Active directory login breaks after one day

Hello,

i've got a problem with a new macbook pro running 10.6.5 and active directory.
we run a windows 2003 native domain and i want to authentificate against the
domain and allow domain users to log into the mac.
Binding to the domain is no problem, everything looks fine until the next day, when the login screen just shakes the login off...
With the local account, everything still seems fine, the Account utility still tells me bound to the domain (green dot). oThe checkbox for allowing domain memeber to log in is still checked. With dscl i can browse the domain and the see all user accounts and computers.
The one thind that's not working ist "id".
If i try id <domainuser> i only get what seems to be local groups, no group memeberships of the active directory.
The other strange thing is, in the authentificatio options, where i can choose witch domain members should be allowed to log into the mac, it does not show any users....

Stuff that i already looked at is time is in sync, active diretory does not give me errors in the eventlog when i try to log on. I checked the domain with the ms tools and they came back fine. I tried different domain users and they all could not log in, while they are working fine on non mac computers. Also, if i unbind from the domain the ad account of the mac is deleted, so it communicates with the ad.

It seems to me that the macs isn't even trying to authentificate against the ad.
Has any one ever had a problem like this?
Apple support tells me itś a problem with the domain, but if i format and reinstall it works again. The next day, no more login for domain users...
Are there any meaningful logs on the mac that i can check?

At one point i had "domain not in search path" (in german "Domäne nicht im Suchpfad") in the Active Directory tool, but it was only once and disappeared after unbind / bind.

Macbook Pro, Mac OS X (10.6.5)

Posted on Nov 21, 2010 1:11 PM

Reply
3 replies

Dec 3, 2010 1:56 PM in response to chewbakka09

I have what I believe may be similar issues. Binding to the domain succeeds, users can authenticate to the machine with AD credentials at the login screen and using SSH. 'id' shows only ONE group membership from AD and then shows local group memberships. However, if I try to limit logins using an AD group, all logins fail. I replicated this with another 10.6.5 Mac newly bound to the domain.

It seems that the error may be in enumerating group memberships?

The domain is using Windows Server 2008 R2.

Jan 10, 2011 9:53 AM in response to chewbakka09

I believe I may be experiencing similar issues.

I've been joined to the domain for about 3 weeks.

I have the option set to allow login when I am away from the domain.

Over the weekend I logged into my Bootcamp install and when I returned to work today it shakes off all my login attempts. When I login to a local user it works fine. It still shows it is binding to the domain. But I cannot login with my existing AD User.

Jan 21, 2011 8:39 AM in response to chewbakka09

I have the same issue. Began the week of 1/10/2011. OS 10.6.5. Machines bound to AD using locally created home directories.

On one machine opening Accounts Pref Pane does not show all previously (self) created user accounts. Home and normal auto created folders are still present in the /Users directory. Opening Workgroup Manager for the localhost of the machine does show the accounts that are not seen in the Pref Pane.

New users who have not connected to the box previously can log in and an account is created. Deleting users from within Workgroup manager does not allow those users to log back in to recreate an account.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Active directory login breaks after one day

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.