Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Critical problem after update OS X Server 3.0,anyone can help me?

first of all,forgive me using the "critical problem".... corz I am totally crazy now...Before I update,OS X server 2.2 working on OS X 10.8,and everything works fine.

After I upgrade to OS X 10.9 Mavericks, the old server app shows "can not work". Ok.... I download the OS X Server 3.0 and upgrade with it.

After it,the server app going crazy....


Original Toggle On Services include:

Time Machine,VPN,wiki,Message,File sharing,Calendar,Address Book,Mail

DHCP,DNS,Open Directory


Now working ok Services include:

DHCP,DNS


Now Toggle On but got problems Services include:

Open Directory,File Sharing


Problem with service:

Open Directorory

Toggle as on in server app,but seems my local network account was crash.

any existing user login to server,the server ask them to change password,but the chage not worked. It was stuck on the "change password".When I directly changing the password in server app, its also no response.

If I create a new accout,the mail adrees will not be auto fill,and when I click "Create", a error windows showed "existing connection is not authenticated: password change denied", and the server app go crash. Re open it , new account shows "not allowed" in the list.

Time Machine,Calendar,Address Book

Can't Login.... seems because Open Directory


File Sharing

Using a server local account was ok.Can not login as a "network account",if I using Open Directory account, it stucks on change password window.


Mail

Just after I upgrade the server app , it shows "ON",but when I telnet port 110 or 25, no response. I guess maybe the devocot didn't Starting up. So I toggle it to off and on again, the status showing "stating...." and got no response...


I am totally crazy... seems the Open Directorory was crash,also the mail server was crash...


Can anybody help me solve these problem?

OS X Server-OTHER, OS X Server

Posted on Oct 26, 2013 8:41 AM

Reply
23 replies

Oct 26, 2013 11:21 AM in response to Han_Tu

I have this issue too. Further information: When trying to change a user's password using Workgroup Manager (10.9), I get this error:


The password could not be set.

In order to set the password of a a user with an Open Directory Password, your own password type must be Open Directory. Administrators with other password types cannot set the password of a user with an Open Directory password.


... however I am authenticated to the directory as the directory admin (diradmin) and the password is of type 'Open Directory'.


Users on the network attempting to log in for File Sharing or Time Machine (anyone other than 'admin', that is, who inexplicably works fine) are unable to log in. The Console shows:

NetAuthSysAgent[707]: ERROR: AFP_OpenSession - Login failed with 80


and

NetAuthSysAgent[707]: NAHSelectionAcquireCredential The operation couldn’t be completed. (com.apple.NetworkAuthenticationHelper error -1765328228 - acquire_kerberos failed #####.######@LOCAL: -1765328228 - unable to reach any KDC in realm LOCAL, tried 0 KDCs)

[where #####.###### is the user attempting to log in].



Any help here would be appreciated as network services are essentially disabled.

Oct 30, 2013 1:11 PM in response to Han_Tu

I have the same issue after upgrading to Mavericks and Sever 3.0. I google a bit and found, that the Open Directory master is the root cause. I've done the following:

1. backed up the Open Directory using the archive function

2. remove my Open Directory master using the (-)

3. create a new Open Directory master using the archive


Now the Profile Manager runs without probs. I can push settings to my devices, can change user passwords without error....but I still have the trouble with the Mail Server. The Mail Server starts only, when I deactivate the Virus Filter, blacklisting and so on. And when the Mail Server is running, then I can't connect - even when I try on the server using terminal "telnet servername 25". I getting always the error "connection refused".


I appreciate any help!

Oct 30, 2013 9:26 PM in response to thomsen-rockt

Thanks my friend. But I have tried this solution before. When I export my Server 2.2 OD as a file,and Inport to the new 3.0 Server, OD shows 'Version doesn't match'.


also I made a call to apple customer service. They give me several solutions. I tried again and again... Still fail.


Acturally,I think I was defeated.


Cry....


Now I rollback the server with my time machine,running OS X server 2.2 with OS X 10.8.5... Its fine.


I hate Mavericks! I hate Server 3.0! (Just Kidding)

Nov 7, 2013 5:17 AM in response to Linc Davis

I've just tried this. I get


touch: /var/db/openldap/migration/.rekerberize: No such file or directory


I've been on the phone to Apple Support for over 5 hours on and off since upgrading to Mavericks, which is a bit frustrating. The last chap I spoke to thinks he tracked the issue down to a drive misconfiguration, so I've gone for a full reformat, and a completely clean reinstall of Mavericks, and Server.app.


