Q: After upgrade server 5.1.5 network user login impossible from most workstations
Hello all,
Intro
I upgraded one of my customer's Xserves from 10.6.8 server to El Capitan / Server app 5.1.5.
The server is set up with network homefolders and mobile homefolders. Also we use MCX. The 10.6.8 configuration has run perfectly fine and still does. But now it's time to move on.
The upgrade process from was relatively smooth. I had to configure network interface again, next check DNS (forward / reverse) and also I had to re-setup the sharepoints including the network homes sharepoint (using AFP).
Problem:
Next, I started testing login as network users from the client computers. I found that it was not possible to login from most client computers.
After entering the credentials login was denied right away. As would be the case when entering incorrect credentials.
On the client computers nothing was changed.
Client computers are running Yosemite 10.10.5 and some are running 10.6.8
As soon as I reboot the Xserve from it's original 10.6.8 everything is back to normal.
What does work:
The ones that would login worked fine:
• Mobile sync (on computers not affected)
• Log is as network home user (on computers not affected)
• MCX worked fine. New settings were deployed correctly. On all computers.
• Automatically mount certain shares worked fine on all computers. There is a local admin on the client computers. When logging in to the account, network shares are mounted using MCX.
• DNS resolving from all client computers
• DHCP is working OK
• Client computers running 10.6.8 seem to be not affected.
At one point one of the affected workstations that didn't work, started to work.
What I tried and did not resolve the problem:
• Renew DHCP on client
• Removed OD binding and set it up again
• Trashed Managed Preferences folders (these were correctly recreated)
Ideas on possible causes:
The most logical causes for this behaviour could be:
1) Client machine cannot find the OD master.
2) Negotiating the credentials fails.
Since the OD binding works, MCX works etc, the client machine does find the OD Master.
The latter seems the more lickely cause. Ticketviewer doesn't show any tickets. Manually requesting a TGT from Ticketviewer using the credentials of a OD user works fine.
Any advise is appreciated.
Regards,
Nico
Mac mini, OS X Server, CentOS Linux
Posted on May 30, 2016 3:07 AM
Hi Nico,
thx for these infos. Nice to hear the problem is solved. Nice also to hear that the import of the OD-Database from MacOS 10.6.8 to 10.11.5 (Server 5.1.5) is no problem. I didn't expect this!
Regards,
Peter.
Posted on May 30, 2016 9:22 AM