Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Network Users Unable to login on MAC Clients using OD accounts

Hi Folks,

I have spent the last few days going over manuals and posts on the net and don't seem to be able to solve this one, hoping someone out there has come across same issue and solved it.

Problem: Network users unable to login to clients using accounts created in OD

Scenario: Small business network, 1 OSX Mac Mini Server (10.6.6) and 1 iMac and 2 Macbook Pro's (10.6.6). I have successfully setup OD, SUS, DHCP, DNS, Webserver, VPN, iCal, Address Book Server etc. All tested and working fine. Now time to migrate users on OSX clients from local accounts to their Network account - want to setup mobile accounts for Macbook Pro users.

*What has been setup:* Have used workgroup manager to create accounts required in OD, have also created computer entries in OD. I have gone into login option on all three and successfully bound the computers to the "network account server". At the login screen the "network user" icon is shown and settings in system preferences to allow networked users to login to client.

*Troubleshooting already done:* Have used OD accounts to login directly to server and this works fine. Users are also able to use OD accounts to login to iCal server and Address Books server and also to create and edit Wiki's . Also able to login to VPN using OD accounts. I have checked the firewall settings and both the Password Server and Authentication Service ports are open.

So this has me stumped - I goto the client login screen- select the "Network User" icon (as opposed to local user), enter the OD user name and the OD user password and then I get the "shaking login box" . So for some reason - the login on the client seems unable to authenticate or initiate login. I have not read anywhere that the login must be <OD server>/username or anything like that - so have just been using the OD user name.

+One last thing:+ The short name of both the local account and the OD account are the same - I am trying to minimise change and plan to simply migrate settings and files and change permissions/ownership from local account to OD account once successfully logged in. I have however tested a user name that is not the same short name as the local account and get the same error, so don't think it is related to that.

I am sure its something obvious to someone knowledgeable - thanks in advance for your help.

MBPro 13, iMac 27, Macmini, Mac OS X (10.6), OSX Server in Use

Posted on Feb 7, 2011 1:00 PM

Reply
10 replies

Feb 7, 2011 3:00 PM in response to adwatson.au

Update: Trawling through the logs trying to find something specific and found that this entry seems to come up after unsuccessful login attempt with OD accounts -

8/02/11 11:52:37 AM com.apple.UserEventAgent-LoginWindow[95] ALF error: cannot find useragent 1102

If there are any other log entries I scan search for that would help solve this issue - keen to hear your thoughts.

Feb 7, 2011 4:44 PM in response to Antonio Rocco

So that does confirm a suspicion that I had (may need to change the user short names then) - however I created a testuser account to test the ability to Login to an OSX client using the OD account and unfortunately I am still getting the same error - so still there is an issue with the client being able to authenticate with the OD server using the OD accounts and login.

Feb 7, 2011 6:40 PM in response to adwatson.au

Update - Came across some useful trouble shooting in a post from Gordon Davisson who suggested running the following commands:

- id <username>
- kinit <username>

Both commands successfully identified the user from a MAC Client - so client appears to be able to successfully communicate with the OD server and get the correct responses for identification. Keen to know what other tests I can do here to solve.

Feb 8, 2011 12:08 PM in response to cpragman

Hi Folks

First - thanks for your help.

Closing this out - here is what I learned:

1) Needed to ensure my server was Kerberised and that Kerebos was running correctly
2) Local users have precedence over network so I need to ensure I don't use the same short name. While using the "id" command you may be able to see the network user ID, the local of the same name appears to take precedence.
3) Using the "kinit" command useful for confirming Kerebos is working correctly
4) Home directories created - had already done this but what finally got this working was stopping and restarting AFP Service.

So was able to successfully login to Mac Client using OD username and password - it mounted the network home share just fine on the client, loaded preferences etc.

Now on to create network users with Mobile Accounts for my laptop users - wish me luck 🙂

Network Users Unable to login on MAC Clients using OD accounts

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.