Q: Can't create Local Network Users in Yosemite
I can't create Local Network Users (or change passwords)
Logged on to /LDAPv3/127.0.0.1 as directory administrator
When I try to create a new user (press the [+], fill in the form), it brings up the message:
existing connection is not authenticated or secure: password change denied
I suspect this is emblematic of other issues. I can authenticate for Mail and SMB, but not for AFP or Xcode
Server 4.0, OS X Yosemite (10.10)
Posted on Oct 25, 2014 10:09 PM
So I fixed it for myself, but it is not a pretty solution.
Archiving and Restoring was putting me in a loop where the issues was not getting fixed.
the Directory Administrator account was working and authenticated but still could not create new users or change users passwords.
I traced it to issues with SASL from the upgrade.
1. So, downloaded WorkGroup Admin and installed (Thankfully it still works in 10.10)
2. From Workgroup Admin I exported the users and then the groups.
3. Open Server.app and I turned off OpenDirectory, then quit Server.app
4. Open terminal and destroy the directory
sudo slapconfig -destroyldapserver
5. Open Server app and set up a NEW OpenDirectory server
6. Add a test user and try changing the password to verify it is all working
7. If it works then blow away that user
8. Select Manage import Accounts from File and import your users and verify they all come in
9. Do the same but this time select your groups file
10. unfortunately this does NOT preserve passwords so you can either set a temp password and have users change it at login or if you know them you can re-enter them
At this point you should have a clean, functional OpenDirectory server with full control over users again.
Posted on Nov 19, 2014 10:54 AM