Upgrading from Mavericks to Yosemite breaks Active Directory. Is there a fix / work-around?
I work for an organization that uses Active Directory (Windows Server 2008, I believe) for user account management and also for managing printer shares. Until Yosemite, OS X worked brilliantly with AD and our user accounts and machines were bound easily and reliably. When any user upgrades to Yosemite, the process occurs without a hitch except that AD connectivity breaks.
The color indicator for Network Account Server in Users & Groups is green, indicating that believes the connection to the directory server is OK. If you select "Edit" for the directory configuration - everything looks as it did before. However, if one attempts to access the Active Directory tree using Directory Utility it displays the error "Connection failed to node '/Active Directory/COMPANY/All Domains'. If one uses the command line utility 'dscl' to attempt to list AD entries, you also get errors:
> ls Active\ Directory/COMPANY
All Domains
> ls Active\ Directory/COMPANY/All\ Domains
ls: Invalid Path
<dscl_cmd> DS Error: -14009 (eDSUnknownNodeName)
If I go to add a printer, I can no longer retrieve the printer list from the domain.
I have checked, and there DNS search domains are correctly configured and fully configured properly on all the computers involved. They can all ping the AD servers, and if I used dig to check for SRV records for LDAP (_ldap._tcp.directory.company.com), they are correct.
Does anyone have an idea what's going on? What's changed and how to fix it?