Previous 1 2 3 Next 42 Replies Latest reply: Jul 23, 2012 5:49 AM by Alfista_SK
Alfista_SK Level 1 (0 points)



can anybody help mi with binding Lion Servers Open Directory to Windows Active Directory?

I Have setuped Windows 2008 Server and Windows 2003 Server. On both is full working Active Directory. The clients can conect to it (win).

I would lice to have some Mac clients and will setuped Lion server an in Open Directory I have set to connect to another server. Then in Directory Utility I will set the connection to AD Server over Connect in File menu and I have only error mesage "Can't connect to the server - Directory Services may not be installed on the remote server, they may be turned off, or the URL may have been entered incorrectly." and then I try the connection over Services - Active Directory and have error mesage "Authentication server could not be contacted." too.

Can somebody help me with setting Lion Server to connect to Win Active Directory?





Mac OS X (10.7.4)
  • furby Level 1 (25 points)

    Let's assume you have things setup correct and try this way:


    On the Lion Server.

    1. System Preferences
    2. Users and Groups
    3. Login Options (click the lock to Authenticate)
    4. Network Account Server and click Edit...
    5. Click on the +
    6. Enter your AD domain name like apple.local or whatever it is for you.

    More options should drop down, enter whichever account lets you bind to the network (you don't need the domain\username just username).


    I'm at a machine that's already bound to the domain but I think there rest is fairy straight forward.

  • Alfista_SK Level 1 (0 points)

    Thanks, but i have the same error "Unable to add server - Authentication server could not be contacted. (5200)" like when i go over Directory Utilty.

    And your connection is for connecting clients to AD server, but I need to bind AD and OD Servers together.


    Any other idea?

  • furby Level 1 (25 points)

    I think there is a little something getting lost here  but let's see if we can work this out. I think I know what's going on but just to be sure.


    Can you bind a mac client to the AD?

  • Alfista_SK Level 1 (0 points)

    No the same error like on the server. But I have Lion clients only so I know that I cant't connect it to Win 20089 server directly, so I try to do it over Lion server (Apples Magical Triangle).

  • furby Level 1 (25 points)

    Not true. You can bind to the AD (Server 2008/3) without the Lion Server.


    What you can't do is mange the machines (and to a lesser extent user settings) without the Lion Server and more specifically Profile Manager. But let's not go there yet.


    I thought you had another problem so this is a little trickier than I thought. If we can sort this out on a client machine we can then sort out the server.



    Did you bind the Client machines to the OD? And you're using the Exact same information (domain, user, pass) when binding the windows clients and Lion clinets?


    In the Network Utility app go to the Lookup tab and put in the DC does it return an IP ad FQDN? (server.domain.local)?

  • Alfista_SK Level 1 (0 points)

    I have read that with the Lion isn't possible to connect to WIn 2008 RC2 server (witch I have) while there isn't support of some NT4 protocol. But you have right, I do it while I need to manage later all users and accounts.


    I have ported the DNS on the Win server with AD and tested. It looks that all is workink OK. All servers are working (win2008server, win2003server,


    Now, I can't connect to OD server while I have seted it in OD Service to connect to annother server and so I can't start the service (I don't know why, I don't have there the start button). I thing when I connect the servers it will apair or start automaticaly.


    I have posted on all servers some clients (for test), but i use for binding the admin login.

  • furby Level 1 (25 points)

    Yes, all my lion machines and servers are bound to our Server 2008 R2 active directory. Mercifully that's the easiest part.


    Cool, good that DNS is working. This is essential as Mac systems tend to rely more heavily on it.


    Your problem is how you've setup the OD. What you need to to do it destroy/break your OD, bind to the AD first. Once you've bound to the AD then create a Open Directory Master.


    I'm a bit wary of posting this as it's different on 10.7 but this is the general order:


    To get clients into your OD you need to then enroll them using the profile manager. If you don't need external access just start at the section "Provided the Welcome to Lion Server page loads, click on the Profile Manager service. Here, click on the Configure button.



    Hopefully this is helpful. The next step would be creating Augmented Records but I don't want to get too far ahead.

  • Alfista_SK Level 1 (0 points)

    If I uderstand what I shold do is:


    1. make cleen instal of Lion Server

    2. then bind AD Server over Directory utility

    3. Create OD Master on Lion Server


    Over the profile magager I ennroll the users witch i get from AD or that witch i created in workgroup manager?

    The binding AD and OD server where still working when I change the OD setings to Master?

    After the change to OD Master when I add user on AD server, I see him on OD server too?


    I was in it, that I need to be connected with the AD server (in OD setings "to conect to another server"), but I don't understand when I change the seting to that, why I have there the standalone OD and can start the service ...


    Thanks, I go test it :-)

  • Alfista_SK Level 1 (0 points)

    Can you tell me why my Lion client can't connect to AD on my Win 2008 Server and give me the same error like a server when it should be possible?

  • furby Level 1 (25 points)

    Lots's of questions there. I'll try and aswer them in order.


    1. If you haven't no, you probably don't need to.

    2. Yes

    3. Yes


    No, use Profile Manager to enroll devices, not users but let's get back to that later.


    Yes, it's still bound when you change to OD master.


    No, at least from my experience, you need to import users each time. I think you already know how to do this but just in case ory-architecture



    Yes, it doesn't work if you do it in that order for some reason. I didn't feel like it was worth my time trying to figure it out but feel free to


    I don't know. Are all your clients 10.7.4?

  • Alfista_SK Level 1 (0 points)

    All is on Lion 10.7.4.


    I do now the cleen instal of Lion server and I would like to check that the binding AD to server should I do before I start and setup OD on server? (I do it on full clean install, there can't be the service in Server Admin Tools installed).

  • furby Level 1 (25 points)

    Yes. Do it before.


    I forget about if the service need to be runnign or not. Try it without first.

  • Sinerg1 Level 1 (0 points)



    I am also having this exact same issue and followed your (furby) steps as much as possible with no luck.  I just can't seem to bind to AD but will happily bind to ldap...


    Our client machines happily bind to AD but the server will not.  As Alfista last mentioned, it sounds like he is doing a clean install of lion and I was hoping to avoid this, do you have any alternative guidence furby?



  • furby Level 1 (25 points)

    Same error? If you're clients can connect but not the server that would seem to be the source of the problem. Do you get a proper response when you do an nslookup for the Domain Controller?


    I suspect the problem is a DNS one but that will be tricky to troubleshoot.


    I actually had an idea for a workaround for Alfista_SK but I don't see why you couldn't try it as well. I'll post it when I get a moment later.

Previous 1 2 3 Next