what I am trying to achieve is this: the client should be able to access the Java application/service as if it was some synchronous write/read operation (similar to a HTTP post request waiting for a response). There might be several clients working in that way but the the server should make sure that they get cleanly serialised: only one text file can be processed at any one time because the API is not thread safe.
    I also cannot change the API itself -- just wrap into something that will do what I described. The more lightweight,easy to use, and easy to implement the solution the better.
    For example, is there some kind of mini HTTP server and some serialization mechanism in Java that would make it possible to run the Java application disguised as a web service? Are there disadvantages to this and other solutions that are more suited?
    I have looked at JMS and it does make a bit of a heavyweight impression to me. Also I'd prefer a solution where the clients use some mechanism that is more general, e.g. HTTP or the file system or maybe even a RDBS table (not sure what the possible traps with regards to deadlocks, timeouts etc. are there).

  • OS X Mavericks Server.app doesn't show site, but default Welcome to OS X Server page

    I am completely new to Mac OS X Server.app, so sorry if I sound dumb .
    1. I installed Server.app to Mavericks.
    2. Enabled Websites service in it.
    3. Installed MySql.
    4. Installed Wordpress using this script: https://github.com/MacMiniVault/Mac-Scripts/blob/master/mmvwordpress/mmvwordpres s-README.md
    5. Created coresponding website to Websites
    6. I opened Safari and navigated to my new created website: http://predstavitev.net:8081 and all I get is server's default page.
    7. I checked what is the content of my "predstavitev.net" folder on server and found that it actually contains Wordpress installation files:
    Please help me find out, what am I doing wrong. Thanks.

    Check the Console.log for details that might be getting logged there related to this issue.
    You're probably using NAT here, which means you'll be using split DNS or using an internal domain and an external domain.  (Confusingly, DNS centrally matters with the web client accessing the web site, and rather less so with the web server itself.)
    OS X Server itself requires DNS, irrespective of the web server — usual setup is the local IP network (not in 192.168.0.0/24 nor 192.168.1.0/24 subnets due to collisions with VPN connections later, and preferably somewhere "weird" in the 192.168.0.0/16 or 172.16.0.0/12 or 10.0.0.0/8 private IP blocks — pick a weird range for your subnet, not the first few ones that everybody else uses. 
    To verify local DNS services, launch Terminal.app from Applications > Utilities and issue the following harmless diagnostic command:
    sudo changeip -checkhostname
    That'll require an administrative password, might show a one-time informational message around the use of sudo, and will then display some network information and then an indication that no changes are required, or that there are DNS or network problems.
    Do not use .local nor .arpa as your domain.  (That works fine for incidental stuff, but network security and secure connections and related underpinnings all expect the servers involved to have valid DNS — not Bonjour.)
    Unfortunate, if DNS is actually incorrectly configured, then various services including the mail server and Open Directory and the profile manager all tend to have problems, and all SSL-based security is dependent on proper DNS configurations.
    FWIW, I'd be careful with managing a WordPress server, as breached with that Content Management System (CMS) package are common.  I'd probably either host the site elsewhere (in the "cloud"), or would configure the WordPress web server in a DMZ to isolate the potential damage arising from a breach.   (I use Drupal locally and while breaches with that are somewhat less common than with WordPress, I still lock that down, and still prefer to DMZ that.)  With WordPress or Drupal or any other CMS, keep your patches current, too.

  • Hanging on boot after upgrading server.app

    After upgrading to 10.9 Server.App my boot hangs at "/etc/rc.server: line 14: /etc/rc.server.firewall: No such file or directory" and won't boot into safe mode either. Anyone know how I can fix this without restoring from a backup?

    Cameron, thanks for your feedback.
    I'm on a 2011 iMac, with a DIY Fusion Drive (I added a SSD inside). I always had slow startups. I thought it was the custom Fusion Drive's fault, but now I know it was not.
    Now I can't boot at all, just after applying the most recent 10.9.2 security update. This is a software issue. The iMac was running Mountain Lion Server, then I upgraded to Mavericks but did not upgrade to Mavericks Server. However there were remains of the old 10.8 Server app.
    As I said, yesterday I deleted all those remains (booting from an external drive). However I forgot the most obvious thing: open that **** /etc/rc.server file and comment out line 14.
    This morning I booted the iMac again, in verbose mode. The message about /etc/rc.server was not there, at last, but fsck was launched and took a long time. I had to go to work, where I am now, and I don't know if fsck finished its work. I'll let you know...

