We've got a mix of iMac G5 and PowerMac G5 machines running on a Windows 2003 network. They were bound to the domain and everything was working splendidly as far as AD is concered. We retired our old Primary Domain Controller; since then, we're unable to log into a Mac with an Active Directory. If we log in with a local account, we can browse the internet, see all network resources...we can even connect to shares on Windows PCs/Servers and authenticate using AD accounts. If we try to unbind, we get an "unable to access domain controller" error. Forcing the unbind works, but trying to re-bind generates the same "unable to access domain controller" error. I've tried it on 10.4.4, 10.4.5 and 10.4.7 with the same results. I've wiped clean and installed Tiger fresh on a machine, I've even moved to a couple different locations just to eliminate a switch or fiber connection as the culprit. None of this made a difference.
I've gone over the new PDC with a fine-toothed comb, and made some policy changes based on some stuff I read at macwindows.com, but all to no avail. Any ideas what might be the sticking point? Any and all help is greatly appreciated!
Naturally, after posting this here, I found the culprit. Just in case anyone else has a similar issue, make sure the LDAP Server signing policies on the Domain Controller are set to "None". Macs will bind nicely now.