6 Replies Latest reply: Dec 31, 2009 1:42 PM by kb2yht
tnine Level 1 Level 1 (0 points)
Hi all,
I'm working on trying to get my OD server to authenticate our new windows vmware workstations. I have both LDAP and Kerberos set up, and everything works really well with my OS X clients, as do our Linux servers. However, I'm unable to get our windows clients authenticating. I can browse the "spidertracks" computer as well as the Samba shares, so the shares themselves are working. I'm simply unable to join our Windows 7 64Bit clients to the domain to authenticate with OD accounts. Here is what I have configured in the samba settings. Am I missing something? I've read the manual nearly 20 times, and joining the domain simply doesn't work, so I'm guessing I've missed a configuration somewhere when creating my Kerberos realm. Is there a command I can use to validate my samba settings are correctly running as a PDC?

Thanks,
Todd


LDAP config dc=spidertracks,dc=local
Kerberos Realm: SPIDERTRACKS.LOCAL

Samba Settings

MAIN
Role: Primary Domain Controller
Description: Spidertracks
Computer Name: Spidertracks
Domain: SPIDERTRACKS

ACCESS
Authentication: NTLMv2 & Kerberos, NTLM

ADVANCED
Wins Registration: Enable Wins Server


DHCP Settings (on different machine, Free BSD Based)

WINS Server: 10.0.1.11 (My OD server's IP)

MacBook Pro, Mac OS X (10.5.2)
  • 1. Re: Unable to join domain when OD Master is set up as PDC
    tnine Level 1 Level 1 (0 points)
    BUMP. A pointer to some documentation that has a bit more depth than the OD manual would be greatly appreciated. I wasn't able to get much support from Apple short of "start over" which is definitely not an option for me.

    Message was edited by: tnine
  • 2. Re: Unable to join domain when OD Master is set up as PDC
    Andbrowny Level 4 Level 4 (1,610 points)
    Hi tnine, is it only 7 clients giving this problem, can you bind with an XP client?
    I suspect it maybe a Windows7 issue. I ran into some earlier in the year with the RC binding to a OSX PDC.
    As far as documentation goes, apart from this document , which I suspect you have probably covered everything in anyway, I can't help.

    Cheers
  • 3. Re: Unable to join domain when OD Master is set up as PDC
    tnine Level 1 Level 1 (0 points)
    Hi Browny,
    You're right. It's something specific to windows 7. XP joins fine. I guess I'll contact Windoze support.
  • 4. Re: Unable to join domain when OD Master is set up as PDC
    Andbrowny Level 4 Level 4 (1,610 points)
    Hi again, I did find this post that says you need Samba v3.3.4, where OS X Server version is Samba 3.0.25b-apple and also need to add a couple of registry keys.

    Cheers.
  • 5. Re: Unable to join domain when OD Master is set up as PDC
    tnine Level 1 Level 1 (0 points)
    That definately helps. Unfortunately, I'm not sure how to go about upgrading Samba, and it appears that 10.6 server still uses an old version, so just buying the new distro won't get me anywhere. I did a fair amount of googling, and I can't find any information on upgrading Samba. Does anyone know of a way to go about this so that Samba still will use the OD LDAP and Kerberos services to authenticate and apply permissions?

    Thanks,
    Todd
  • 6. Re: Unable to join domain when OD Master is set up as PDC
    kb2yht Level 1 Level 1 (0 points)
    Bump:
    Rather than starting a new thread,
    I am fighting with the same thing on one of our servers, this is an issue that was fixed by the Samba guys, but I can't deploy their fix and still use OD.
    I'm starting to think that our experiment using OSX instead of linux as a server may be at an end, I keep spending a lot of effort chasing down issues that are solved months ago on linux.
    Somebody help, I dont want to be told to get rid of the shiny Mac ( or more likely bootcamp it to linux )
    --Bill