Leopard Server OD messing up AD logins
I've got a test server running OS X 10.5.2 Server and I'm running into some problems with users not being able to logon to their AD accounts when the computer is also bound to the 10.5 OD server.
After binding it to the 10.5 OD server, it will immediately reject AD logins at the login window.
- I'm still able to bind it to the 10.4 OD server without any problems.
- If I login as the local admin, I can mount shares using my AD login.
- If I go into Directory Access and change the LDAP mappings from "From Server" to "Active Directory", then it will work. Unfortunately, I can't figure out how to script this change.
I've tried everything I can think of and nothing seems to help. I can't find any errors in the logs. I've mainly been using an eMac running 10.4.11 to test this, but it's also happening on a MacBook running 10.5.2.
The only thing that works is removing the 10.5 LDAP binding or setting it to AD for the LDAP mappings.
As for scripting the LDAP mappings, I tried looking at DSLDAPv3PlugInConfig.plist before and after making the change and the only difference was "Server Mappings" went from being true to false. I tried to script this with PlistBuddy, but it didn't work. Maybe there's another plist that gets changed.
If anyone has any ideas as to what's causing this, I would love your comments and suggestions.
Thanks,
Jason