Slow workgroup manager, slow screensharing, slow account management

Hi,
At home on my Mac Mini Server, i try to connect to the workgroup manager. It works but it need a lot of time to connect. During this time, i get certain times this error in the log message:
DirectoryService[29]: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)
DirectoryService[29]: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server ldap/[email protected] not found in Kerberos database)
Is there something i can do to fix that problem. Because i think this is the reason why it's so slow.
Greetings Roger

archiving the ldap directory, demote to standalone, "remote" to OD Master, followed by restoring the LDAP directory did the trick to me.
I have been mad at WGM for months and stumbled on this tip and it fixed all my problems!
see here:
http://discussions.apple.com/thread.jspa?threadID=1520446&tstart=66

Similar Messages

  • HT1338 XSERVE 10.6.8 is running very slow, and Workgroup Manager is not responding

    XSERVE 10.6.8 is running very slow, and Workgroup Manager is not responding. There is no more updates to download.

    munish khanna wrote:
    1. upgrade to lion, which should over write previous software and the reasons for it being slow.
    No, you don't want to upgrade over a buggy system, Lion has issues of it's own that will only complicate matters, plus Lion is slower than Snow Leopard.
    Learn all the pitfalls before you upgrade to Lion, like all your Rosetta/older programs will no longer work and more.
    Leave Lion for a new hardware purchase is my advice, it's still got plenty of security and other issues.
    For your performance, your likely better off replacing the hard drive with a 7,200 RPM model and maxing the RAM, download the free MacTracker to find out your specs, and OtherWorld Computing is good for videos, tools and parts.
    http://eshop.macsales.com/installvideos/
    2. Format the hard disc and reinstall snow leopard.
    That will work, provided your data is off the machine first.
    Now how do i reinstall snow leopard as it was an online purchased upgrade from leopard.
    The 10.6 Snow Leopard disk that you upgraded 10.5 Leopard from actually has the full OS X 10.6 on it.
    All you have to do is stick the disk in and hold the c key down while booting, use Disk Utility to erase the entire drive, quit and install 10.6.
    Of course your not going to get the free iLife that came with the 10.5 grey disks, see if you can first install 10.5 with the same methods, then setup with the same user name as before, then upgrade to 10.6
    I think Apple nulled booting off the 10.5 disks, but it won't hurt to try.
    Another method would be to install 10.6 fresh by itself, then use the program called Pacifist to extract iLife from the 10.5 disks.
    http://www.charlessoft.com/
    Read here for plenty of how to's
    https://discussions.apple.com/message/16276201#16276201

  • 10.4 Workgroup manager and xserv slow..

    We have an XSERV running 10.4.11 server that was working fine. last week the server OS drive became corrupted and I have to reformat and reload the backup we had from retrospect. All seemed OK... BUT.. now when a user going to login to workgroup manager, it is very slow getting to the desktop and getting any icons on the desktop. this is happening in our 2 computer labs that have IMAC computers. They were fast BEFORE the server crashed and had to be restored...

    Quote:
    Do we need to modify/update some schema changes with Lion to be applied to the AD?
    That's the question, it looks to me like it might be trying to store the configurations in a different attribute or something.

  • Disabling Keyboard Shortcuts for LDAP Accounts -Workgroup Manager...

    I work in a school and all our students are on LDAP accounts. Recently some of the kids realized that hitting Ctrl-Opt-CMD-8 inverts the screen display. You wouldn't believe the amount of havoc this has created at school, especially when they do it to a kid’s account that doesn't know how to fix it.
    Keyboard and Mouse are NOT one of the items under preferences for either groups or accounts in Workgroup Manager. Does anyone know if there is a way around this, or an alternate way of getting rid of the keyboard shortcuts for Universal Access, for either groups or accounts?
    Thanks
      Mac OS X (10.4.6)  

    Within the Workgroup Manager pane for Preferences, there is an option to manage Universal access. Within that section, there is a tab for 'Options'. You will want to change that management to 'Always' and leave the box for 'Allow Universal Access Shortcuts' UNchecked. This will, in effect, disable the usage of the shortcuts for a User or a selected Group account.
    Hope this helps out!!
    www.Admin660.com