Now, same issues. It was suggested that I try creating a home folder share point on the primary hard drive (we have a drive for OS, and a drive for files); when I try and do this Server.app says that the drive is 'read-only'. A permissions fix doesn't resolve that.


This is getting quite frustrating. Any other suggestions appreciated.

Nov 13, 2013 12:49 AM in response to Han_Tu

Try this from Apple KB >>>

After upgrading to Lion Server, AFP clients may no longer be able to authenticate via Kerberos. The AFP service may be referencing the LKDC.


Resolution


On the AFP server, execute the following command in Terminal using the correct Kerberos REALM_NAME and a user account authorized to make changes in the Kerberos database:


sudo sso_util configure -r REALM_NAME -a diradmin afp


Note: You will be prompted for two passwords. First, for the current user's password, and then for the directory administrator's password.


Restart the server.

Nov 20, 2013 8:05 AM in response to Mikep58

I've tried this, doesn't seem to help me.


I've got a clean install of Mavericks and Server.App, and a brand new Open Directory. It works for the first couple of users, then I get the password and authentication errors.


I am wondering if this is related to me installing Workgroup manager, so having tried both the sudo touch /var/db/openldap/migration/.rekerberize and sudo sso_util configure -r REALM_NAME -a diradmin afp terminal commands without success, I'm going to do yet another clean install, and this time try without putting Workgroup Manager on. Time I learnt how to apply Profile Manager instead I think!

Nov 20, 2013 1:29 PM in response to JamesSails

Here's what I discovered just a few hours ago.


I had created a new Mavericks Server install, done the migration wizard from 10.6.8 and got the same errors. "Existing connection is not authenticated. Password chage denied". Performed sudo touch /var/db/openldap/migration/.rekerberize, yada yada. Then I ran through the whole gamut of trouble shooting and norrowed it down to this:


Before starting, make an archive of your previous OD (SL or Lion). After doing the migration your users may not be there and you have to reimport the LDAP again, sometimes after step 2 below.


1. Double check your DNS service on the server you're building. Make sure any test DNS names and real DNS names have correct corresponding IP addresses. I used two so I could switch back and forth from names and IPs. Set your local DNS in the network control panel to 127.0.0.1 so its referrencing itself while you build.


2. Double check your host name under 'fileserver' and correct any errors. The local and domain have to match. example: fileserver.local, fileserver.my.domain.com. Verify all hostnames and IP address and make sure they match in DNS service. Use changeip command in terminal if you wish, but under 'Fileserver' in the 'Server.app' menu it works fine. After this you may need to re-import from your original server's LDAP archive.


3. Run the "touch" commands listed above.


4. Reboot.


5. Archive your directory again and name it for referrence. Save it to a flash drive so you can use it again if you need to rebuild later (you probably won't)


5. (here's the kicker) Turn off OD and look at your certificates in Server.app. Generate a new self-signed certificate and assign everything to that. You might need to stop OD to change its cert. Delete any expired or unused certificates. Rerun the touch commands and reboot (to be sure).


6. reimport from the LDAP archive you just saved.


6. Go through your users and edit server access. (trick, hold down the option key to turn them all on per user with a single click.s I was able to add users, edit users and connect on AFP and SMB.


After I did this it all worked, even adding users. I even did a fresh build of Mavericks server and was able to just import from the new LDAP archive with no issues.

Nov 24, 2013 9:22 AM in response to Lunchbox LP

Hi guys.

First, I apologyze for my english: I'm italian and I'll do my best to describe the problem, thet I guess you already know.

Since the upgrade to Maverick and relative server.app upgrade, even to 3.0.1, I got always the same error during network users creation:

"Existing connecting is not authenticated: password change denied".

I tried hundreds times in every issued way, even the latest of 20/11/2013 by Lunchbox LP.

NOTHING!!!

NOTHING!!!

NOTHING!!!


Does somebody Knows if Apple is going to solve this and all the other server 3.0.x bugs (including L2TP) with a BIGFIX?


Thank you.


THERE'S ANOTHER THING....

AFTER THIS LATEST Solution, + AND - BUTTONS ON NETWORK USERS PAN ARE OFF..

Is this helpful to understand the main problem?


Now I clone back the machine and I try again.... for the 10000000E000 time.....


Thank you.

Critical problem after update OS X Server 3.0,anyone can help me?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.