WGM error while trying to connect to Active Directory

Hello I'm trying to insert AD groups into OD groups so I can create automounts to a users specific network folder. When attempting to connect to AD from within WGM I get an unexpected error. It states:

Error of Type eDSOpenNodeFailed (-14002) on line 4125 of /SourceCache/WorkGroupManager/WorkGroupManager-361.3.1/PMMUGMainView.mm

I tried googling the whole error and parts of the wording but havent found anything relative. It used to work.

Same error using Macmini 10.6.4 and Xserve 10.6.4, recently the district office did change the way my domain sync's with theirs as I was having syn errors with groups. I have a 2000 domain structure and the D.O. has a 2003 structure. i will be migrating the DC roles over to my 2003 Server this Thanksgiving, but for now I have to deal with what I have.

Thanks in advance...Art

MacMini and Xserve, Mac OS X (10.6.4)

Posted on Oct 20, 2010 1:24 PM

Reply
9 replies

Oct 21, 2010 6:04 AM in response to redrider03

The error is exactly what is says. Error -14002 is eDSOpenNodeFailed which means that you failed to open the directory node. Start with the basics. Have you changed DNS? Is your time off? DNS and time are the two most common causes of AD drop off. Run these commands:

sudo changeip -checkhostname
nslookup <fqdn of_your_macserver>
nslookup <ip address_of_yourserer>

host -t SRV ldap.tcp.domain.tld

host -t SRV kerberos.tcp.domain.tld

host -t SRV kpasswd.tcp.domain.tld

host -t SRV gc.tcp.domain.tld

In the last 4, replace domain.tld with your domain and top level domain suffix (such as mydomain.com)

If DNS is all still in place, then check your time. You are pointing the Mac at the Windows DC for time, correct?

ntpq -p

This will check your time sync. What is the jitter. If it is high, then stop and start time sync in System Preferences. Again, make sure you are using a mutually accepted (preferably an internel) time server on all domain resources.

If DNS and time check out, you can always try doing a rebind of the machine. It is possible that in the changes to AD you moved or deleted the machine record.

Hope this helps

Oct 21, 2010 7:32 AM in response to Strontium90

Thanks for the Post Strontium90
All checked out fine from the Server except host -t SRV _gc....it relayed a host not found: 3(NXDomain) Is this a Global Catalog error relayed from the Windows domain?

The time on the Server and the Macmini that I have the admintools installed on are synced with my DC which syncs with the district office DC's, as stated earlier in less description I have been getting GC errors on newly created user groups on my Windows DC because the district made some schema changes before the summer to put the rest of the district on 2003 structure, I still have 2000 to fix my problem they made some kind of replication changes for my domain, I wonder how this would effect the Xserve, all AD users can log into the machines my only problem is in pulling AD groups into OD. The Xserve OD DNS structure is seperate from AD, but I do have the Xserve bound to AD, I have unbound and rebound my macmini before I made the post to see if that would change anything but it did not, I think I will try the Xserve next.

Oct 21, 2010 9:35 AM in response to redrider03

All checked out fine from the Server except host -t SRV _gc....it relayed a host not found: 3(NXDomain) Is this a Global Catalog error relayed from the Windows domain?


Yes
... I wonder how this would effect the Xserve, all AD users can log into the machines my only problem is in pulling AD groups into OD. The Xserve OD DNS structure is seperate from AD, but I do have the Xserve bound to AD, I have unbound and rebound my macmini before I made the post to see if that would change anything but it did not, I think I will try the Xserve next.


Why is DNS independent? Not that it is related, but maintaining two DNS identities is going to lead to confusion at best and disaster at worst. If the primary domain is AD, you should be using only the AD DNS. In a normal AD promotion all the SRV records get created by default. While it is possible to create the service records for AD on OS X, it is usually not recommended. Too much management. My gut is to track down the absence of the GC service record. If you truly have independent DNS hosted on OS X and that is the primary resolver for the machine (assuming same domain), then try creating the svr record on OS X for the GC. Seems a bit odd but if you are at odds with the Windows admins, this might be your only way of proving that this is the issue.

You mention that users can log into machines. This is from the workstation. Have you tried dscl from the server or the workstation to see if you are able to browse the groups?

Oct 21, 2010 10:46 AM in response to Strontium90

The district is primarily Windows only, I have an Xserve only for managing the computer policies, all Mac clients are bound to OD for WGM policies and AD for authentication. The district was hesitant to having MAC servers, there is only a couple of us techs located at sites not the d.o. that have Mac servers, the rules passed down to us was to have the mac servers run their own DNS but setup forwarders to our windows DNS so thats what I did.

I am able to browse all smb shares from the server or any mac all machines bind to ad with no problems, I just cant connect to ad within WGM.

Oct 21, 2010 5:36 PM in response to redrider03

Do you know how to use the dscl command?

Maybe you are truly dealing with an odd WGM issue. Try to use dscl to query the AD domain. In Terminal, enter (followed by the return key):

dscl

This will enter you into the interactive dscl shell. It will take simple commands like ls and cd. For example, if you want to navigate to the AD container, enter this:

cd Active\ Directory/All\ Domains/Groups/

Hit return. Then list the contents of the Groups container using:

ls

That is a lower L as in list

Do you get an error here?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

WGM error while trying to connect to Active Directory

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.