  • Cannot login with a account created with workgroup manager on local box

    Hi my name is richard and i recentgly acqquired from one of ,y friends a macbook pro with leopard 10.5.7 and I downloaded the server tools to it because workgroup manager gives me more control over user creation and the like.there are three issues that i am facing right now:
    1) I create an account for a user "VERONICA MARS" short name vmars with a password of apple. when I try to login using that account the login window just sits there and shakes its head at me like no no no wrong cridentials.
    2) using the same account vmars i try to reset her password using wgm and it says that it cannot reset the password.
    3) when i try to create the account it tells me that the home directory cannot be created.
    oh and heres a bonus one:
    most of the time in wgm it takes forever to get from one tab to the next and ill have to do a force quit to restore my mkac back to normal.
    if anyone can help with these issues please respond
    thanks in advanced
    richard johnson
    mac fan for life

    Please let us know the username of the account that is giving you trouble.

  • Can't create computer account in Workgroup Manager

    Hi everybody !.
    I am installing a new Xserve with Mac OS X Server 10.5.6 and I am having some trouble with computer accounts in Workgroup Manager.
    I have a couple of PCs with Windows XP that I have added to the Windows domain created by Mac OS X Server with no problem,and they do appear in my computer account list, with the name PC_NameX$.
    My Xserve also appears in this list with the name ServerName.DomainName$
    But my iMacs (with Mac OS X 10.4.11) are not listed. When I try to create their accounts, I write their names and their MAC address but when I push the button "Save", Workgroup Manager says that I can't create this account because there is a computer with that name and that MAC address yet.
    I can't find a solution for this problem by myself. Could anybody give some advices to solve it ?.
    Many thanks.

    Hi Mabel,
    In my computer list appears my Windows computer names (followed by a "$" symbol, i.e., name$) and my Xserve name followed by domain name and a "$" symbol, i.e, name.domain$. Finally, there is a Guest account I added a few days ago (without "$" symbol).
    No iMac is listed here. When I try to add them manually, I write "Name", "Short Name" and "Ethernet ID" fields, and when I push "Save" button, I get this message:
    "The name you have chosen conflicts with a name assigned to another computer. You can’t assign the name “Pollux” to two different computers. Remember that names are not case-sensitive when checking for conflicts." (Pollux is the name I gave to one of the iMacs).
    If I change this name and use another one, but I don't change "Ethernet ID" and then push "Save", the message is:
    "The ethernet address you have chosen conflicts with an ethernet address assigned to another computer. You can’t assign the ethernet address “00:17:f2:d3:38:95” to two different computers."
    So, It seems that WGM knows Name and Ethernet ID from this iMac because it does not let me type them again, but I have not typed this information before nor the iMacs are listed in computer list.
    This is what I don't understand.
    I have have read chapter 6 "Setting Up Computers and Computer Groups", the one that starts on page 105, from top to bottom. I have not found a single clue that helps me solving this problem. Here explains the procedure when everything is working properly.
    Finally, another piece from the puzzle. There is an iMac, that always connects to Directory with Airport interface. I have tried to add this iMac, manually. Well, I get the name conflict message, the Ethernet ID conflict message (with its airport id) and... an Ethernet ID message when I type its Ethernet ID. It seems Directory knows this Ethernet ID even, it has never been used to connect to it.
    Is there some detail I am missing ???.
    Kind regards.

  • Workgroup Manager doesn't create home directories for OD accounts

    I'm having an issue where home directories aren't created for OD accounts. My setup is as follows, the home directories are stored on the OD Master (the only Apple/OD/AD server on the network), and the home directory paths are filled as afp://192.168.1.254/Customers, fakeuser, /Users/Customers/fakeuser
    This same pathing scheme works fine for local accounts, however for OD, clicking Create Home Directory and saving the account does nothing (no errors, nor folders created). If I ftp into said account, I wind up being directed to /Users (definitely not the expected behaviour)
    I am deploying a web based upload system that I want to authenticate against OD users so as to share home folders and permissions with the ftp server, once I have this figured out I will be migrating a bunch of accounts to OD from local.

