Home Forums OS X Server and Client Discussion Open Directory LDAP OD binding and MCX

Viewing 3 posts - 1 through 3 (of 3 total)
  • Author
    Posts
  • #358760
    dragonmac
    Participant

    Big Grin
    Well after much frustration Evil with setting up a new 10.3 client to login via “list of names” from a OD LDAP 10.3 Server and use MCX workgroup management I think I got it. Would love any input on this. I did NOT use AD my only shared domain is the LDAP. My main problem comes in because of all the info out there appears to be WRONG! I’ll explain.

    I wanted to set up my new clients like they where under MM in OS9 so I set on the road to bind the clients for Auth and Home Dir. Now my server is an OD Master ok no problem. All my users have an OD Password ok no problem. KDC is up and running fine. Added client Node to Accounts Computer list and set MCX prefs for Login only. So to the client and the Directory Access utility. Now with out going into detail about the config I followed the Apple Setup Documentation, Philly School Districts nice Web page on Binding a 10.3 client and numerous other little notes from forums like afp548 on how to do this. Nothing seemed to work. Everyone kept saying to set the LDAPv3 config with “LDAP mappings” set to “From Server” adding or don’t have to add as Apple says your

    dc=domain,dc=com
    
    
    

    entry.
    NOT once could I get this to work on a 10.3 client. So I finally after many hours of restarts I set it to “Open Directory Server” and added

    dc=domain,dc=com
    
    
    

    entry. to the search base. OMG it WORKED. The user now gets a List of User Network of the groups I allowed, Local Users, and Other. This is how my MCX Login prefs are set for this Group of Mac’s. The Home Dir. is a Network home and You can’t even tell, No Mounted server just all your default home link in Finder and such go to a “User Home” on the server. I had to copy a file and look as root on the server in the Users Home to be sure and it was. So Cool!!! Big Grin
    No whole Users Dir. Share point and no mounting of servers visible to client.
    Now before I go any further with this can folks out there tell me:
    A) What problems will I have with clients setup this way if any?
    Cool Why does everyone go the AD way with this MCX, LDAP, OD setup?
    C) Will this setup work on 10.2 clients?
    D) Are there security issues with the Auth this way? Is it going KDC or I could force the KDC check at login?
    E) Did I just hit the jackpot? lol.

    To Admin: If you would like I could write a Detailed Post or PDF of how I did this for others out there that want the easy way to Bind a client without AD and only use shared directory LDAP.

    #358777
    dragonmac
    Participant

    [QUOTE]I’m thinking that you might have a DNS issue or did when you set your master up.[/QUOTE]
    Dam I could have used that cash, Thanx Josh for the info. One thing more if you could.
    Funny you should mention the quote above. I did as a matter of fact have an issue after a clean install of 10.3 Server on a Mac G5. Ahh well beat me with a stick if you must but when I first setup and booted the unit my Ethernet plug was not in tight. OK not in at all, it was late. So yes when I started I had issues and had to redo my KDC setup from scratch but all appears fine now. OD seems ok too but your note concerns me. How can I fix the issue so the “From Server” works? My DNS info was right and is OK. Since the server was not on the Network at first startup what happened to OD and KDC?

    #358842
    dragonmac
    Participant

    Well still no responce to my last reply. He is a busy guy so can someone else tell me what I can do to fix the “From Server” connection to LDAPv3 from client. There has to be a way that doesn’t mean a fresh install.

Viewing 3 posts - 1 through 3 (of 3 total)
  • You must be logged in to reply to this topic.

Comments are closed