Home Forums OS X Server and Client Discussion Active Directory 10.5.x can bind to AD, but 10.4 cannot

Viewing 5 posts - 1 through 5 (of 5 total)
  • Author
    Posts
  • #375645
    PERTnet
    Participant

    My organization is ready to leverage AD authentication for the Mac. I’ve done this before on 10.4 at other places without much trouble, so I’m quite familiar with the process (at least from the Mac side).

    Our problem is that the 10.3 and 10.4 Macs cannot bind to AD, but a 10.5.x Mac did bind sucessfully with no special accomodations. The bind process is failing at the 5th step. I enabled the Directory Service debug verbose logging, and here are a few of the lines where I’m seeing failure, I just don’t know how to interpret it. It’s a small organization with a vanilla implementaion of AD.


    2009-03-05 13:07:05 EST – ADPlugin: Calling CustomCall
    2009-03-05 13:07:05 EST – ADPlugin: Good credentials for [email protected]
    2009-03-05 13:07:05 EST – ADPlugin: No existing connection in connection mgr for [email protected]@pnco.com:389
    2009-03-05 13:07:05 EST – ADPlugin: GSSAPI FAILED doing gss_init_sec_context: Server not found in Kerberos database
    2009-03-05 13:07:05 EST – ADPlugin: Secure BIND Session FAILED with server dns03.hbg.pnco.com:389
    2009-03-05 13:07:06 EST – ADPlugin: GSSAPI FAILED doing gss_init_sec_context: Server not found in Kerberos database
    2009-03-05 13:07:06 EST – ADPlugin: Secure BIND Session FAILED with server dns02.vdc.pnco.com:389
    2009-03-05 13:07:06 EST – Client: Directory Access, PID: 1013, API: dsDoPlugInCustomCall(), Active Directory Used : DAR : Node Ref = 16777794 : Request Code = 85 : Result code = -14006
    2009-03-05 13:07:06 EST – Plug-in call “dsDoPlugInCustomCall()” failed with error = -14006.
    2009-03-05 13:07:06 EST – Port: 0 Call: dsDoPlugInCustomCall() == -14006
    2009-03-05 13:07:06 EST – ADPlugin: Calling CloseDirNode

    I suspected a DNS problem so I populated the Macs network prefs with our search domain and DNS server IP’s, but that made no difference. What stumps me is that the Leopard Mac bound without a hitch.

    Anyone?

    thanks,
    Darrin

    #375676
    PERTnet
    Participant

    I’ve got a slight clue to resolving my problem…

    Installing ADmitMac on a 10.4 machine configures and binds no problem what so ever. However, it’s not really a solution for us.

    So what in the world is the Thursby Plug-in doing that the Apple’s is not?

    Grrrrr. 👿

    #375738
    PERTnet
    Participant

    Looks like Management is considering opening a case with Apple Engineering ($$$) to figure this out… 😡

    Other ideas, Anyone?

    D.

    #375741
    Tom H
    Participant

    How many DC’s do you have, and what sort of Sites and Services setup do you have ?

    #375743
    PERTnet
    Participant

    We have four DC’s, two virtual and two physical, all represented properly (as far as I can tell) in the Service Records. Using the FQDN or IP as the prefered DC while binding does no good. This AD was just implemented as an ‘upgrade’ from an NT domain.

    One Site and using AD DNS…

Viewing 5 posts - 1 through 5 (of 5 total)
  • You must be logged in to reply to this topic.

Comments are closed