    In addition to potential DNS issues, it sounds like you may be using the wrong procedure to define the users' home directories. You should never have to specify the paths manually; instead, define the share point ("Customers" in your case) to be automounted, and then it should automatically show up in the list of available home folder locations, with all the necessary paths predefined. Here's the full procedure:
    1. Run Server Admin, and select: the server name in the sidebar -> File Sharing in the toolbar -> Volumes & Browse under that -> navigate to the /Customers folder in the column view.
    2. Make sure the folder is being shared (with it selected, you should see an "Unshare" button near the top right of the window); if not share it with the Share Button (then Save the change).
    3. Select the Share Point tab under the file browser (NOT the one above it), and select the Enable Automount checkbox. A dialog will open asking for the automount details; make sure the Directory is set to /LADPv3/127.0.0.1, Protocol to AFP, and Use for is User home folders and group folders. OK the dialog, and be sure to click Save to make the change take effect.
    4. Run Workgroup Manager, and select Accounts in the toolbar -> Users (single person icon) tab under that -> some user account(s) you want to configure under that -> Home tab on the right.
    5. Select (None) from the location list and click Save (this wipes out any current setting, so we can rebuild it correctly).
    6. The Customers share point should be in the list of available locations (due to being configured for automount); select it, then click Create Home Now, and finally Save.

  • Computer accounts in Workgroup Manager

    Is it just me or is there no way to browse the network for computers and add them as computer accounts in 10.5 server's Workgroup Manager? I can tell you I am not going to manually enter over 500 computers one at a time. Apple needs to stop taking steps backward with 10.5 server and reinstate the 10.4 server functionality here.

    This one had me scratching my head yesterday. There used to be a browse function in 10.4.x Workgroup Manager where you could browse the network for machines and then drag them in. I have been looking all over for this function in 10.5 WGM. After I couldn't find it I started reading through the manual to see what it says. All it mentions is adding them by MAC address. Is this feature really gone ? Are they planning to add it back ? As a plan B is there some way to import a list of MAC addresses ?

  • Can't re-enable accounts with workgroup manager

    Morning,
    We have had cause to disable approximately 100 student accounts earlier this week, and we are now finding that we can not re-enable them. This is a major problem as it's coming to the end of term and they all need to be able to login!
    The server is running 10.4.6 and the accounts were disabled using Workgroup Manager by selecting the account, unticking the 'access account' box and then saving.
    I am trying to re-enable the accounts by simply reversing the process, i.e. ticking 'access account' and then clicking save, however every time I try this the following error pops up:
    "Got unexpected error
    Error of type eMemoryAllocError (-14901) on line 3318 of /SourceCache/ServerManagerUserGeneral/ServerManagerUserGeneral-193.2.5/UserAdva ncedPluginView.mm"
    I have tried this with various of the disabled users on various different machines (including the server itself) and the same error comes up universally. I've had a poke about on Google but I can't find any reference to this happening anywhere else.
    My inital thought was that the admin tools were out of date but looking we have version 10.4.4 of Workgroup Manager which is what is available on the apple site; is this the latest version?
    I thought the point releases for admin tools ran in parallel with the server versions, i.e. the latest server admin tools would be of version 10.4.6?
    Any help/ideas appreciated...!
    Ian Atkinson

    Additionally, I have come up with a fudge:
    I have turned on the advanced view in Workgroup Manager so that I can see the LDAP inspector for each user. If I delete the two attributes 'AuthenticationAuthority ;DisabledUser;' and 'dsAttrTypeNative:authAuthor ;DisabledUser;' and then save, I can then go on to tick 'access account' and save with no problem (which does in fact re-enable the account).
    I don't know if this sheds any light on the subject, but it's working for now at least...
    Ian.

  • AD accounts and workgroup manager settings

    We have several Windows AD accounts that can logon, but are not applying the correct settings that have been created in workgroup manager. Open Directory and Active Directory bindings appear to be fine.
    Can anyone help!!