  • How do I revoke a DHCP lease in the 10.8.4 server app?

    Hello Everyone,
    I have some devices (security cameras) that have successfully requested a DHCP lease.  Since then I went ahead and manually created a static reservation for them with a MAC hardware address in the DHCP.  For whatever reason they are not switching over to the reserved address.  The leases were originally for 1 day.  It has been 5 days now.  After the first day I switched my lease time to 1 hour.  I have done everything short of leaving the devices off for 24 hours.
    In Lion server, I could revoke the lease via the gui.  No such luck now.  My call to Applecare resulted in a "there is no way in 10.8.4 to do this".  They said it would switch to the new reserved address after the initial lease period timed out, so I'm hoping the representative was wrong twice.  They mentioned a complete lease wipe, but couldn't say if this would cause me to lose my list of reserved static addresses, which isn't an option.
    It seems crazy that such a basic feature wouldn't make it into this release of the DHCP service.  Any help would be greatly appreciated!

    Are there any DHCP queries from the cameras?  Check the DHCP server log via Console.app or Server.app (or Terminal.app) for details.  (I don't know the 10.8 path to the DHCP logs offhand.)
    According to a FAQ over at the Vivotek site, the following is the setup sequence for various recent cameras; the boxes start up in the "I don't have an IP address" self-allocated address block oddly enough, and apparently don't ask for a DHCP address?  (You may well be aware of all of this, but this is the block that DHCP clients use when they first communicate with DHCP servers.)
    If you are using our new product such as IP7138 / IP7139 / FD7131 / VS7100… etc, no matter your network environment is what, you can always find the camera by Installation Wizard II with the IP address 169.254.x.y.
    And then, please double click the camera found by Installation Wizard II or directly type the IP address to your Internet Explorer URL box to access your camera (you do not need to change your PC's IP address). After access your camera, please go to "Network" page to configure proper network settings.
    See if the devices are available via mDNS, as well; download the Bonjour Browser and have a look around your LAN.  (If you're very lucky, the cameras might be visible and chatting on mDNS.)
    Might also try resetting one of the cameras back to factory defaults, and seeing if you can get them to re-ask the DHCP server.
    (I've had issues with some HP printers and DHCP clients and IP address assignment, but that's fodder for another discussion.  And I also wouldn't rule out a rogue DHCP server, either.  I've seen all sorts of unexpected stuff connected to networks over the years...)

Maybe you are looking for

  • Old laptop stolen, can't add music from new laptop to iPhone

    Basically, my old laptop was stolen out of my car, so bought a new one. I've put all my backed up music onto my new laptop, but can't add music from my new laptop to my iPhone. I've deauthorised my old laptop and authorised my new one, but iTunes won

  • Name to be displayed along with the emailid in the email

    Iam sending email with the help of java mail but the requirement of mine is to display the name of the sender along with the emaiil id of the sender i.e the name should appear along with the from address Hope you will help me in this regard and do th

  • References​: Appearance different in Developmen​t System and in Run Time System

    I noticed a difference the references appearance in Development System and in Run Time System.  It seems to have no effect in the executable version but, per curiosity, someone have an explanation? Development System Run Time System Jean-Marc Jean-Ma

  • Data Base Layout Placement??

    Hi all, Question about entering information in a database. For example, "Will" has two sets of info that need to be shown. Not all names like "Will" have two sets of infomration. How do you attach the second set of info to be displayed on the line be

  • SFTP problems with new connection/server

    We are moving to a new server and have decided to use sFTP this time around. We have a Windows 2012 R2 Server, and are running Contribute CS5 (with No CPS). My sFTP works great using winSCP, but when I go to set up the connection in Contribute I am g