Home Forums OS X Server and Client Discussion Active Directory Home folders on Win2003 Server

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • #360046
    gregpica
    Participant

    Hello,
    I am authenticating Mac user against our Win2003 Active Directory server. I am trying to get user “Home” folders to reside on the server, rather than locally. I am using the OS 10.3.6 Active Directory plug-in to authenticate to the server. Authentication works fine. I used dsconfigad to disable localhome folders. Mount style is SMB. I used dsconfigad -show to verify AD settings and they appear correct. I also used dscl commands to read more detailed information about the user account and all parameters look fine. However, when I attempt to login to the system as the user, I get a dialog that reads:

    “You are unable to log in to the user account “mac” at this time. Logging in to the account failed because an error occurred. The home folder for the user account is located on an AFP or SMB server. Contact your system administrator for help”.

    I have the server Home folder shared out with a folder inside of it for the mac user. I used the connect feature of the Profile tab of the user account to set the Home folder location as \\servername\HOME\%username%. where username is “mac” . the folder permissions seem correct.

    I’m not certain what the error dialog means or what the issue is. It seems like a pretty straight forward setup to configure.

    Any assistance as to what to look for would be very much appreciated.
    thank you
    greg

    #360078
    gregpica
    Participant

    The Active Directory plug-in does not currently support SMB signing. The Security Option policy named “Microsoft network server: digitally sign communications” needed to be disabled. Once I did that the client logged in and mounted its network home folder.

    #360178
    sketch
    Participant

    ignore me Oops!

    #360568
    tmhayes
    Participant

    I have experienced this issue as well. However in my case the answer was more complicated as we were transitioning from an older nt4 domain to a new AD domain. In short the AD server sat in the new domain while the win2k server with the smb home folder on it was sitting in the older doamin. If a user changed a password in one domain and not in the other, you get the aforementioned error message. Hope the info is of help to others.

Viewing 4 posts - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.

Comments are closed