-T--

Q: Can't create or delete users and group

Hi, I'm not sure why the users button become disableScreen Shot 2014-08-28 at 10.31.58 AM.pngScreen Shot 2014-08-28 at 10.32.45 AM.png

 

I had try this OS X Server (Mavericks): After upgrading or migrating, network user cannot be created

but now the local network users can't connect to the services at all. Anyone can show me how to find the problem?

Thanks!

 

I just check the Password Service Server log, it keep showing this
Screen Shot 2014-08-28 at 3.55.29 PM.png

Mac Pro, OS X Mavericks (10.9.4), OS X Server 3.1.2

Posted on Aug 28, 2014 1:00 AM

Close

Q: Can't create or delete users and group

  • All replies
  • Helpful answers

  • by jonasmn,

    jonasmn jonasmn Aug 28, 2014 1:25 AM in response to -T--
    Level 1 (9 points)
    Servers Enterprise
    Aug 28, 2014 1:25 AM in response to -T--

    I have not had this problem, but I have had a lot of other problems with Mavericks Server, less with each new update though. But I have found that several problems can be solved by:

     

    1) repairing file permissions

    2) then reboot the server

     

    Good luck

    Jonas Möller Nielsen

    Sweden

  • by Linc Davis,Helpful

    Linc Davis Linc Davis Aug 28, 2014 6:54 AM in response to -T--
    Level 10 (207,995 points)
    Applications
    Aug 28, 2014 6:54 AM in response to -T--

    Search the System keychain on the server for application passwords with the name "/LDAPv3/127.0.0.1" and delete any you find. Sign out of the Server app and sign back in using the FQDN of the server, not "localhost" or "127.0.0.1".

    Credit for this observation to ASC member Peter Jurg2. See also this discussion.

  • by -T--,

    -T-- -T-- Aug 30, 2014 5:53 AM in response to -T--
    Level 1 (5 points)
    Mac OS X
    Aug 30, 2014 5:53 AM in response to -T--

    Thanks for the reply.

    Linc Davis , now I can connect back my services but it slow respond. When I connect to my afp file sharing, it takes about 40 seconds to login. Do you know why?

    I still can't create or delete users and groups.

  • by Linc Davis,

    Linc Davis Linc Davis Aug 31, 2014 10:15 AM in response to -T--
    Level 10 (207,995 points)
    Applications
    Aug 31, 2014 10:15 AM in response to -T--

    Many Open Directory problems can be resolved by taking the following steps. Test after each one, and back up all data before making any changes.

    1. The OD master must have a static IP address on the local network, not a dynamic address.

    2. You must have a working DNS service, and the server's hostname must match its fully-qualified domain name. To confirm, select the server by name in the sidebar of the Server application window, then select the Overview tab. Click the Edit button on the Host Name line. On the Accessing your Server sheet, Domain Name should be selected. Change the Host Name, if necessary. The server must have at least a three-level name (e.g. "server.yourdomain.com"), and the name must not be in the ".local" top-level domain, which is reserved for Bonjour.

    3. The primary DNS server used by the server must be 127.0.0.1 (that is, itself) unless you're using another server for internal DNS. The only DNS server set on the clients should be the internal one, which they should get from DHCP if applicable.

    4. Follow these instructions to rebuild the Kerberos configuration on the master.

    5. If you use authenticated binding, check the validity of the master's certificate. The common name must match the hostname and domain name. Deselecting and then reselecting the certificate in Server.app has been reported to have an effect in some cases. Otherwise delete all certificates and create new ones.

    6. Unbind and then rebind the clients in the Users & Groups preference pane. Use the fully-qualified domain name of the master.

    7. Reboot the master and the clients.

    8. Don't log in to the server with a network user's account.

    9. Disable any internal firewalls in use.

    10. As a last resort, export all OD users. In the Open Directory pane of Server, delete the OD server. Then recreate it and import the users. Ensure that the UID's are in the 1001+ range.

  • by -T--,

    -T-- -T-- Sep 10, 2014 12:18 AM in response to Linc Davis
    Level 1 (5 points)
    Mac OS X
    Sep 10, 2014 12:18 AM in response to Linc Davis

    Hi, when I archive my Open Directory, it show this

    Screen Shot 2014-09-10 at 3.14.09 PM.png

    Do you know why? I checked the server DNS is 127.0.0.1 and 8.8.8.8. The host name is correct. But I still can't create users or groups

  • by -T--,Solvedanswer

    -T-- -T-- Sep 13, 2014 5:41 PM in response to -T--
    Level 1 (5 points)
    Mac OS X
    Sep 13, 2014 5:41 PM in response to -T--

    Thanks Linc Davis and jonasmn. I delete the open directory and recreate all the user.