Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

10.7.2 & Active Directory

I know that Lion first two releases has issues with Active directory.. but Im using 10.7.2 now and I was able to bind my Mac to the main domain but not with the child domain..

main domain: domain.com

child domain: test.domain.com


I'm able to bind 10.5 & 10.6 with the child domain just fine.. but not 10.7, and when i try to bind 10.7.2 it goes through the process and then dsplay an error message: Authentication server failed to complete the requested operation.


Any idea ?

Posted on Nov 16, 2011 9:58 AM

Reply
11 replies

Feb 6, 2012 8:15 AM in response to ivaldiz

I was having the same issue and it seemed to stem from a mis configuration in Kerberos. I nuked the local KDC and the bind worked as expected.


Destroy Local KDC:

  1. sudo rm -rf /var/db/krb5kdc
  2. sudo rm -rf /etc/krb5.keytab
  3. sudo rm -rf /Library/Preferences/edu.mit.Kerberos
  4. Bind the Server to Active Directory.


Also - and I'm not sure if this had any effect, but in our Domain our Admin accounts are in a different forest than the computer accounts and standard user accounts, this is usually not an issue, but just to be safe, instead of allowing the AD plugin to create the computer object I created it in the correct OU first and made sure that my standard user which lives in the same forest had permission to join that object.

Jul 13, 2012 9:02 AM in response to ivaldiz

Another reason you might be seeing this error is if the name of the macine is over 15 characters long. NetBIOS doesn't support more chartacters and even though AD will allow you to create names with more characters when you try to bind to the AD domain you can end up with


"authentication server failed to complete the requested operation"


messages and a lot of frustration. 15 or less characters may well remove your problem.


Cameron,

xxx.

10.7.2 & Active Directory

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.