Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Attempting Active Directory Bindings in 10.4.3



John Buell <email@hidden> on Thursday, November 17, 2005 at 2:16 PM
-0500 wrote:
>
>
>
>On 11/17/05 11:46 AM, "Phillip Burk" <email@hidden> wrote:
>
>> On Nov 16, 2005, at 4:29 PM, John Buell wrote:
>> 
>>> Dsconfigad -show results in:
>>> 
>>> You are bound to Active Directory:
>>>   Active Directory Forest        = domain.net
>>>   Active Directory Domain        = domain.net
>>>   Computer Account               = mac-jbuell
>> 
>> There are no subdomains, then, correct?  I mean, you don't have a
>> setup like this:  northamerica.domain.net, europe.domain.net, etc.
>> 
>
>Correct. One forest, one domain.
>
>>> Advanced Options - User Experience
>>>   Create mobile account at login = Disabled
>>>      Require confirmation        = Enabled
>>>   Force home to startup disk     = Disabled
>>>   Use Windows UNC path for home  = Enabled
>>>      Network protocol to be used = smb:
>>>   Default user Shell             = /bin/bash
>> 
>> OK
>> 
>>> Advanced Options - Mappings
>>>   Mapping UID to attribute       = not set
>>>   Mapping user GID to attribute  = not set
>>>   Mapping group GID to attribute = not set
>> 
>> Not needed probably in your case
>> 
>>> Advanced Options - Administrative
>>>   Preferred Domain controller    = not set
>>>   Allowed admin groups           = domain\domain admins,domain
>>> \enterprise
>>> admins
>>>   Authentication from any domain = Enabled
>> 
>> I'd set a preferred DC and see how that goes.  Sometimes if DNS can't
>> return the DC address you'll have this issue.
>> 
>
>By name or by IP address?
 If you are going to do this, I would use the IP address.  It could be
that the AD domain's DNS servers aren't returning the correct information
to the client.  Although, you probably wouldn't have been able to bind to
AD if it wasn't working on some level.  In any case, the IP address will
eliminate the DNS server from the equation.
>
>
>>> Advanced Options - Static maps
>>>   None
>> 
>> 
>> 
>>> MAC-JBUELL:~ buelljd$ id jbuell
>>> uid=834315997(jbuell) gid=1972167813(D129\domain users)
>>> groups=1972167813(domain\domain users), 1025(adusers), 81
>>> (appserveradm),
>>> 1227302558(domain\domain_technicians), 353220042(domain\admin_users),
>>> 1623269779(domain\sophosadministrator), 1419159470(domain\domain
>>> admins),
>>> 267633726(domain\administrators), 79(appserverusr),
>>> 852718252(domain\wh_techs), 80(admin)
>>> 
>>> 
>>> Note that buelljd is my local Mac's admin account, and jbuell is my AD
>>> domain account.
>> 
>> Any other networking issues?  Duplex mismatch can cause problems but
>> that's admittedly a reach.
>> 
>
>The iMac is on wireless, but we've got 20 PC laptops in a wireless cart in
>the same location, and they log into the domain.
>
>-- 
>John Buell
>Computer Technician
>Kane County School District 129
>North Aurora, Aurora and Montgomery, IL
>
>
> _______________________________________________
>Do not post admin requests to the list. They will be ignored.
>Client-management mailing list      (email@hidden)
>Help/Unsubscribe/Update your Subscription:
>http://lists.apple.com/mailman/options/client-management/email@hidden
>
>This email sent to email@hidden



Mike Bumbalough
Network Systems Analyst
School District of Manatee County
(941)708-8800 Ext. 1021

 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Client-management mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/client-management/email@hidden

This email sent to email@hidden

References: 
 >Re: Attempting Active Directory Bindings in 10.4.3 (From: John Buell <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.