    The folks who hang out in the OS X Server forums are helpful for these kinds of things:
    http://discussions.apple.com/forum.jspa?forumID=1232

  • Cannot connect Workgroup Manager using a domain administrator account

    Hello,
    I'm trying to determine if this is normal behavior or something is not working right:
    When using Workgroup Manager (remotely or locally on the server) it will only let me connect with the local (Netinfo) administrator account that was created upon install of the server. It will NOT let me log in with the diradmin account that was created when promoting the server to an OD master (or any other accounts I created (under the LDAP directory) and checked User can "administer the server" and "administer this directory domain").
    Once connected to WGM with the local admin account I then can (and still need to) authenticate to the directory database using the diradmin account (which works). Is this normal behavior?
    From reading Apple's User Management documentation it seems to indicate that once a domain administrator account is set up you can use that account to log into WGM.
    Thanks in advance.
    - Brian
    Mac OS X (10.4.6)

    OK, it looks as though I've figured this out. Using the Directory Access utility on the server itself, I needed to add the "LDAPv3/127.0.0.1" directory domain to the list of domains to search for authentication.

  • Workgroup Manager - Computer accounts

    Hi,
    Does anyone know how in Workgroup Manager it find computers so that they can be added to computer groups? When I'm in Accounts --> Computer groups --> select a computer group --> Members --> Click "..." --> It displays a list of computers within my network but some would not show up.
    I'm trying to understand if Workgroup Manager uses Bonjour or IP protocols to find and list computers.
    I have forward and reverse lookup with dynamic updates working properly on a separate FreeBSD server but Workgroup Manager just shows a limited list of computers to add to computer groups.
    Can anyone help?

    I haven't looked into this very much, but it's always seemed to me that it was using Bonjour.

  • Recreate user account in Workgroup Manager, empty mailbox

    We have OS X 10.3.8 Server version. Postfix mail server.
    We have a user/account with email problems and a huge mailbox. He (user: gordon) had over 16000 emails in his mailbox (/var/spool/imap/user/gordon). All other mail users on this server work fine, including newly created user accounts.
    Our solutions was to try and delete all mail from his mailbox via Terminal. This did not seem to decrease the size of his mailbox. Our next idea was to delete this user in Workgroup Manager and then re-created this user. Hoping to created an new mail setup and empty mailbox. This idea failed aswell.
    How does one basically purge an old account/user in Workgroup Manager, and then, recreate that same user name and effectively recreate the user with a new account, including a new/empty mailbox?
      Mac OS X (10.3.8)  

    cyradm is not part of 10.3.x
    To use it you would have to install it first. See here:
    http://www.afp548.com/article.php?story=20040814204411280&query=cyradm
    And then follow the instructions given beforehand.
    Having said that, your issue can be resolved differently. You deleted all mail manually in the file system (not a good idea, but what is done is done). So the mail is actually gone. What you are seing is Cyrus' index. Since you deleted manually the index didn't get updated. To get rid of the problem either reconstruct that users mailbox throgh Server Admin - > Mail or alternatively run:
    sudo -u cyrus reconstruct -r user/gordon (assuming that's the user's name)
    Alex

  • Any changes in workgroup manager I make are not working!

    First off I know this isn't the place to vent, but I am so sick of all the bugs loaded in the directory system of mac. I think Apple has produced a horrible product and it is always one problem after another. I am experienced with all the other directory systems and I firmly believe Open Directory is the worst!
    Ok, now on to my problem. Our set up includes 6 Mac OS X 10.6 servers. 1 is the Master OD and the others are all replicas. We recently upgrades the servers from 10.5 and ever since I have been having problems with OD. During the upgrades I took an archive of the system, decommissioned the Master and all replicas, then after the upgrade I restored the archive and replicated all the others. Things worked fine for a couple of days. Everyone can login and I could create new users and make changes in workgroup manager. After a couple of days I could no longer make any changes in workgroup manager. I can physically make the changes and create new users and save with no errors, but when I try to log into the file server with the new user or use the changed password, it doesn't work. No errors in the logs that I looked in.
    Here is something weird: When I log into workgroup manager using the local administrator account, I do not see the changes I made in workgroup manager. When I click the unlock button and log in as the diradmin I can see the changes.
    Any, ANY, help would be greatly appreciated. I've been working on this for weeks now. Please don't advise to decommission the Master and rebuild the directory. I already tried that about 10 times with the same result.
    Thanks!

