UUID for client machine not the same as UUID for account on Server...
I've been having some odd issues with permissions and I'm wondering if it has something to do with UUIDs on our system. We're coming from an environment running 10.3 Server (running as Standalone OD) and just upgraded to 10.5 Server (running OD as Master) and the setup is something like this:
- Intel Xserve running OS X Server 10.5.6 running the following services:
- AFP/File Sharing
- DNS (internal DNS, Primary Zone)
- Open Directory (OD Master)
- VPN
There are other 2 other Xserves on the networking, both with OD connected to an OD Master (the Xserve listed above.
All employees have had Open Directory based accounts created on the Xserve. But, these accounts are not used for logging into desktop Macs (ie. network homes), these accounts are for logging into th server ONLY, via AFP, for file sharing.
All desktop computers are Macs and a mix of G4, G5 and Intel, running the latest version of either 10.4 or 10.5 (though all machines are being upgraded to 10.5 this summer). As for user accounts on these computers — each employee has their own computer and on each computer they have a local user account (ie. not a network based user accounts) for logging in — thus, they're tied to a single computer. There are also some computers that have generic user accounts (for example "Design" or Production" depending on the department) that anyone can log into.
So, here's where I think I'm having a problem. Since machine-based user accounts are "local" to the machine, the UUID of the local account wouldn't be the same as the UUID of the account they login to the server with. And even if they were the same (per user), on the machines with generic logins, these generic logins don't have equivalent OD/Server accounts — for example, a user logs into the computer via a generic "Design" account, but once logged into the computer they mount a Share Point using their server-based OD account credentials (via AFP). So, there's no way the local machine account UUID could ever be the same as the UUID of the server-based account they're logging in as.
So, since 10.5 Server pretty much relies on UUID (or, so it seems), is there any way I can deal with this sort of environment and have permissions work properly (ie. local machine accounts utilizing server-based OD accounts to mount Share Points which utilize ALCs based on these server-based OD accounts)?
If anyone is still reading this, and I haven't thoroughly confused you, your advice would be appreciated!
Regards,
Kristin.
20" Intel iMac 2.16 Ghz, 12" PowerBook G4 1.33 Ghz, Power Mac G4 667 Mhz, Mac OS X (10.5.6), Xserve (Intel), Xserve (G5), Mac Pro