Very slow login away from work AD network

My MacBook is bound to my work Active Directory (AD). When I'm at home my MacBook can take up to 10 minutes to login once I have entered my password. AirPort is on. I think Snow Leopard is trying to find the AD domain (Windows 2008 Server) over the AirPort connection. This times out and the Mac uses the cached credentials (my password) instead. Anyone know a way to force it NOT to use the AirPort connection?

iMac (2009), MacBook (2009), Mac OS X (10.6.3)

Posted on Apr 23, 2010 6:00 PM

Reply
4 replies

Apr 26, 2010 4:18 PM in response to Anthony Seng

The problem is that your machine is searching the network for the AD controllers (and possibly other machines should it have additional login hooks). There's no really good way, that I know of, to force it not to do this only when you're home.

The easiest way to avoid this is to turn off Airport prior to logging out and make sure you don't have a physical network connection when logging in. That way all network requests will immediately timeout (due to the lack of any network connection) and your login won't be hung up waiting for responses that will never come. It's a bit of a pain to do this every time, but if it makes it so you don't have to wait 10 minutes I'd say it's worth it.

Apr 28, 2010 4:19 AM in response to trite1

Thanks. I thought this was happening. The strange thing is that the MacBook isn't always slow to log in when away from the AD even if AirPort is active and connected.

I'll try to remember to turn off AirPort or log in 10 minutes before I actually need it. This is one time I wish there was a hardware switch on the Mac for AirPort on/off instead of only through the OS.

May 9, 2010 1:48 AM in response to Anthony Seng

I'm having this same problem, and haven't been able to find much in terms of a solution.

The peculiar thing, is that it has only started doing this recently.

I've been using the MacBook for about 3 weeks now, and haven't had any issues logging in out of the office. Just tonight, I turned it on, and was surprised to find it taking 2 or 3 minutes to log in.

Seems to me that there should be a way to set a much lower timeout for active directory logins - maybe 5 to 10 seconds, instead of 5 to 10 minutes... Of course, add it to the other unusual circumstance - the fact that it seemed to work fine for a couple of weeks...

Hopefully a fix comes out for this fast.. I was setting this up for the president of our company, and had just informed him that all the bugs were worked out... he will not be happy if he has to wait 5 or 10 to log in...

May 9, 2010 2:11 AM in response to James Ball

I found this website -
http://prowiki.isc.upenn.edu/wiki/Solvingtimeout_issues_withActiveDirectory

Here, it is described that you can modify the following file: /Library/Preferences/DirectoryService/ActiveDirectory.plist

If you look for the line which contains "LDAP Connection Timeout". He states a default of 240 seconds, but found my default to be 90. I changed it to 5, and found that the login speed was greatly improved. However, it still takes about 20 seconds for any password to be authenticated, unless I turn off AirPort... sigh.

Perhaps there is another timeout value somewhere else which can be altered.

Have a nice day, and hope this helps.
-James

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Very slow login away from work AD network

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.