    5 days should be plenty, unless you have a really slow link. Here are a few diagnostics that come to mind to figure out more about what's going on:
    To test to figure out of I'm right about replication being the source of the problem, and if so which replicas aren't up to date, use the "ldapsearch" command to compare the data in the master vs. the various replicas. For instance, to check whether a new user named "fred" has shown up in the server at serverIP, run the command: ldapsearch –LLL –x –h serverIP –b cn=users,dc=masterserver,dc=example,dc=com “(uid=fred)”
    (replace serverIP with your server's address, "dc=masterserver,dc=example,dc=com" with your search base, and fred with the actual account name). Try this on the master and the various replicas, and see which (if any) of the replicas are out of sync.
    If some/all of the replicas are out of sync, check /var/log/slapd.log on the problematic replica(s). It's visible in Server Admin -> servername > Open Directory in sidebar -> Logs in toolbar -> LDAP Log in the View pop-up at the bottom of the window.
    Also, check the replica status in Server Admin -> Open Directory -> Settings -> General.
    Also, on the problematic replica(s), check the replication connections: "sudo lsof -i | grep ldap" should show an entry starting with "slapd" and ending "->masterserver.example.com:ldap (ESTABLISHED)". If it doesn't, you may have some sort of network connectivity/firewall issue.
    If you want to get even more detailed, running "sudo tcpdump host masterserver.example.com and port ldap" on the replica will let you spy on the content of the replication connection.

  • How to you "publish" Bonjour Shared printers using Workgroup Manager?

    Dear Friends,
    Hello. We have just spend considerable time setting up Mac OS X 10.6.4 server to host some printers to our Mac clients (previously we had used a Windows print server but it was too slow and inflexible). We have the printers we need set-up and shared out as Bonjour Shared printers because that sends out all of the duplex setting we need. I have tried to "publish" these using Workgroup Manager and they do not show up on the list. How do you "publish" these printers using WGM? NOT: We can't just let people select "nearby" printers because we want to set a default and use kerberos security.

    Eric T Gadsby wrote:
    Anthony,
    Thank you for you help. The procedure you outline is what we have attempted to do. We add the Bonjour-shared printers to a client and then open Work Group Manager on the same computer but when you go to the "Printing" pane of "Preferences" the printers do not show under "Available Printers", neither do USB printers.
    Hope this clarifies our problem. We would like to use Work Group Manager as advertised but it doesn't seem to be working for us.
    Welcome to my world…
    This 'bug' has existed for several major versions of Mac OS X Server (10.6, 10.5, and maybe 10.4). I did report it more than once to Apple as an official bug but they don't seem to 'get it' despite my best efforts.
    You can do the following
    Add a printer directly to a computer running WGM,
    Then use WGM to 'push' the printer out to clients,
    The model of the printer will then also be pushed out to clients so they automatically select the correct driver but not the correct paper tray/duplex/etc. settings.
    You can do the following
    Add a Mac OS X Printer Server queue to the computer running WGM (which must not be the same computer acting as the Mac OS X Printer Server) if you do this via the Bonjour advertisement of the queue then it will not get the model, or any settings from the print server.
    You can then push this queue out to clients via WGM
    You cannot do the following
    Add a Mac OS X Printer Server queue to the computer running WGM (which must not be the same computer acting as the Mac OS X Printer Server) if you do this via IPP, then the WGM machine will get the model automatically, but not any paper tray/duplex settings.
    However this queue cannot then be seen in WGM and therefore cannot be pushed out to clients.
    Apparently doing custom XML, would allow also pushing out printer settings, but this is so far from 'the Macintosh Way' that only a masochist would do it.
    This area is one of the few where the Mac is significantly worse than Windows, it is an area that Microsoft (mostly) sorted literally decades ago. Not only in the Windows world can you push the printer model, and the printer settings, but you can even if needed push the entire printer driver out to the (Windows) clients.

Maybe you are looking for