Home Forums OS X Server and Client Discussion Open Directory Mobile Account login fails from login window, OK via SSH

Viewing 3 posts - 1 through 3 (of 3 total)
  • Author
    Posts
  • #369496
    thegooch49
    Participant

    Hello, I have a laptop client running 10.4.10. We have LDAP auth, and the machine is setup as a Moble Account system (caching the password, for non-networked logins). I am having a strange problem where the user is unable to login via the login window. Authentication fails. I looked in Net Info, and see the cached account listed here. Everything looks normal. I cannot login via the login screen however. I can SSH successfully to it.

    To troubleshoot, I removed the account from NetInfo. I logged in again (while attached to the network). It accepted my credentials, and asked to create a mobile home (which I did). When I log out/in, my authentication fails again! I can’t figure this out, has anyone seen this? It seems like the cached credentials (or password) is corrupt in NI. It appears that LDAP auth works every time, it’s just local against NI that fails. Has anyone seen this, or have suggestions?

    -Jeff

    #369510
    thegooch49
    Participant

    This is output from: dscl localhost -read /Search/Users/jbaker

    Thanks for the help, I appreciate it!

    accountConfig: blah=1
    cn: Jim Baker
    gecos: Jim Baker
    gidNumber: 200
    givenName: Jim
    homeDirectory: /home/j/jbaker
    l: carolina
    loginShell: /bin/sh
    mail: [email protected]
    objectClass: top person organizationalPerson inetOrgPerson posixAccount shadowAccount apple-user Account
    sn: Baker
    title: Admin
    uid: jbaker
    uidNumber: 5099
    userPassword: {MD5}wQGB7oSGUYLVGXfsTNxPow==
    AppleMetaNodeLocation: /LDAPv3/ldap.company.com
    EMailAddress: [email protected]
    FirstName: Jim
    JobTitle: Admin
    LastName: Baker
    NFSHomeDirectory: /home/j/jbaker
    Password: {MD5}wQGB7oSGUYLVGXfsTNxPow==
    PrimaryGroupID: 200
    RealName: Jim Baker Jim Baker
    RecordName: jbaker Jim Baker
    RecordType: dsRecTypeStandard:Users
    UniqueID: 5099
    UserShell: /bin/sh

    #369528
    thegooch49
    Participant

    Yes, that is the cached record.

    Thanks again for the help.

Viewing 3 posts - 1 through 3 (of 3 total)
  • You must be logged in to reply to this topic.

Comments are closed