Home Forums OS X Server and Client Discussion Active Directory Changing from Mobile Accounts back to Local Accounts

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #368218
    rmleonard
    Participant

    in my current laptop hell – I am faced with a dilemma –

    I know how to convert a local account to a mobile one and get things managed by AD and or OD – BUT…

    on laptops I am getting GINORMOUS timeouts (on some boxen as much as 2 hours)..

    in combination there are about 11 Directory servers (both AD and OD) (backups and replicants and such)

    I have run the python script found at http://macenterprise.org/content/view/248/84/

    and I’ve reduced the values from 240 sec down to 10.. it has made a world of difference – again BUT…

    What I’d like to do until a fix from apple is released, is to convert the user instance from the network/mobile authenticated user to a local user with the AD userID-GroupID – so that when things get working again – I can just flip a bit and get it network authenticated again – I realize that if the AD or OD passwords change then there will be a disconnect and Kerb will get grouchy – but right now I have VERY grouchy faculty and administrators who get locked out of their own machines because of network time outs…

    (the main cause that I’ve found is when they are connected to a wireless AP, cisco at the university, who knows what at home – and then they log out or shutdown – then get to an area were there is no wireless and no wire and they try to log back in – )

    Yes – I can do the create new user – and then move the home directory over and do the chown/chmod trick to reown the home to the new user – but that defeats the purpose of trying to keep the UID/GID the same…

    This is a Mac!!! there should be a way to do this!!!!!!
    (tongue in cheek)

    Rich Leonard

    #368233
    rmleonard
    Participant

    just blanking out the Directory Access points (one for AD and one for OD) doesn’t seem to make a difference…

    we have tried just disabling them and removing the entries – it makes no difference – if wireless is on and the system needs to authenticate in – it gets shot to #$%@#$%

    it is only when you need to login or wake from sleep –

    i’m probably not explaining as well as i should…

    but on my Dean’s laptop – I’ve completely removed Directory Access points and made sure that entries are removed the services (LDAP and Active Directory) and that only /netinfo/defaultlocalnode is in Authentication and no contacts entries other than defaultlocalnode…

    and looking at the log files – shows sequential timeouts still

    I timed it at about 45 minutes to finally auth in.

    after the python script to shorten things up I got it under 5 minutes

    Rich

Viewing 2 posts - 1 through 2 (of 2 total)
  • You must be logged in to reply to this topic.

Comments are closed