image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X Server

Reply
 
Thread Tools
  #1  
Old June 18th, 2008, 04:12 PM
Registered User
 
Join Date: Jun 2008
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
cbarthmann is on a distinguished road
Lightbulb Leopard and Active Directory Integration Problems

Hi Everybody,

Here's my test setup:
*Mac Pro running Leopard Server 10.5.3
*G5 running Leopard Client 10.5.3
*Dell machine running Windows Server 2003 R2.

The main purpose of the setup is to test having both Mac and PC usernames stored in Active Directory, and to access file shares on the Mac server (to avoid paying for Windows CAL's).

I created a new domain on the Windows server, and promoted it to be a domain controller. The Windows server is also a DHCP and DNS server for the test network. The DNS server has reverse DNS entries for all machines on the test network. A few test users were created just to eventually test file and directory permissions.

The OS X server was installed as a Workgroup/Standard installation, and then upgraded to an Advanced Server.

I was able to bind both Server and Client versions of OS X to the Active Directory domain using the Directory Utility. This has allowed me to log in to OS X using usernames from Active Directory. Binding the server automatically changed the SMB server type from Standalone/Workgroup to Domain member. Workgroup Manager also now shows users created in Active Directory.

I created a new file share point in Server Admin on the OS X server, and added one of my Active Directory users under the ACL permissions section. I granted the user read and write privileges in the ACL entry.

Now, when I try to connect to the server via the OS X client using "Go to Server..." and that test account, I get a username/password combination denied, and can't log onto the server. Strangely enough, I can use the same username and password to SSH into the file server. So OS X server is authenticating against Active Directory. When trying to browse the file server from the Windows Server, I get the same issue.

However, when I use an account to that is a local administrator on the OS X server, I'm able to mount the shares properly.

Any ideas/help?

Thanks,

Charles
Reply With Quote
  #2  
Old June 20th, 2008, 10:32 AM
Registered User
 
Join Date: Jun 2008
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
cbarthmann is on a distinguished road
Red face

Oop! Somebody at work came to my rescue.

I didn't set the access controls for the AFP and SMB services in Server Admin.
Reply With Quote
  #3  
Old June 27th, 2008, 03:43 PM
Registered User
 
Join Date: Jun 2008
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
haZZard is on a distinguished road
I have a very similar question, except that instead of OS X Server, I'm just running the standard OS X 10.5.3 install.

I have bound the Mac to my Windows Active Directory domain, and local logins and SSH work fine. However, when I try to share a folder using Samba, the directory users don't authenticate. FTP works fine though.

I have noticed that while in the File Sharing preferences, if I click the "Options" button, underneath the "Share files and folders using SMB" option, there is a box containing the local accounts and the following explanation:
"When you enable SMB sharing for a user account, you must enter the password for that account. Sharing with SMB stores this password in a less secure manner."

So does this mean I'm not able to share folders with AD users using SMB?

Any help would be appreciated!

Thanks,
-Kevin
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 09:21 AM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.