AFP548

10.6 Workgroup Manager sees AD computers, won’t create OD computer account.

Hi - Having a problem with our upgraded OD setup. Our equipment was replaced, and we ended up with 10.6 Server. We operate with a Magic Triangle, which has worked for years and years. What I'm struggling with is that in Workgroup Manager, I need to create accounts for each of the machines, or rename existing ones (for various reasons). But I'm running into a message: "The name you have chosen conflicts with a name assigned to another computer." "You can’t assign the name “TEST-02” to two different computers. Remember that names are not case-sensitive when checking for conflicts." The computer does not exist in the OD domain. I've trolled through the whole thing, exported the entire database and looked through it, and that computer does not exist in the OD domain. However, it [i]does[/i] exist in the AD domain, since it has been added to AD for authentication. Workgroup Manager is seeing the AD account and figuring the one I'm trying to setup/rename in OD (/LDAPv3/127.0.0.1) is a duplicate. This is different than my experience on our our (10.4) OD domain, where I could create OD computer accounts even if the server is in AD and an AD account for a computer already exists. I've confirmed this by disabling Active Directory in the server's Search Policy. Once that's done, I can create an account with the name I need. Once I re-enable Active Directory (to get back the AD users and groups), and add a computer to a Computer Group, Workgroup Manager sees two computer accounts when using the "Search Policy" (as opposed to /Active Directory/All Domains or /LDAPv3/127.0.0.1/) I can't add the AD computer account to an OD computer group, because a) the AD accounts don't have MAC addresses (or at least, the attribute is not mapped) and b) I don't have write access to the AD domain to add the MAC anyway. I understand why it's doing what it's doing - DirectoryServices is seeing all the resources in all available directory services. I just seem to be missing something as to how drive this thing correctly (and apparently, differently to 10.4). I have checked the 10.6 Open Directory guide, but didn't see much there to help. Augmented records seemed kind of interesting, but as I understand it, is for user records, not computers. The Triangle requires accounts in both OD and AD in order to work properly - so how do you do that and still be able to use the AD users and groups? And am I missing something stupidly obvious?
Exit mobile version