Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Network Users Unable to Log On

I have just purchased a mac mini with a lion server preinstalled (10.7.3). The server is for home use with 5 users hanging of it and (eventually) a number of mobile devices>


I have set up the server and am using a Open Directory Master. I have then inputed groups and users.


I have been able to select the server on the client machines (two mac pros and one macbook pro) under the Network Account Server section of the Users & Groups preferences pane. I can select all users or nominated ones without a problem. I can also see the server through finder and mount the shared folders.


However, I can not get get the server to accept network logins (on any of three machines that I have tried to do it from). I keep getting a "You are unable to log in to the user account "xxx" at this time. Logging in to the account failed because an error occured." I get no indication what that error may be.


This is the same result for each client and for each user.


After being frustrated for some time I resent the open directory by changing it to a standalone and then recreating a master. I reentered the users and groups and then tried again. Same result.


I have not adjusted the hostname or DNS as they seem to be working fine.


All clients and the server are operating of the latest Lion installation. All were up to date before I started the server setup.


This is killing me.

Does anyone have any suggestion what I need to look at.


T

Mac Pro (Mid 2010), Mac OS X (10.7.3), 2 x 2.93 6 Core Intel Xeon 32GB 13

Posted on Apr 7, 2012 5:41 AM

Reply
15 replies

Apr 7, 2012 8:17 AM in response to Jonathan Melville

Hi Jonathan - I use the server admin app - selected the server andthe Open Directory service and changed the role of the Open Directory under the General tab to Standalone and then to Master. I had initially setit up using the manage network accounts in the server app. It didn't seem to make a difference which way I did it. I still got the same result when trying to log in with the clients.

Apr 7, 2012 10:21 AM in response to Tim Chapman

I am afraid that recreating the ODM, users etc only from the server app did not fix the problem. I still get the same error message. There is obviously a tweak somewhere that I need to deal with. I can see the server, I can move files, I can sign on directly from finder using AFP and entering a user name and password which is excepted. For some reason I just can not get the network login working.

Apr 7, 2012 10:35 AM in response to Tim Chapman

Ok - some updates.


I raised a brand new user (one I haven't used before) and log in it works. Then, in the server app, I change the home folder from local to the server (Users), I then the get the same error as before. So the only thing I changed was the home page reference. When I change it back again - it works. So there seems to be some problem with the network identifying or accessing the home folder.

Apr 7, 2012 11:19 AM in response to Tim Chapman

Tim,

Lion Server can be very challenging at times as I also discovered. I had the same problem but gave up more quickly than you since I wasn't that desperate.


Potential causes you may still want to review:

Success and let us know when you succeed.

Apr 7, 2012 11:23 AM in response to Tim Chapman

It does not seem to be a permissions issue as the users folder as correct permissions set for root rw with admin and others ro. I have also done a repair permissions through disk utility.


I have checked the home tab in the workgroup manager app and it appears to be pointing correctly to the users folder.


I have also set preferences for the user under the workgroup manager user account creation tab for mobility to create a mobile account when logging on - still get the same error message.

Apr 7, 2012 11:32 AM in response to forappie

forappie - thanks for the response and the reading hints. I had in fact been following Terry's (excellent) article which I purchased as an ebook. I have followed his suggestions to the letter from what I can tell and am still having the issue.


With the home folder set to local, I was able to log in and have the dialog box about setting up a home folder come up on login. However, when I go to sync the home folder I get a "Sync could not complete because your network home at "(null)" does not allow writing" This seems to imply a permission issue again?


Got me stumped (and a little annoyed).


T

Apr 8, 2012 4:11 AM in response to Tim Chapman

Tim,

It isn't quite clear to me whether you are migrating users from existing (local) accounts to network accounts or creating entirely new network accounts. The migration route from an existing local account to a new Lion Server network account didn't work for me and I got the same error message as you do (I gave up since).



What worked for me is the following is creating entirely new network accounts as follows:

  1. Ensure the Users folder on the server is enabled for Home directories:
    User uploaded file
  2. In Server.app add a user via the Accounts/Users
    User uploaded file
  3. In Workgroup Manager I executed the following settings under Preferences:
    User uploaded file
    User uploaded file
    User uploaded file

... I wasn't allowed to add any more images ... I will continue in a new post.

Apr 8, 2012 4:21 AM in response to forappie

(cont)


User uploaded file


Lastly I selected the afp://.../Users on the Accounts tab in WGM as the Home directory location:

User uploaded file


After this I entered the 'testuser' network account for the first time directly on the server. Subsequently I accessed the testuser account from another Mac. I did have some problems the first time as it didn't get past Synchronisation but I clicked cancel and proceeded without a home directory. When I did get in I synced the account.


Hope this helps.


Although I can access network accounts created like this now from a Mac, these account give me still authentication problems when accessed via VPN or as account when I want to access the Profile Manager. Any help is highly appreciated (see my post https://discussions.apple.com/thread/3859651)

Apr 8, 2012 11:34 AM in response to forappie

Hi forappie - thanks for the effort I can't tell you how much I appreciate the time you have taken.


I have done everything exactly as used proposed above. I still get exactly the same error. I can not get the accounts to sync. I can see the server, connect, download and upload files no problems - but whenever I have anything other than local selected as the home folder for the user I can not connect the user.


I am beginning to think a reinstall of the server and starting again makes sense.


Is there a way to restore everything on the server to default and start over without a reinstall?


Going bananas


T

Apr 8, 2012 12:13 PM in response to Tim Chapman

Interestingly - when I log onto the server from the user account I can not access the user directory on the server. I have checked the permissions and on the server the permission is set to allow the 'testuser' to rw. When I get info on the user 'testuser' user directory on the client machine (after I have logged on to the server using cmd k through finder) it also shows rw access for the 'testuser' however when I go to open the folder it still gives me a can't open error because I don't have permissions!!! HHuh!!


I can mount the user/testuser folder directly and have no problems accessing it.

So it seems to me there is something funky happening with the r/w permissions on the user folder.


I have these set to (through the server app file sharing portal:


system administrator (owner) rw

administrator (primary group) ro

everyone else ro


plus spotlight.


These are the defaults as I haven't changed them deliberately.


When I go to the hardware portal and select storage the permissions are shown as:


root rw

admin ro

others ro


which I think seems consistent.


The "testuser" folder under users shows


everyone custom

testuser rw

staff ro

others ro


which again seems consistent?



Any thoughts?

Apr 20, 2012 10:29 PM in response to forappie

Forappie - I ended up resolving the above problem pretty simply. On my client machines I needed to include the server IP address as a DNS server under the network preferences tab. After that I have had no problems at all. I hadn't seen any reference to this in other posts or instructions. I am not sure why this was an issue for me but doesn't appear to have been a problem for anyone else.


Tim

Network Users Unable to Log On

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.