"Invalid Domain and Forest combination" During an Active Directory (AD) Bind
I am using 10.6.8 and trying to bind to an active directory server over which I have complete control. DNS has an entry for the fully qualified domain name of the Active Directory Domain Controller (AD DC). Regardless of what I enter into the dialogs in Directory Utility, I get the error below:
Invalid domain
An invalid Domain and Forest combination was specified. You should enter a fully qualified DNS name for the domain and forest (e.g., ads.company.com).
- The Directory Utility tool does not permit editing the "Active Directory Forest".
- I enter a valid fully qualified host name in for the "Active Directory Domain:".
- I enter a simple "titan" in the "Computer ID" field.
- I press the I let Directory Utility generate the "Bind..." button.
- I let Directory Utility generate the "Computer OU:" field.
- I enter my username and password for the account on the Active Directory server; the account with god privileges on the AD server.
- I press the OK button
- and ... invalid domain.
Mind you, the forest and the computer OU are all entered into the Directory Utility by the AD plugin at this point. Is the AD plugin telling me it itself is defective? (ah sweet irony). If it is not, then the AD plugin is tossing up a pretty darn useless error dialog. (had more helpful fortune cookies)
http://support.apple.com/kb/TS1206 states updating to 10.5.3 and beyond will fix this problem. If that were trully the case, why is the error dialog even present in Mac OS X 10.6.8? (ah huh... buggy is as buggy does!)
What comes to mind is the guessing game of what the AD plugin is assuming as the forest name as it will not let me enter it. Does anyone know what assumption the AD plugin makes? I can try and shave the AD square plug to fit Apple's round hole if I knew the diameter ;-)
Someone should just tell Microsoft to fix their stuff to work like Apple wants!