Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

10.9.2 machines having issues connecting to open directory

So i've set up a new mac mini with 10.9.2 and the most recent Server App. I managed to bind a 10.8.5 macbook air 11" and have had no issues, but when I started testing on the new machines (brand new iMac 27") with 10.9.2 im having issues, tested on my machine running 10.9.2 and another 10.8.5 machine to replicate, only the 10.9 machines are having issues. This is what im seeing in the console when i try to log in (names changed for security)



4/16/14 7:29:08.266 PM SecurityAgent[1568]: User info context values set for new.user

4/16/14 7:29:08.337 PM opendirectoryd[22]: GSSAPI Error: Miscellaneous failure (see text (Server (krbtgt/16.3.133@SERVER.LOCAL) unknown (negative cache))

4/16/14 7:29:08.338 PM authorizationhost[1622]: Failed to authenticate user <new.user> (error: 9).



ive done a permissons check, this mac mini is only running profile manager and open directory, no other services...


Please Help!

OS X Mavericks (10.9.2)

Posted on Apr 16, 2014 4:42 PM

Reply
3 replies

Apr 16, 2014 9:17 PM in response to Deltaforte

Many, if not most, Open Directory problems can be resolved by taking the following steps. Test after each one, and back up all data before making any changes.

1. The OD master must have a static IP address on the local network, not a dynamic address.

2. You must have a working DNS service, and the master's hostname must match its fully-qualified domain name. To confirm, select the server by name in the sidebar of the Server application window, then select the Overview tab. Click the Edit button on the Host Name line. On the Accessing your Server sheet, Domain Name should be selected. On the Accessing your Server sheet, change the Host Name, if necessary. The server must have at least a three-level name (e.g. "server.yourdomain.com"), and the name must not be in the ".local" top-level domain, which is reserved for Bonjour.

3. The primary DNS server used by the master must be 127.0.0.1 (that is, itself) unless you're using another server for internal DNS. The only DNS server set on the clients should be the internal one, which they should get from DHCP if applicable.

4. Follow these instructions to rebuild the Kerberos configuration on the master.

5. If you use authenticated binding, check the validity of the master's certificate. The common name must match the hostname and domain name. Deselecting and then reselecting the certificate in Server.app has been reported to have an effect in some cases.

6. Unbind and then rebind the clients in the Users & Groups preference pane. Use the fully-qualified domain name of the master.

7. Reboot the master and the clients.

8. Don't log in to the server with a network user's account.

9. Export all OD users, delete them, turn off OD, turn it back on, and import. Ensure that the UID's are in the 1001+ range.

Dec 1, 2014 9:56 AM in response to rodvela

Hi rodvela,

thank you for the fix.

However, rather than having to type that into every computer, do you know what isn't working that forces us to have to enter the info manually?


We have a number of sites. All connected with tunnels.

We handed out new computers and started getting calls from people whose computers are bound to one particular site (site 'S').

They are unable to login when they are at some sites but are able to at other sites.

The settings at all the sites are the same.

They are able to get to site 'S' using Command-K and using site 'S' domain name.

They can even ping site S using it's domain name.

If we could figure out the reason why the computers are able to resolve the DNS and are bound to the server but still can't login to their mobile accounts that would be preferable over having to edit the host file on 90 computers.


Thank you for any tips you have.

10.9.2 machines having issues connecting to open directory

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.