Home Forums OS X Server and Client Discussion Open Directory WGM not authorized

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • #371453
    tbone
    Participant

    Brought up a new 10.4 server, set to standalone. Later tried to replicate to OD master running 10.3. Saw this wouldn’t work so did an upgrade install of 10.4 server on old OD master. Replication appeared to work like a champ.

    Later downed the old master but before doing so promoted the new server to master. Went well I thought.

    Now the new server, OD master, can’t make any changes to the LDAP database. I’m logging in with the dir admin account but can’t create new users or anything. Get “not authorized to make changes” error.

    Any ideas? Thanks.

    😳

    #371455
    tbone
    Participant

    Well I thought I had solved but I it seemed solved because I powered the old server up. So even though I’ve made the old server standalone and made the new server OD master I can’t change anything in OD without the old server reachable by the new one. There is nothing in Directory Access so I just don’t understand why this is.

    #371469
    tbone
    Participant

    Get not authorized error unless old server is reachable.

    #371471
    tbone
    Participant

    I have run it to check only.
    The names match, there is nothing to change.

    I’ve now broken all ability to update the database even with the old server online by mucking with the old server attempting to restore it from an older backup.

    I notice kerberos isn’t running on the new one and I can’t kerberize it. This is not good because of the large number of users and groups. This may not be an issue because kerberos wasn’t running on the old server either. I stepped into this migration on a contract. Doing a tcpdump reveals it is still trying to contact the old server when I click to make any changes in WGM. I did promotion by the OD manual, I can’t understand what is lingering or why.

Viewing 4 posts - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.

Comments are closed